File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 3636 docker stop test-api
3737 docker rm test-api
3838
39- push-to-dockerhub :
39+ security-scan :
4040 runs-on : ubuntu-latest
4141 needs : build-and-test
42+ steps :
43+ - name : Checkout code
44+ uses : actions/checkout@v4
45+
46+ - name : Build image for scanning
47+ run : |
48+ cd Day-9/python-ap
49+ docker build -t devops-api:scan .
50+
51+ - name : Run Trivy vulnerability scan
52+ uses : aquasecurity/trivy-action@master
53+ with :
54+ image-ref : devops-api:scan
55+ format : table
56+ exit-code : ' 0'
57+ severity : ' CRITICAL,HIGH'
58+ output : trivy-results.txt
59+
60+ - name : Show scan results
61+ run : |
62+ echo "🔍 Security Scan Results:"
63+ cat trivy-results.txt
64+
65+ - name : Upload scan results
66+ uses : actions/upload-artifact@v4
67+ with :
68+ name : trivy-security-report
69+ path : trivy-results.txt
70+
71+ push-to-dockerhub :
72+ runs-on : ubuntu-latest
73+ needs : [build-and-test, security-scan]
4274 if : github.ref == 'refs/heads/main' && github.event_name == 'push'
4375 steps :
4476 - name : Checkout code
74106 - name : Summary
75107 run : |
76108 echo "🐳 Image pushed to Docker Hub!"
109+ echo "🔐 Security scan passed!"
77110 echo "Tags: ${{ steps.meta.outputs.tags }}"
Original file line number Diff line number Diff line change 11# Use official Python slim image — smaller than full python
2- FROM python:3.11-slim
2+ FROM python:3.11-alpine
33
44# Set metadata
55LABEL maintainer="awspractical57"
@@ -11,9 +11,17 @@ WORKDIR /app
1111# Set environment variable
1212ENV PORT=8000
1313
14+ # Upgrade pip package to fix known vulnerbilities
15+ RUN pip install --upgrade pip wheel setuptools
16+
1417# Copy application code
1518COPY app.py .
1619
20+
21+ # Create non-root user
22+ RUN adduser -D -u 1000 appuser
23+ USER appuser
24+
1725# Expose the port
1826EXPOSE 8000
1927
You can’t perform that action at this time.
0 commit comments