CCM-13343: Trivy Package and Library Scans #2144
cicd-1-pull-request.yaml
on: push
Set CI/CD metadata
6s
Commit stage
/
Scan secrets
10s
Commit stage
/
Check file format
6s
Commit stage
/
Check Markdown format
4s
Commit stage
/
Check English usage
10s
Commit stage
/
Check TODO usage
5s
Commit stage
/
Trivy Package Scan
56s
Commit stage
/
Count lines of code
8s
Commit stage
/
Scan dependencies
29s
Commit stage
/
Check for changes to event schema package compared to main branch
6s
Commit stage
/
Check event schema version has been updated
0s
Commit stage
/
Check for event schemas package version change
0s
Commit stage
/
Run terraform-docs
0s
Commit stage
/
Lint Terraform
0s
Commit stage
/
Trivy IaC Scan
0s
Test stage
/
Check generated dependencies
Test stage
/
Linting
Test stage
/
Pact tests
Test stage
/
Typecheck
Test stage
/
Perform static analysis
Test stage
/
Test coverage
Publish stage
/
Publish npm packages to npm.pkg.github.com
Publish stage
/
Publish nuget packages to nuget.pkg.github.com
Publish stage
/
Success notification
Annotations
1 error
|
Commit stage / Trivy Package Scan
Process completed with exit code 2.
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
lines-of-code-report.json.zip
|
1002 Bytes |
sha256:6a9a03a31c51db2a3ce85d3a62a97c3c8963d7c086596c3f122ab514c575be06
|
|
|
sbom-repository-report.json.zip
|
237 KB |
sha256:012eeeadfabf4d38dfe18b6d76af137be5a5787725dd04aef8aaaaa3502c083a
|
|
|
vulnerabilities-repository-report.json.zip
|
2.27 KB |
sha256:9adae29788e336c736541933282b1e59edeaaad676de00e305e115f483cf94e2
|
|