.github: scan docker images with Dive/Dockle

Open
#53 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
45/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
docker, github-actions
Domain
ci-cd, devops, security

Research direction

Start with the global ci-docker.yml workflow and review how Docker images are currently built. Determine where Dive and/or Dockle scans should run, then verify that the workflow performs the requested image scanning successfully.

Written by the indexing model from the issue text.

Description

6+ months Docker effort:Medium GitHub actions LizardByte/.github planned priority:Low
Is there an existing issue for this item?
  • I have searched the existing issues
Repositories

LizardByte/.github

Languages/Skills/Technologies

Docker, GitHub actions

Description

The idea is to modify our global ci-docker.yml workflow to scan images with Dive and/or Dockle

Estimated Effort

effort:Medium

Priority

priority:Low

Target Milestone

6+ months

Dependencies

No response

Dominant language
No language data
Stars
2
Forks
0
Avg merge
25m
Merged PRs (30d)
5

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from LizardByte/roadmap

All issues in LizardByte/roadmap

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.