ckan / ckan/ckan-docker-base

Scanning Official CKAN Docker Images for vulnerabilities

Open
#55 0 comments 0 reactions 1 assignee Claimed by @kowh-ai View on GitHub
Dominant language
Shell
Stars
35
Forks
41
PR merge metrics
No merged PRs in 30d

Description

Create GitHub action(s) Workflow to run (maybe nightly) a vulnerability scan on the _Official_ CKAN images in DockerHub

Create a report that can be view manually

What tool (or tools) should we use:

1. **Synk Container**
2. **Trivy**

Trivy seems to be a one of the better ones after rudimentary analysis of image scanners currently on the market

**UPDATE:** The report should just highlight the most important vulnerabilities (CRIT, maybe HIGH too) for each of the CKAN images. The report should run once a week and an email of the report should be sent.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.