Skip to content

Commit 24d856e

Browse files
bluesentinelsecjoshuagrishamJoshua-Grisham_SSCSpace
authored
v1.4.0 (#133)
* Use aws-cli instead of amazonlinux to speed up container build time (#128) * Change Dockerfile source image to aws-cli * Set WORKDIR back to default value --------- Co-authored-by: Joshua-Grisham_SSCSpace <joshua.grisham@sscspace.com> * set workflows to develop for aws-cli runtime tests * add explicit permissions to GitHub Actions workflows (#130) * Measuring installation time (#131) (#132) * measuring installation time * Change workflows to point to v1.4.0 branch --------- Co-authored-by: Joshua Grisham <josh@joshuagrisham.com> Co-authored-by: Joshua-Grisham_SSCSpace <joshua.grisham@sscspace.com>
1 parent b8917ac commit 24d856e

15 files changed

+67
-19
lines changed

.github/workflows/build_scan_container.yml

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,11 @@ on:
1212
branches: #
1313
- '*'
1414

15+
permissions:
16+
contents: read
17+
id-token: write
18+
actions: write # For uploading artifacts
19+
1520
jobs:
1621
build:
1722
name: Build docker image
@@ -47,7 +52,7 @@ jobs:
4752
role-to-assume: ${{ secrets.AWS_IAM_ROLE }}
4853

4954
- name: Scan built image with Inspector
50-
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.3.0
55+
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.4.0
5156
id: inspector
5257
with:
5358
artifact_type: 'container'

.github/workflows/example_display_findings.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,10 @@ on:
88
branches: #
99
- '*'
1010

11+
permissions:
12+
contents: read
13+
id-token: write
14+
1115
jobs:
1216
daily_job:
1317
runs-on: ubuntu-latest
@@ -29,7 +33,7 @@ jobs:
2933
# modify this block to scan your intended artifact
3034
- name: Inspector Scan
3135
id: inspector
32-
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.3.0
36+
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.4.0
3337
with:
3438
# change artifact_type to either 'repository', 'container', 'binary', or 'archive'.
3539
# this example scans a container image

.github/workflows/example_vulnerability_threshold_exceeded.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ jobs:
4848

4949
# Inspector scan
5050
- name: Scan container with Inspector
51-
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.3.0
51+
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.4.0
5252
id: inspector
5353
with:
5454
artifact_type: 'container' # configure Inspector for scanning a container

.github/workflows/run_unit_tests.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,10 @@ on:
77
branches: #
88
- '*'
99

10+
permissions:
11+
contents: read
12+
id-token: write
13+
1014
jobs:
1115
build:
1216
runs-on: ubuntu-latest

.github/workflows/scan_repo_with_semgrep.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,9 @@ name: Semgrep Scan
22

33
on: [push]
44

5+
permissions:
6+
contents: read
7+
58
jobs:
69
semgrep:
710
runs-on: ubuntu-latest

.github/workflows/test_archive.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ on:
1111
branches: #
1212
- '*'
1313

14+
permissions:
15+
contents: read
16+
id-token: write
17+
1418
jobs:
1519
daily_job:
1620
runs-on: ubuntu-latest
@@ -32,7 +36,7 @@ jobs:
3236

3337
- name: Test archive scan
3438
id: inspector
35-
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.3.0
39+
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.4.0
3640
with:
3741
artifact_type: 'archive'
3842
artifact_path: 'entrypoint/tests/test_data/artifacts/archives/testData.zip'

.github/workflows/test_binary.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ on:
1111
branches: #
1212
- '*'
1313

14+
permissions:
15+
contents: read
16+
id-token: write
17+
1418
jobs:
1519
daily_job:
1620
runs-on: ubuntu-latest
@@ -32,7 +36,7 @@ jobs:
3236

3337
- name: Test binary scan
3438
id: inspector
35-
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.3.0
39+
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.4.0
3640
with:
3741
artifact_type: 'binary'
3842
artifact_path: 'entrypoint/tests/test_data/artifacts/binaries/inspector-sbomgen'

.github/workflows/test_containers.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ on:
1111
branches: #
1212
- '*'
1313

14+
permissions:
15+
contents: read
16+
id-token: write
17+
1418
jobs:
1519
daily_job:
1620
runs-on: ubuntu-latest
@@ -32,7 +36,7 @@ jobs:
3236

3337
- name: Test container scan
3438
id: inspector
35-
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.3.0
39+
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.4.0
3640
with:
3741
artifact_type: 'container'
3842
artifact_path: 'ubuntu:14.04'

.github/workflows/test_dockerfile_vulns.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ on:
1111
branches: #
1212
- '*'
1313

14+
permissions:
15+
contents: read
16+
id-token: write
17+
1418
jobs:
1519
daily_job:
1620
runs-on: ubuntu-latest
@@ -31,7 +35,7 @@ jobs:
3135

3236
- name: Scan Dockerfiles
3337
id: inspector
34-
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.3.0
38+
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.4.0
3539
with:
3640
artifact_type: 'repository'
3741
artifact_path: './'

.github/workflows/test_installation.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ on:
1111
branches:
1212
- '*'
1313

14+
permissions:
15+
contents: read
16+
id-token: write
17+
1418
jobs:
1519
daily_job:
1620
runs-on: ubuntu-latest
@@ -28,7 +32,7 @@ jobs:
2832
role-to-assume: ${{ secrets.AWS_IAM_ROLE }}
2933

3034
- name: Test Amazon Inspector GitHub Actions plugin
31-
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@1.x
35+
uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1.4.0
3236
with:
3337
artifact_type: 'container'
3438
artifact_path: 'alpine:latest'

0 commit comments

Comments
 (0)