Skip to content

Commit 37a3c19

Browse files
Merge pull request #23 from awspractical57/feat/day-12-security-scanning
feat: add Trivy security scanning to CI pipeline + fix Dockerfile user
2 parents eff925f + 03fbef6 commit 37a3c19

2 files changed

Lines changed: 43 additions & 2 deletions

File tree

‎.github/workflows/docker-cicd.yml‎

Lines changed: 34 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,9 +36,41 @@ jobs:
3636
docker stop test-api
3737
docker rm test-api
3838
39-
push-to-dockerhub:
39+
security-scan:
4040
runs-on: ubuntu-latest
4141
needs: build-and-test
42+
steps:
43+
- name: Checkout code
44+
uses: actions/checkout@v4
45+
46+
- name: Build image for scanning
47+
run: |
48+
cd Day-9/python-ap
49+
docker build -t devops-api:scan .
50+
51+
- name: Run Trivy vulnerability scan
52+
uses: aquasecurity/trivy-action@master
53+
with:
54+
image-ref: devops-api:scan
55+
format: table
56+
exit-code: '0'
57+
severity: 'CRITICAL,HIGH'
58+
output: trivy-results.txt
59+
60+
- name: Show scan results
61+
run: |
62+
echo "🔍 Security Scan Results:"
63+
cat trivy-results.txt
64+
65+
- name: Upload scan results
66+
uses: actions/upload-artifact@v4
67+
with:
68+
name: trivy-security-report
69+
path: trivy-results.txt
70+
71+
push-to-dockerhub:
72+
runs-on: ubuntu-latest
73+
needs: [build-and-test, security-scan]
4274
if: github.ref == 'refs/heads/main' && github.event_name == 'push'
4375
steps:
4476
- name: Checkout code
@@ -74,4 +106,5 @@ jobs:
74106
- name: Summary
75107
run: |
76108
echo "🐳 Image pushed to Docker Hub!"
109+
echo "🔐 Security scan passed!"
77110
echo "Tags: ${{ steps.meta.outputs.tags }}"

‎Day-9/python-ap/Dockerfile‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
# Use official Python slim image — smaller than full python
2-
FROM python:3.11-slim
2+
FROM python:3.11-alpine
33

44
# Set metadata
55
LABEL maintainer="awspractical57"
@@ -11,9 +11,17 @@ WORKDIR /app
1111
# Set environment variable
1212
ENV PORT=8000
1313

14+
# Upgrade pip package to fix known vulnerbilities
15+
RUN pip install --upgrade pip wheel setuptools
16+
1417
# Copy application code
1518
COPY app.py .
1619

20+
21+
# Create non-root user
22+
RUN adduser -D -u 1000 appuser
23+
USER appuser
24+
1725
# Expose the port
1826
EXPOSE 8000
1927

0 commit comments

Comments
 (0)