Skip to content

Scan built docker images using trivy or grype #3177

Closed
@jawnsy

Description

@jawnsy

We use AquaSec Trivy in some of our other projects for scanning our source code as well as built containers for possible security issues related to our third-party dependencies (e.g. packages installed with apt-get or yarn), and should consider the same for code-server

This would complement the audit-ci tool that we have already integrated.

Metadata

Metadata

Assignees

Labels

choreRelated to maintenance or clean upciIssues related to cifeatureNew user visible feature

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions