From 4616c9f6a1d899717ec60b58149ef9fdba4f8ef7 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 11 Aug 2026 14:00:17 +0200 Subject: [PATCH 01/22] Add reusable SBOM vulnerability workflow --- .github/workflows/sbom-vulnerability-scan.yml | 45 +++++++++++++++++++ 1 file changed, 45 insertions(+) create mode 100644 .github/workflows/sbom-vulnerability-scan.yml diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml new file mode 100644 index 0000000..56a5edf --- /dev/null +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -0,0 +1,45 @@ +name: SBOM Vulnerability Scan + +on: + workflow_call: + inputs: + dockerfile: + description: "Path to the Dockerfile" + required: true + type: string + image: + description: "Name of the locally built Docker image" + required: false + default: "localbuild/testimage:latest" + type: string + fail-build: + description: "Fail the workflow when vulnerabilities above the severity cutoff are found" + required: false + default: false + type: boolean + +jobs: + sbom-vulnerability-scan: + runs-on: ubuntu-latest + + steps: + - name: Checkout the code + uses: actions/checkout@v7 + + - name: Build the Docker image + run: docker build . --file "${{ inputs.dockerfile }}" --tag "${{ inputs.image }}" + + - name: Generate SBOM and upload dependency results + uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + with: + image: "${{ inputs.image }}" + artifact-name: image.cyclonedx.json + output-file: image.cyclonedx.json + format: cyclonedx-json + + - name: Scan SBOM for vulnerabilities + uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + with: + sbom: image.cyclonedx.json + fail-build: ${{ inputs.fail-build }} + output-format: table \ No newline at end of file From 803d0dd8a06cbd591b15edb689addfcbe387e065 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 11 Aug 2026 15:02:03 +0200 Subject: [PATCH 02/22] Add SBOM workflow documentation --- README.md | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/README.md b/README.md index deaa8ce..860edf9 100644 --- a/README.md +++ b/README.md @@ -172,6 +172,35 @@ jobs: secrets: PYPI_PASSWORD: ${{ secrets.PYPI_API_TOKEN }} ``` +## SBOM Vulnerability Scan +The SBOM vulnerability scan workflow builds a Docker image, generates a +CycloneDX SBOM with Syft and scans the generated SBOM for known +vulnerabilities with Grype. +You can use it e.g. like this: +```yaml +name: SBOM Vulnerability Scan + +on: + push: + branches: [ main ] + +jobs: + sbom-scan: + uses: mundialis/github-workflows/.github/workflows/sbom-vulnerability-scan.yml@main + with: + dockerfile: docker/actinia-core-alpine/Dockerfile + +``` +For reuse, the `dockerfile` input must be adapted to the path of the Dockerfile +in the calling repository. + +Optional inputs: + +- `image`: Name and tag of the locally built Docker image. Default: `localbuild/testimage:latest`. +- `fail-build`: Set to `true` if the workflow should fail when vulnerabilities above the severity +cutoff are found. Default: `false`. + +The generated SBOM is uploaded as `image.cyclonedx.json`. # pre-commit From 5027c8f1a8575731f90ea121c5e85231d4cdcbf9 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Mon, 17 Aug 2026 14:33:16 +0200 Subject: [PATCH 03/22] Upload vulnerability results to code scanning --- .github/workflows/sbom-vulnerability-scan.yml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 56a5edf..8359031 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -38,8 +38,13 @@ jobs: format: cyclonedx-json - name: Scan SBOM for vulnerabilities + id: vulnerability-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: sbom: image.cyclonedx.json fail-build: ${{ inputs.fail-build }} - output-format: table \ No newline at end of file + output-format: sarif + - name: Upload vulnerability results to GitHub Security + uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 + with: + sarif_file: ${{ steps.vulnerability-scan.outputs.sarif }} \ No newline at end of file From 078ce33facd9b9eb4e9217140f203790e5221bcd Mon Sep 17 00:00:00 2001 From: TaniaG Date: Mon, 17 Aug 2026 14:39:40 +0200 Subject: [PATCH 04/22] Retest reusable SBOM workflow From fa2175d1a8fce2dc66b9cdfb48ab4ac4640ae2c2 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Mon, 17 Aug 2026 15:11:25 +0200 Subject: [PATCH 05/22] update readme SBOM vulnerability scan --- README.md | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 860edf9..cb1a2ed 100644 --- a/README.md +++ b/README.md @@ -174,9 +174,11 @@ jobs: ``` ## SBOM Vulnerability Scan The SBOM vulnerability scan workflow builds a Docker image, generates a -CycloneDX SBOM with Syft and scans the generated SBOM for known -vulnerabilities with Grype. +CycloneDX SBOM with Syft, scans the generated SBOM for known vulnerabilities +with Grype, and uploads the vulnerability results to GitHub Code Scanning. + You can use it e.g. like this: + ```yaml name: SBOM Vulnerability Scan @@ -186,6 +188,10 @@ on: jobs: sbom-scan: + permissions: + contents: read + security-events: write + uses: mundialis/github-workflows/.github/workflows/sbom-vulnerability-scan.yml@main with: dockerfile: docker/actinia-core-alpine/Dockerfile @@ -194,6 +200,11 @@ jobs: For reuse, the `dockerfile` input must be adapted to the path of the Dockerfile in the calling repository. +The calling job requires the following permissions: + +- `contents: read` to check out the repository. +- `security-events: write` to upload the vulnerability results to GitHub Code Scanning. + Optional inputs: - `image`: Name and tag of the locally built Docker image. Default: `localbuild/testimage:latest`. @@ -202,6 +213,8 @@ cutoff are found. Default: `false`. The generated SBOM is uploaded as `image.cyclonedx.json`. +The vulnerability results are available under **Security and quality** → **Code scanning**. + # pre-commit ## Python Linting From 9103001c7be70a03a55ff6f9d73dd521f3a353b6 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 1 Sep 2026 10:08:57 +0200 Subject: [PATCH 06/22] Support Dockerfile and requirements inputs --- .github/workflows/sbom-vulnerability-scan.yml | 34 +++++++++++++++++-- 1 file changed, 32 insertions(+), 2 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 8359031..222d45e 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -5,7 +5,11 @@ on: inputs: dockerfile: description: "Path to the Dockerfile" - required: true + required: false + type: string + requirements: + description: "Path to the requirements.txt file" + required: false type: string image: description: "Name of the locally built Docker image" @@ -23,13 +27,27 @@ jobs: runs-on: ubuntu-latest steps: + - name: Validate inputs + run: | + if [ -n "${{ inputs.dockerfile }}" ] && [ -n "${{ inputs.requirements }}" ]; then + echo "Provide either a Dockerfile path or a requirements.txt path, no both." + exit 1 + fi + + if [ -z "${{ inputs.dockerfile }}" ] && [ -z "${{ inputs.requirements }}" ]; then + echo "Provide either a Dockerfile path or a requirements.txt path." + exit 1 + fi + - name: Checkout the code uses: actions/checkout@v7 - name: Build the Docker image + if: inputs.dockerfile != '' run: docker build . --file "${{ inputs.dockerfile }}" --tag "${{ inputs.image }}" - - name: Generate SBOM and upload dependency results + - name: Generate SBOM from Docker image + if: inputs.dockerfile != '' uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 with: image: "${{ inputs.image }}" @@ -37,6 +55,18 @@ jobs: output-file: image.cyclonedx.json format: cyclonedx-json + - name: Create Python environment + if: inputs.requirements != '' + run: | + python -m venv .venv + .venv/bin/pip install -r "${{ inputs.requirements }}" + + - name: Generate SBOM from Python environment + if: inputs.requirements != '' + run: | + .venv/bin/pip install cyclonedx-bom + .venv/bin/cyclonedx-py venv .venv -o image.cyclonedx.json + - name: Scan SBOM for vulnerabilities id: vulnerability-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 From feb6193638103849b535555c90b5f07ec2d7fd80 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 1 Sep 2026 11:29:59 +0200 Subject: [PATCH 07/22] inspect sarif locations --- .github/workflows/sbom-vulnerability-scan.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 222d45e..59e5a2d 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -74,6 +74,13 @@ jobs: sbom: image.cyclonedx.json fail-build: ${{ inputs.fail-build }} output-format: sarif + + - name: Inspect SARIF locations + if: inputs.requirements != '' + run: | + echo "SARIF file: ${{ steps.vulnerability-scan.outputs.sarif }}" + jq '.runs[].results[].locations' "${{ steps.vulnerability-scan.outputs.sarif }}" + - name: Upload vulnerability results to GitHub Security uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: From ddefbbeac3ac613a63c2b21a7757df85d4df0c8f Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 1 Sep 2026 12:07:59 +0200 Subject: [PATCH 08/22] Fix SARIF locations for requirements scan --- .github/workflows/sbom-vulnerability-scan.yml | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 59e5a2d..9f081a5 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -75,11 +75,15 @@ jobs: fail-build: ${{ inputs.fail-build }} output-format: sarif - - name: Inspect SARIF locations + - name: Add SARIF locations for requirements scan if: inputs.requirements != '' run: | - echo "SARIF file: ${{ steps.vulnerability-scan.outputs.sarif }}" - jq '.runs[].results[].locations' "${{ steps.vulnerability-scan.outputs.sarif }}" + jq --arg requirements "${{ inputs.requirements }}" \ + '(.runs[].results[].locations[].physicalLocation.artifactLocation.uri | select(. == "")) = $requirements' \ + "${{ steps.vulnerability-scan.outputs.sarif }}" \ + > fixed.sarif + + mv fixed.sarif "${{ steps.vulnerability-scan.outputs.sarif }}" - name: Upload vulnerability results to GitHub Security uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 From 350d2fa6e56063f02fe8283fa83df3f6fbe1fc2a Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 1 Sep 2026 13:49:56 +0200 Subject: [PATCH 09/22] test python vulnerability scan --- .github/workflows/sbom-vulnerability-scan.yml | 37 ++++++++++++------- 1 file changed, 24 insertions(+), 13 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 9f081a5..1a988ea 