Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 3478f540 authored by Arnau Vàzquez's avatar Arnau Vàzquez
Browse files

Merge branch 'dev/container-vuln-scan' into 'master'

container vulnerability scaner

See merge request e/documentation/user!659
parents 1cca0638 f96072f9
Loading
Loading
Loading
Loading
+26 −1
Original line number Diff line number Diff line
@@ -5,6 +5,7 @@ variables:
stages:
  - deep-build
  - build
  - scan
  - deploy
default:
  image: docker:20.10
@@ -69,6 +70,30 @@ build:branch:
  variables:
    IMAGE_TAG: $CI_COMMIT_REF_SLUG

include:
  - template: Container-Scanning.gitlab-ci.yml

container_scanning:
  stage: scan
  variables:
    SECURE_LOG_LEVEL: 'debug'
    DOCKER_IMAGE: $CI_REGISTRY_IMAGE:$CI_COMMIT_REF_SLUG

jekyll_container_scanner:
  extends: container_scanning
  variables:
    DOCKER_IMAGE: $CI_REGISTRY_IMAGE/jekyll:$CI_COMMIT_REF_SLUG

nginx_container_scanner:
  extends: container_scanning
  variables:
    DOCKER_IMAGE: $CI_REGISTRY_IMAGE/nginx:$CI_COMMIT_REF_SLUG

ubuntu_container_scanner:
  extends: container_scanning
  variables:
    DOCKER_IMAGE: $CI_REGISTRY_IMAGE/ubuntu:$CI_COMMIT_REF_SLUG

# Deploy stage
.deploy:compose:
  stage: deploy