Skip to content

Commit

Permalink
Confirm effectiveness of vuln scans (#2248)
Browse files Browse the repository at this point in the history
### Time to review: __1 mins__

## Changes proposed

Confirms that grype is scanning down to "medium" level vulnerabilities

## Context for reviewers

I wasn't sure that it was already doing this, and this PR confirms that
it is.
  • Loading branch information
coilysiren authored Sep 27, 2024
1 parent d30fadf commit e075024
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 0 deletions.
2 changes: 2 additions & 0 deletions .github/workflows/vulnerability-scans.yml
Original file line number Diff line number Diff line change
Expand Up @@ -147,6 +147,8 @@ jobs:
with:
image: ${{ needs.build-and-cache.outputs.image }}
output-format: table
fail-build: true
severity-cutoff: medium

- name: Save output to workflow summary
if: always() # Runs even if there is a failure
Expand Down
2 changes: 2 additions & 0 deletions .grype.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
fail-on-severity: "medium"

# List of vulnerabilities to ignore for the anchore scan
# https://github.com/anchore/grype#specifying-matches-to-ignore
# More info can be found in the docs/infra/vulnerability-management.md file
Expand Down

0 comments on commit e075024

Please sign in to comment.