From d828db46a36b68dbe6c72ff4dde50893a317e855 Mon Sep 17 00:00:00 2001 From: Sacha Al Himdani Date: Wed, 10 Sep 2025 17:44:19 +0200 Subject: [PATCH] Use official anchore github actions Signed-off-by: Sacha Al Himdani --- .github/workflows/make.yaml | 41 ++++++++++------------------------ .github/workflows/release.yaml | 27 ++++++++++------------ .grype.yaml | 5 +++++ GNUmakefile | 6 ++--- 4 files changed, 32 insertions(+), 47 deletions(-) create mode 100644 .grype.yaml diff --git a/.github/workflows/make.yaml b/.github/workflows/make.yaml index 69fba1bef..59dcdcab1 100644 --- a/.github/workflows/make.yaml +++ b/.github/workflows/make.yaml @@ -29,7 +29,7 @@ jobs: - uses: "docker/setup-qemu-action@v3" - uses: "docker/setup-buildx-action@v3" - uses: "sigstore/cosign-installer@v3" - - uses: "anchore/sbom-action/download-syft@v0" + - uses: "anchore/sbom-action/download-syft@da167eac915b4e86f08b264dbdbc867b61be6f0c" # v0.20.5 - uses: "goreleaser/goreleaser-action@v6" with: distribution: "goreleaser" @@ -72,33 +72,16 @@ jobs: coverage.html retention-days: 30 - run: "make lint" + - name: Generate SBOM + uses: anchore/sbom-action@da167eac915b4e86f08b264dbdbc867b61be6f0c #v0.20.5 + with: + path: ./ + format: cyclonedx-json + output-file: sbom.json - vulnerability-scan: - name: "vulnerability-scan" - runs-on: "ubuntu-24.04" - permissions: - contents: "read" - steps: - - uses: "actions/checkout@v4" + - name: Run vulnerability scan + uses: anchore/scan-action@1638637db639e0ade3258b51db49a9a137574c3e #v6.5.1 with: - fetch-depth: 0 - - uses: "actions/setup-go@v5" - with: - go-version: "1.25" - - uses: "actions/setup-node@v4" - with: - node-version: 22 - - run: "npm ci" - - name: "Install Syft" - uses: "anchore/sbom-action/download-syft@v0" - - name: "Install Grype" - run: | - curl -sSfL https://raw.githubusercontent.com/anchore/grype/v0.85.0/install.sh | sh -s -- -b /usr/local/bin - - name: "Generate SBOM" - run: | - syft dir:. --output cyclonedx-json --source-name probo --source-version ${{ github.sha }} > sbom.json - - name: "Scan SBOM for vulnerabilities" - run: | - echo "Scanning SBOM for vulnerabilities..." - grype sbom:sbom.json --fail-on critical --output table - echo "Vulnerability scan completed successfully - no critical vulnerabilities found" + path: ./ + fail-build: true + severity-cutoff: critical diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 0de021501..9f803262e 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -37,13 +37,6 @@ jobs: - name: Install dependencies run: npm ci - - name: Install Syft - uses: anchore/sbom-action/download-syft@v0 - - - name: Install Grype - run: | - curl -sSfL https://raw.githubusercontent.com/anchore/grype/v0.85.0/install.sh | sh -s -- -b /usr/local/bin - - name: Install Cosign uses: sigstore/cosign-installer@v3 @@ -71,15 +64,19 @@ jobs: env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - - name: Generate SBOM for attestation - run: | - syft dir:. --output cyclonedx-json --source-name probo --source-version ${{ github.ref_name }} > sbom.json + - name: Generate SBOM + uses: anchore/sbom-action@da167eac915b4e86f08b264dbdbc867b61be6f0c #v0.20.5 + with: + path: ./ + format: cyclonedx-json + output-file: sbom.json - - name: Scan SBOM for vulnerabilities - run: | - echo "Scanning SBOM for vulnerabilities..." - grype sbom:sbom.json --fail-on critical --output table - echo "Vulnerability scan completed successfully - no critical vulnerabilities found" + - name: Run vulnerability scan + uses: anchore/scan-action@1638637db639e0ade3258b51db49a9a137574c3e #v6.5.1 + with: + path: ./ + fail-build: true + severity-cutoff: critical - name: Generate subject for attestation id: hash diff --git a/.grype.yaml b/.grype.yaml new file mode 100644 index 000000000..0cbea09f2 --- /dev/null +++ b/.grype.yaml @@ -0,0 +1,5 @@ +ignore: + - vulnerability: "CVE-2024-3566" + package: + name: "stdlib" + reason: "CERT VU#123335: Go is Not Affected" diff --git a/GNUmakefile b/GNUmakefile index 3a73379c1..7ee974913 100644 --- a/GNUmakefile +++ b/GNUmakefile @@ -87,15 +87,15 @@ sbom: .PHONY: scan-sbom scan-sbom: sbom - $(GRYPE) sbom:sbom.json --fail-on high + $(GRYPE) sbom:sbom.json --config .grype.yaml --fail-on high .PHONY: scan-sbom-docker scan-sbom-docker: sbom-docker - $(GRYPE) sbom:sbom-docker.json --fail-on high + $(GRYPE) sbom:sbom-docker.json --config .grype.yaml --fail-on high .PHONY: scan-docker scan-docker: docker-build - $(GRYPE) docker:$(DOCKER_IMAGE_NAME):$(DOCKER_TAG_NAME) --fail-on high + $(GRYPE) docker:$(DOCKER_IMAGE_NAME):$(DOCKER_TAG_NAME) --config .grype.yaml --fail-on high .PHONY: scan scan: scan-sbom scan-sbom-docker scan-docker