Supply-chain scanning in the CI pipeline (Trivy/Grype + Gitleaks) #29

Open
opened 2026-08-19 02:25:09 +00:00 by itguyeric · 0 comments
Owner

Add security gates to the Forgejo Actions pipeline. Scan every built bootc image for known CVEs with Trivy or Grype, and scan the repos for committed secrets with Gitleaks. Optionally sign images with cosign so deploys can verify provenance.

Slots in as post-build steps, report-only at first, then promoted to hard gates once the baseline is clean. Good hardening for the fleet and a strong talk and portfolio story for the DevRel side.

Add security gates to the Forgejo Actions pipeline. Scan every built bootc image for known CVEs with Trivy or Grype, and scan the repos for committed secrets with Gitleaks. Optionally sign images with cosign so deploys can verify provenance. Slots in as post-build steps, report-only at first, then promoted to hard gates once the baseline is clean. Good hardening for the fleet and a strong talk and portfolio story for the DevRel side.
itguyeric added this to the Homelab project 2026-08-19 02:25:09 +00:00
Sign in to join this conversation.
No description provided.