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -7,15 +7,18 @@ on: description: "Path to the Dockerfile" required: false type: string + requirements: description: "Path to the requirements.txt file" required: false type: string + image: description: "Name of the locally built Docker image" required: false default: "localbuild/testimage:latest" type: string + fail-build: description: "Fail the workflow when vulnerabilities above the severity cutoff are found" required: false @@ -30,7 +33,7 @@ jobs: - name: Validate inputs run: | if [ -n "${{ inputs.dockerfile }}" ] && [ -n "${{ inputs.requirements }}" ]; then - echo "Provide either a Dockerfile path or a requirements.txt path, no both." + echo "Provide either a Dockerfile path or a requirements.txt path, not both." exit 1 fi @@ -67,25 +70,33 @@ jobs: .venv/bin/pip install cyclonedx-bom .venv/bin/cyclonedx-py venv .venv -o image.cyclonedx.json - - name: Scan SBOM for vulnerabilities - id: vulnerability-scan + - name: Scan Docker SBOM for vulnerabilities + if: inputs.dockerfile != '' + id: docker-vulnerability-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: sbom: image.cyclonedx.json fail-build: ${{ inputs.fail-build }} output-format: sarif - - - name: Add SARIF locations for requirements scan + + - name: Scan Python environment for vulnerabilities if: inputs.requirements != '' - run: | - jq --arg requirements "${{ inputs.requirements }}" \ - '(.runs[].results[].locations[].physicalLocation.artifactLocation.uri | select(. == "")) = $requirements' \ - "${{ steps.vulnerability-scan.outputs.sarif }}" \ - > fixed.sarif + id: requirements-vulnerability-scan + uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + with: + path: .venv + fail-build: ${{ inputs.fail-build }} + output-format: sarif - mv fixed.sarif "${{ steps.vulnerability-scan.outputs.sarif }}" + - name: Inspect Python SARIF locations + if: inputs.requirements != '' + run: | + echo "SARIF file: ${{ steps.requirements-vulnerability-scan.outputs.sarif }}" + jq '.runs[].results[].locations' \ + "${{ steps.requirements-vulnerability-scan.outputs.sarif }}" - - name: Upload vulnerability results to GitHub Security + - name: Upload Docker vulnerability results to GitHub Security + if: inputs.dockerfile != '' uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: - sarif_file: ${{ steps.vulnerability-scan.outputs.sarif }} \ No newline at end of file + sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }} \ No newline at end of file From 6ad5113dfd50a7df484ab26c4b4036528b34a9b7 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 1 Sep 2026 14:02:02 +0200 Subject: [PATCH 10/22] upload python vulnerability results to code scanning --- .github/workflows/sbom-vulnerability-scan.yml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 1a988ea..1a4b33a 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -88,15 +88,15 @@ jobs: fail-build: ${{ inputs.fail-build }} output-format: sarif - - name: Inspect Python SARIF locations - if: inputs.requirements != '' - run: | - echo "SARIF file: ${{ steps.requirements-vulnerability-scan.outputs.sarif }}" - jq '.runs[].results[].locations' \ - "${{ steps.requirements-vulnerability-scan.outputs.sarif }}" - - name: Upload Docker vulnerability results to GitHub Security if: inputs.dockerfile != '' uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: - sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }} \ No newline at end of file + sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }} + + - name: Upload Python vulnerability results to GitHub Security + if: inputs.requirements != '' + uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 + with: + sarif_file: ${{ steps.requirements-vulnerability-scan.outputs.sarif }} + \ No newline at end of file From 2f9c2a5d6b92458f93ec4a769997c3c39ff23ea5 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 1 Sep 2026 14:24:03 +0200 Subject: [PATCH 11/22] add categories to vulnerabilities --- .github/workflows/sbom-vulnerability-scan.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 1a4b33a..1720b67 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -93,10 +93,12 @@ jobs: uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }} + category: grype-docker - name: Upload Python vulnerability results to GitHub Security if: inputs.requirements != '' uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: sarif_file: ${{ steps.requirements-vulnerability-scan.outputs.sarif }} + category: grype-requirements \ No newline at end of file From fdd42dedf93245130094638839d452fe295ecbbb Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 1 Sep 2026 14:40:15 +0200 Subject: [PATCH 12/22] add requirements-based SBOM and vulnerability scanning --- .github/workflows/sbom-vulnerability-scan.yml | 18 ++++++++++-------- 1 file changed, 10 insertions(+), 8 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 1720b67..02243ac 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -54,8 +54,8 @@ jobs: uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 with: image: "${{ inputs.image }}" - artifact-name: image.cyclonedx.json - output-file: image.cyclonedx.json + artifact-name: docker.cyclonedx.json + output-file: docker.cyclonedx.json format: cyclonedx-json - name: Create Python environment @@ -66,16 +66,19 @@ jobs: - name: Generate SBOM from Python environment if: inputs.requirements != '' - run: | - .venv/bin/pip install cyclonedx-bom - .venv/bin/cyclonedx-py venv .venv -o image.cyclonedx.json + uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + with: + path: .venv + artifact-name: python.cyclonedx.json + output-file: python.cyclonedx.json + format: cyclonedx-json - name: Scan Docker SBOM for vulnerabilities if: inputs.dockerfile != '' id: docker-vulnerability-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: - sbom: image.cyclonedx.json + sbom: docker.cyclonedx.json fail-build: ${{ inputs.fail-build }} output-format: sarif @@ -100,5 +103,4 @@ jobs: uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: sarif_file: ${{ steps.requirements-vulnerability-scan.outputs.sarif }} - category: grype-requirements - \ No newline at end of file + category: grype-requirements \ No newline at end of file From 0bd15eea7676bdb5a2be091d08de4419f0db8604 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 1 Sep 2026 16:21:36 +0200 Subject: [PATCH 13/22] Update SBOM workflow documentation --- README.md | 22 ++++++++++++++-------- 1 file changed, 14 insertions(+), 8 deletions(-) diff --git a/README.md b/README.md index cb1a2ed..ef5f1a6 100644 --- a/README.md +++ b/README.md @@ -173,9 +173,12 @@ jobs: PYPI_PASSWORD: ${{ secrets.PYPI_API_TOKEN }} ``` ## SBOM Vulnerability Scan -The SBOM vulnerability scan workflow builds a Docker image, generates a -CycloneDX SBOM with Syft, scans the generated SBOM for known vulnerabilities -with Grype, and uploads the vulnerability results to GitHub Code Scanning. + +The SBOM vulnerability scan workflow generates a CycloneDX SBOM and scans +dependencies for known vulnerabilities with Grype. The workflow can be used +with either a Dockerfile or a `requirements.txt` file. + +The vulnerability results are uploaded to GitHub Code Scanning. You can use it e.g. like this: @@ -184,7 +187,7 @@ name: SBOM Vulnerability Scan on: push: - branches: [ main ] + branches: [main] jobs: sbom-scan: @@ -195,10 +198,13 @@ jobs: uses: mundialis/github-workflows/.github/workflows/sbom-vulnerability-scan.yml@main with: dockerfile: docker/actinia-core-alpine/Dockerfile - + # requirements: requirements.txt ``` -For reuse, the `dockerfile` input must be adapted to the path of the Dockerfile -in the calling repository. + +Provide exactly one of the following inputs: + +- `dockerfile`: Path to the Dockerfile. +- `requirements`: Path to the requirements.txt file. The calling job requires the following permissions: @@ -211,7 +217,7 @@ Optional inputs: - `fail-build`: Set to `true` if the workflow should fail when vulnerabilities above the severity cutoff are found. Default: `false`. -The generated SBOM is uploaded as `image.cyclonedx.json`. +The generated SBOM is uploaded as workflow artifact. The vulnerability results are available under **Security and quality** → **Code scanning**. From 86b74467ccacb8dbcbf5706d10b6f5b4f967cb4b Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 1 Sep 2026 16:24:19 +0200 Subject: [PATCH 14/22] update SBOM documentation --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index ef5f1a6..2d49d6b 100644 --- a/README.md +++ b/README.md @@ -187,7 +187,7 @@ name: SBOM Vulnerability Scan on: push: - branches: [main] + branches: [ "main" ] jobs: sbom-scan: From 22c00df520cea4a19dba022e4398820da2bdd8b9 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 8 Sep 2026 10:22:33 +0200 Subject: [PATCH 15/22] Compare Grype scan sources --- .github/workflows/sbom-vulnerability-scan.yml | 123 +++++++++++++++--- 1 file changed, 103 insertions(+), 20 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 02243ac..5f09a65 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -45,6 +45,17 @@ jobs: - name: Checkout the code uses: actions/checkout@v7 + # Scan the repository before creating .venv so that the Python + # environment does not influence the plain repository scan. + - name: Scan repository directly with Grype + id: code-scan + uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + with: + path: . + fail-build: false + output-format: json + + # Docker case - name: Build the Docker image if: inputs.dockerfile != '' run: docker build . --file "${{ inputs.dockerfile }}" --tag "${{ inputs.image }}" @@ -58,6 +69,25 @@ jobs: output-file: docker.cyclonedx.json format: cyclonedx-json + - name: Scan Docker SBOM with Grype + if: inputs.dockerfile != '' + id: docker-sbom-scan + uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + with: + sbom: docker.cyclonedx.json + fail-build: false + output-format: json + + - name: Scan Docker image directly with Grype + if: inputs.dockerfile != '' + id: docker-image-scan + uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + with: + image: "${{ inputs.image }}" + fail-build: false + output-format: json + + # Python case - name: Create Python environment if: inputs.requirements != '' run: | @@ -73,34 +103,87 @@ jobs: output-file: python.cyclonedx.json format: cyclonedx-json - - name: Scan Docker SBOM for vulnerabilities - if: inputs.dockerfile != '' - id: docker-vulnerability-scan + - name: Scan Python SBOM with Grype + if: inputs.requirements != '' + id: python-sbom-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: - sbom: docker.cyclonedx.json - fail-build: ${{ inputs.fail-build }} - output-format: sarif + sbom: python.cyclonedx.json + fail-build: false + output-format: json - - name: Scan Python environment for vulnerabilities + - name: Scan Python environment directly with Grype if: inputs.requirements != '' - id: requirements-vulnerability-scan + id: python-venv-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: path: .venv - fail-build: ${{ inputs.fail-build }} - output-format: sarif + fail-build: false + output-format: json - - name: Upload Docker vulnerability results to GitHub Security + # Manual comparison + - name: Compare Docker scan results if: inputs.dockerfile != '' - uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 - with: - sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }} - category: grype-docker + run: | + echo "=== Number of vulnerability matches ===" + echo "Docker SBOM:" + jq '.matches | length' "${{ steps.docker-sbom-scan.outputs.json }}" - - name: Upload Python vulnerability results to GitHub Security + echo "Docker image:" + jq '.matches | length' "${{ steps.docker-image-scan.outputs.json }}" + + echo "Repository:" + jq '.matches | length' "${{ steps.code-scan.outputs.json }}" + + echo + echo "=== Unique vulnerability IDs ===" + + jq -r '.matches[].vulnerability.id' \ + "${{ steps.docker-sbom-scan.outputs.json }}" | sort -u > /tmp/docker-sbom-cves.txt + + jq -r '.matches[].vulnerability.id' \ + "${{ steps.docker-image-scan.outputs.json }}" | sort -u > /tmp/docker-image-cves.txt + + jq -r '.matches[].vulnerability.id' \ + "${{ steps.code-scan.outputs.json }}" | sort -u > /tmp/code-cves.txt + + echo + echo "--- Docker SBOM vs Docker image ---" + diff -u /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt || true + + echo + echo "--- Docker SBOM vs repository ---" + diff -u /tmp/docker-sbom-cves.txt /tmp/code-cves.txt || true + + - name: Compare Python scan results if: inputs.requirements != '' - uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 - with: - sarif_file: ${{ steps.requirements-vulnerability-scan.outputs.sarif }} - category: grype-requirements \ No newline at end of file + run: | + echo "=== Number of vulnerability matches ===" + echo "Python SBOM:" + jq '.matches | length' "${{ steps.python-sbom-scan.outputs.json }}" + + echo "Python environment:" + jq '.matches | length' "${{ steps.python-venv-scan.outputs.json }}" + + echo "Repository:" + jq '.matches | length' "${{ steps.code-scan.outputs.json }}" + + echo + echo "=== Unique vulnerability IDs ===" + + jq -r '.matches[].vulnerability.id' \ + "${{ steps.python-sbom-scan.outputs.json }}" | sort -u > /tmp/python-sbom-cves.txt + + jq -r '.matches[].vulnerability.id' \ + "${{ steps.python-venv-scan.outputs.json }}" | sort -u > /tmp/python-venv-cves.txt + + jq -r '.matches[].vulnerability.id' \ + "${{ steps.code-scan.outputs.json }}" | sort -u > /tmp/code-cves.txt + + echo + echo "--- Python SBOM vs Python environment ---" + diff -u /tmp/python-sbom-cves.txt /tmp/python-venv-cves.txt || true + + echo + echo "--- Python environment vs repository ---" + diff -u /tmp/python-venv-cves.txt /tmp/code-cves.txt || true \ No newline at end of file From c82350ae70e424a7315e6ab9ab2274c666c341d1 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 8 Sep 2026 10:39:18 +0200 Subject: [PATCH 16/22] Summarize Docker scan comparison results --- .github/workflows/sbom-vulnerability-scan.yml | 28 +++++++++++++------ 1 file changed, 20 insertions(+), 8 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 5f09a65..4d5c69f 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -125,7 +125,7 @@ jobs: - name: Compare Docker scan results if: inputs.dockerfile != '' run: | - echo "=== Number of vulnerability matches ===" + echo "=== Vulnerability matches ===" echo "Docker SBOM:" jq '.matches | length' "${{ steps.docker-sbom-scan.outputs.json }}" @@ -135,9 +135,6 @@ jobs: echo "Repository:" jq '.matches | length' "${{ steps.code-scan.outputs.json }}" - echo - echo "=== Unique vulnerability IDs ===" - jq -r '.matches[].vulnerability.id' \ "${{ steps.docker-sbom-scan.outputs.json }}" | sort -u > /tmp/docker-sbom-cves.txt @@ -148,12 +145,27 @@ jobs: "${{ steps.code-scan.outputs.json }}" | sort -u > /tmp/code-cves.txt echo - echo "--- Docker SBOM vs Docker image ---" - diff -u /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt || true + echo "=== Unique vulnerability IDs ===" + echo "Docker SBOM:" + wc -l < /tmp/docker-sbom-cves.txt + + echo "Docker image:" + wc -l < /tmp/docker-image-cves.txt + + echo "Repository:" + wc -l < /tmp/code-cves.txt echo - echo "--- Docker SBOM vs repository ---" - diff -u /tmp/docker-sbom-cves.txt /tmp/code-cves.txt || true + echo "=== Docker SBOM vs Docker image ===" + + echo "Only in Docker SBOM:" + comm -23 /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt | wc -l + + echo "Only in Docker image:" + comm -13 /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt | wc -l + + echo "Found by both:" + comm -12 /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt | wc -l - name: Compare Python scan results if: inputs.requirements != '' From 7cacccdfc1f25079133d65ca9b3f03233a8a384a Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 8 Sep 2026 10:49:04 +0200 Subject: [PATCH 17/22] specific vulnerabilities --- .github/workflows/sbom-vulnerability-scan.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 4d5c69f..16d2130 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -167,6 +167,10 @@ jobs: echo "Found by both:" comm -12 /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt | wc -l + echo + echo "=== Vulnerabilities only found in Docker SBOM ===" + comm -23 /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt + - name: Compare Python scan results if: inputs.requirements != '' run: | From 824699684b9b249b43fd2fed87013fb1786901fb Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 8 Sep 2026 11:24:19 +0200 Subject: [PATCH 18/22] Propose SBOM vulnerability scan strategy --- .github/workflows/sbom-vulnerability-scan.yml | 135 +++--------------- 1 file changed, 19 insertions(+), 116 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 16d2130..b68aedc 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -45,17 +45,7 @@ jobs: - name: Checkout the code uses: actions/checkout@v7 - # Scan the repository before creating .venv so that the Python - # environment does not influence the plain repository scan. - - name: Scan repository directly with Grype - id: code-scan - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 - with: - path: . - fail-build: false - output-format: json - - # Docker case + # Docker - name: Build the Docker image if: inputs.dockerfile != '' run: docker build . --file "${{ inputs.dockerfile }}" --tag "${{ inputs.image }}" @@ -69,25 +59,23 @@ jobs: output-file: docker.cyclonedx.json format: cyclonedx-json - - name: Scan Docker SBOM with Grype + - name: Scan Docker SBOM for vulnerabilities if: inputs.dockerfile != '' - id: docker-sbom-scan + id: docker-vulnerability-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: sbom: docker.cyclonedx.json - fail-build: false - output-format: json + fail-build: ${{ inputs.fail-build }} + output-format: sarif - - name: Scan Docker image directly with Grype + - name: Upload Docker vulnerability results to GitHub Security if: inputs.dockerfile != '' - id: docker-image-scan - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: - image: "${{ inputs.image }}" - fail-build: false - output-format: json + sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }} + category: grype-docker - # Python case + # Python - name: Create Python environment if: inputs.requirements != '' run: | @@ -103,103 +91,18 @@ jobs: output-file: python.cyclonedx.json format: cyclonedx-json - - name: Scan Python SBOM with Grype - if: inputs.requirements != '' - id: python-sbom-scan - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 - with: - sbom: python.cyclonedx.json - fail-build: false - output-format: json - - - name: Scan Python environment directly with Grype + - name: Scan Python environment for vulnerabilities if: inputs.requirements != '' - id: python-venv-scan + id: requirements-vulnerability-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: path: .venv - fail-build: false - output-format: json - - # Manual comparison - - name: Compare Docker scan results - if: inputs.dockerfile != '' - run: | - echo "=== Vulnerability matches ===" - echo "Docker SBOM:" - jq '.matches | length' "${{ steps.docker-sbom-scan.outputs.json }}" - - echo "Docker image:" - jq '.matches | length' "${{ steps.docker-image-scan.outputs.json }}" - - echo "Repository:" - jq '.matches | length' "${{ steps.code-scan.outputs.json }}" - - jq -r '.matches[].vulnerability.id' \ - "${{ steps.docker-sbom-scan.outputs.json }}" | sort -u > /tmp/docker-sbom-cves.txt - - jq -r '.matches[].vulnerability.id' \ - "${{ steps.docker-image-scan.outputs.json }}" | sort -u > /tmp/docker-image-cves.txt - - jq -r '.matches[].vulnerability.id' \ - "${{ steps.code-scan.outputs.json }}" | sort -u > /tmp/code-cves.txt - - echo - echo "=== Unique vulnerability IDs ===" - echo "Docker SBOM:" - wc -l < /tmp/docker-sbom-cves.txt + fail-build: ${{ inputs.fail-build }} + output-format: sarif - echo "Docker image:" - wc -l < /tmp/docker-image-cves.txt - - echo "Repository:" - wc -l < /tmp/code-cves.txt - - echo - echo "=== Docker SBOM vs Docker image ===" - - echo "Only in Docker SBOM:" - comm -23 /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt | wc -l - - echo "Only in Docker image:" - comm -13 /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt | wc -l - - echo "Found by both:" - comm -12 /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt | wc -l - - echo - echo "=== Vulnerabilities only found in Docker SBOM ===" - comm -23 /tmp/docker-sbom-cves.txt /tmp/docker-image-cves.txt - - - name: Compare Python scan results + - name: Upload Python vulnerability results to GitHub Security if: inputs.requirements != '' - run: | - echo "=== Number of vulnerability matches ===" - echo "Python SBOM:" - jq '.matches | length' "${{ steps.python-sbom-scan.outputs.json }}" - - echo "Python environment:" - jq '.matches | length' "${{ steps.python-venv-scan.outputs.json }}" - - echo "Repository:" - jq '.matches | length' "${{ steps.code-scan.outputs.json }}" - - echo - echo "=== Unique vulnerability IDs ===" - - jq -r '.matches[].vulnerability.id' \ - "${{ steps.python-sbom-scan.outputs.json }}" | sort -u > /tmp/python-sbom-cves.txt - - jq -r '.matches[].vulnerability.id' \ - "${{ steps.python-venv-scan.outputs.json }}" | sort -u > /tmp/python-venv-cves.txt - - jq -r '.matches[].vulnerability.id' \ - "${{ steps.code-scan.outputs.json }}" | sort -u > /tmp/code-cves.txt - - echo - echo "--- Python SBOM vs Python environment ---" - diff -u /tmp/python-sbom-cves.txt /tmp/python-venv-cves.txt || true - - echo - echo "--- Python environment vs repository ---" - diff -u /tmp/python-venv-cves.txt /tmp/code-cves.txt || true \ No newline at end of file + uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 + with: + sarif_file: ${{ steps.requirements-vulnerability-scan.outputs.sarif }} + category: grype-requirements \ No newline at end of file From 89a321f5b5d23d6120a36e3112a607e23f41a508 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 8 Sep 2026 12:19:28 +0200 Subject: [PATCH 19/22] Support pyproject.toml for Python scans --- .github/workflows/sbom-vulnerability-scan.yml | 36 ++++++++++++------- 1 file changed, 24 insertions(+), 12 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index b68aedc..74dcd6b 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -13,6 +13,11 @@ on: required: false type: string + pyproject: + description: "Path to the pyproject.toml file" + required: false + type: string + image: description: "Name of the locally built Docker image" required: false @@ -32,13 +37,14 @@ jobs: steps: - name: Validate inputs run: | - if [ -n "${{ inputs.dockerfile }}" ] && [ -n "${{ inputs.requirements }}" ]; then - echo "Provide either a Dockerfile path or a requirements.txt path, not both." - exit 1 - fi + count=0 + + [ -n "${{ inputs.dockerfile }}" ] && count=$((count + 1)) + [ -n "${{ inputs.requirements }}" ] && count=$((count + 1)) + [ -n "${{ inputs.pyproject }}" ] && count=$((count + 1)) - if [ -z "${{ inputs.dockerfile }}" ] && [ -z "${{ inputs.requirements }}" ]; then - echo "Provide either a Dockerfile path or a requirements.txt path." + if [ "$count" -ne 1 ]; then + echo "Provide exactly one of: dockerfile, requirements, or pyproject." exit 1 fi @@ -76,14 +82,20 @@ jobs: category: grype-docker # Python - - name: Create Python environment + - name: Create Python environment from requirements if: inputs.requirements != '' run: | python -m venv .venv .venv/bin/pip install -r "${{ inputs.requirements }}" + - name: Create Python environment from pyproject + if: inputs.pyproject != '' + run: | + python -m venv .venv + .venv/bin/pip install . + - name: Generate SBOM from Python environment - if: inputs.requirements != '' + if: inputs.requirements != '' || inputs.pyproject != '' uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 with: path: .venv @@ -92,8 +104,8 @@ jobs: format: cyclonedx-json - name: Scan Python environment for vulnerabilities - if: inputs.requirements != '' - id: requirements-vulnerability-scan + if: inputs.requirements != '' || inputs.pyproject != '' + id: python-vulnerability-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: path: .venv @@ -101,8 +113,8 @@ jobs: output-format: sarif - name: Upload Python vulnerability results to GitHub Security - if: inputs.requirements != '' + if: inputs.requirements != '' || inputs.pyproject != '' uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: - sarif_file: ${{ steps.requirements-vulnerability-scan.outputs.sarif }} + sarif_file: ${{ steps.python-vulnerability-scan.outputs.sarif }} category: grype-requirements \ No newline at end of file From 21cc82204d2f339de10d6430d464686bb8d6b047 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Tue, 8 Sep 2026 14:10:47 +0200 Subject: [PATCH 20/22] Document pyproject.toml support --- README.md | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 2d49d6b..32b331f 100644 --- a/README.md +++ b/README.md @@ -176,7 +176,12 @@ jobs: The SBOM vulnerability scan workflow generates a CycloneDX SBOM and scans dependencies for known vulnerabilities with Grype. The workflow can be used -with either a Dockerfile or a `requirements.txt` file. +with a Dockerfile, a `requirements.txt` file, or a `pyproject.toml` file. + +For Docker-based projects, Grype scans the SBOM generated from the Docker image. +For Python projects, a virtual environment is created from either +`requirements.txt` or `pyproject.toml`, and Grype scans the installed virtual +environment directly. The vulnerability results are uploaded to GitHub Code Scanning. @@ -199,12 +204,14 @@ jobs: with: dockerfile: docker/actinia-core-alpine/Dockerfile # requirements: requirements.txt + # pyproject: pyproject.toml ``` Provide exactly one of the following inputs: - `dockerfile`: Path to the Dockerfile. - `requirements`: Path to the requirements.txt file. +- `pyproject`: Path to the pyproject.toml file. The calling job requires the following permissions: @@ -217,7 +224,7 @@ Optional inputs: - `fail-build`: Set to `true` if the workflow should fail when vulnerabilities above the severity cutoff are found. Default: `false`. -The generated SBOM is uploaded as workflow artifact. +The generated SBOM is uploaded as a workflow artifact. The vulnerability results are available under **Security and quality** → **Code scanning**. From 31dc63df5b7a98292dbe130bf59c269f63e83062 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Wed, 9 Sep 2026 09:38:49 +0200 Subject: [PATCH 21/22] Make checkout fetch depth configurable --- .github/workflows/sbom-vulnerability-scan.yml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 74dcd6b..bec206b 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -3,6 +3,12 @@ name: SBOM Vulnerability Scan on: workflow_call: inputs: + fetch_depth: + description: "Number of commits to fetch. Use 0 to fetch the full history and tags." + required: false + type: number + default: 1 + dockerfile: description: "Path to the Dockerfile" required: false @@ -50,6 +56,8 @@ jobs: - name: Checkout the code uses: actions/checkout@v7 + with: + fetch-depth: ${{ inputs.fetch_depth }} # Docker - name: Build the Docker image From 4447cec54b8e51549ecf0f645721c953b8db0684 Mon Sep 17 00:00:00 2001 From: TaniaG Date: Wed, 9 Sep 2026 11:54:09 +0200 Subject: [PATCH 22/22] Refine SBOM scan configuration and documentation --- .github/workflows/sbom-vulnerability-scan.yml | 17 +++++++---------- README.md | 10 +++++----- 2 files changed, 12 insertions(+), 15 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index bec206b..687ffd1 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -24,12 +24,6 @@ on: required: false type: string - image: - description: "Name of the locally built Docker image" - required: false - default: "localbuild/testimage:latest" - type: string - fail-build: description: "Fail the workflow when vulnerabilities above the severity cutoff are found" required: false @@ -62,13 +56,13 @@ jobs: # Docker - name: Build the Docker image if: inputs.dockerfile != '' - run: docker build . --file "${{ inputs.dockerfile }}" --tag "${{ inputs.image }}" + run: docker build . --file "${{ inputs.dockerfile }}" --tag localbuild/testimage:latest - name: Generate SBOM from Docker image if: inputs.dockerfile != '' uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 with: - image: "${{ inputs.image }}" + image: localbuild/testimage:latest artifact-name: docker.cyclonedx.json output-file: docker.cyclonedx.json format: cyclonedx-json @@ -112,10 +106,13 @@ jobs: format: cyclonedx-json - name: Scan Python environment for vulnerabilities - if: inputs.requirements != '' || inputs.pyproject != '' + if: inputs.requirements != '' || inputs.pyproject != '' id: python-vulnerability-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: + # Scan the .venv directly instead of the generated SBOM because + # the SBOM scan produced empty SARIF artifact locations, while + # the direct .venv scan provides valid locations for GitHub Code Scanning. path: .venv fail-build: ${{ inputs.fail-build }} output-format: sarif @@ -125,4 +122,4 @@ jobs: uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: sarif_file: ${{ steps.python-vulnerability-scan.outputs.sarif }} - category: grype-requirements \ No newline at end of file + category: grype-python \ No newline at end of file diff --git a/README.md b/README.md index 32b331f..fa893ef 100644 --- a/README.md +++ b/README.md @@ -180,8 +180,9 @@ with a Dockerfile, a `requirements.txt` file, or a `pyproject.toml` file. For Docker-based projects, Grype scans the SBOM generated from the Docker image. For Python projects, a virtual environment is created from either -`requirements.txt` or `pyproject.toml`, and Grype scans the installed virtual -environment directly. +`requirements.txt` or `pyproject.toml`. Grype scans the virtual environment +directly because this provides valid SARIF artifact locations for GitHub Code +Scanning. The vulnerability results are uploaded to GitHub Code Scanning. @@ -219,12 +220,11 @@ The calling job requires the following permissions: - `security-events: write` to upload the vulnerability results to GitHub Code Scanning. Optional inputs: - -- `image`: Name and tag of the locally built Docker image. Default: `localbuild/testimage:latest`. +- `fetch_depth`: Number of commits to fetch during checkout. Use `0` to fetch the full history and tags. Default: `1`. - `fail-build`: Set to `true` if the workflow should fail when vulnerabilities above the severity cutoff are found. Default: `false`. -The generated SBOM is uploaded as a workflow artifact. +The generated Docker or Python SBOM is uploaded as a workflow artifact. The vulnerability results are available under **Security and quality** → **Code scanning**.