mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-07 14:00:56 +00:00
22adccb353
The trivy scan fails on HIGH vulnerabilities found in the Debian 13 base images (util-linux, acl, ncurses, systemd and perl-base). None of them has a fixed version available yet, so there is nothing we can upgrade to clear them. List these CVEs in a shared .github/.trivyignore and pass it to every image scan, so the scan stays blocking for any new HIGH or CRITICAL vulnerability. Remove the entries once Debian ships a fix.
79 lines
2.4 KiB
YAML
79 lines
2.4 KiB
YAML
name: Docker images
|
|
run-name: Docker images
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
push:
|
|
branches:
|
|
- 'main'
|
|
tags:
|
|
- 'v*'
|
|
pull_request:
|
|
branches:
|
|
- 'main'
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build-and-push:
|
|
name: ${{ matrix.service }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- service: backend
|
|
image_name: lasuite/meet-backend
|
|
context: .
|
|
file: ./Dockerfile
|
|
target: backend-production
|
|
- service: frontend
|
|
image_name: lasuite/meet-frontend
|
|
context: .
|
|
file: ./src/frontend/Dockerfile
|
|
target: frontend-production
|
|
- service: frontend-dinum
|
|
image_name: lasuite/meet-frontend-dinum
|
|
context: .
|
|
file: ./docker/dinum-frontend/Dockerfile
|
|
target: frontend-production
|
|
- service: summary
|
|
image_name: lasuite/meet-summary
|
|
context: ./src/summary
|
|
file: ./src/summary/Dockerfile
|
|
target: production
|
|
- service: agents
|
|
image_name: lasuite/meet-agents
|
|
context: ./src/agents
|
|
file: ./src/agents/Dockerfile
|
|
target: production
|
|
uses: suitenumerique/ci/.github/workflows/_docker-publish.yml@ca6401ac83e981e5b0a94f06f68baaa6e6d0a436 # v0.0.1
|
|
with:
|
|
image_name: ${{ matrix.image_name }}
|
|
context: ${{ matrix.context }}
|
|
file: ${{ matrix.file }}
|
|
target: ${{ matrix.target }}
|
|
docker_user: "1001:127"
|
|
is_multi_platform: ${{ startsWith(github.ref, 'refs/tags/v') }}
|
|
should_push: ${{ github.event_name != 'pull_request' || startsWith(github.head_ref, 'integration/') }}
|
|
trivy_scan: true
|
|
trivy_ignore_files: ./.github/.trivyignore
|
|
secrets:
|
|
DOCKER_HUB_USER: ${{ secrets.DOCKER_HUB_USER }}
|
|
DOCKER_HUB_PASSWORD: ${{ secrets.DOCKER_HUB_PASSWORD }}
|
|
|
|
notify-argocd:
|
|
permissions:
|
|
contents: read
|
|
needs:
|
|
- build-and-push
|
|
runs-on: ubuntu-latest
|
|
if: github.event_name != 'pull_request'
|
|
steps:
|
|
- uses: suitenumerique/ci/actions/argocd-webhook-notification@ca6401ac83e981e5b0a94f06f68baaa6e6d0a436 # v0.0.1
|
|
id: notify
|
|
with:
|
|
deployment_repo_path: "${{ secrets.DEPLOYMENT_REPO_URL }}"
|
|
argocd_webhook_secret: "${{ secrets.ARGOCD_PREPROD_WEBHOOK_SECRET }}"
|
|
argocd_url: "${{ vars.ARGOCD_PREPROD_WEBHOOK_URL }}"
|