Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix security scanning tools so that reports make sense #3119

Open
jimmykarily opened this issue Jan 13, 2025 · 2 comments
Open

Fix security scanning tools so that reports make sense #3119

jimmykarily opened this issue Jan 13, 2025 · 2 comments
Assignees

Comments

@jimmykarily
Copy link
Contributor

jimmykarily commented Jan 13, 2025

Because currently they report errors but we don't know what's wrong: https://github.com/kairos-io/kairos/security/code-scanning

Also, let's update the GH release ticket template so that it links to the places where we should check for CVEs before we release (e.g. framework security tab, kairos security tab etc)

@jimmykarily jimmykarily converted this from a draft issue Jan 13, 2025
@jimmykarily jimmykarily moved this from Todo 🖊 to In Progress 🏃 in 🧙Issue tracking board Jan 13, 2025
@jimmykarily jimmykarily self-assigned this Jan 13, 2025
@jimmykarily
Copy link
Contributor Author

jimmykarily commented Jan 13, 2025

We added a -trivy and -grype suffix (e.g. here) but the old "configurations" where still dangling (they are created on the fly when we push some results with a category string). I deleted the old configurations and it cleaned up the tool warnings.

The results still fail to load most of the time but with enough refreshes I can get them to show up if I filter by tool (so there are less to load I guess).

@jimmykarily
Copy link
Contributor Author

The reports still don't load in the web ui. @Itxaka opened a ticket on GH support.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: In Progress 🏃
Development

No branches or pull requests

1 participant