# The contents of this file are subject to the terms of the Common Development and
|
# Distribution License (the License). You may not use this file except in compliance with the
|
# License.
|
#
|
# You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the
|
# specific language governing permission and limitations under the License.
|
#
|
# When distributing Covered Software, include this CDDL Header Notice in each file and include
|
# the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL
|
# Header, with the fields enclosed by brackets [] replaced by your own identifying
|
# information: "Portions copyright [year] [name of copyright owner]".
|
#
|
# Copyright 2026 3A Systems, LLC.
|
|
# Scans the published Docker images for known vulnerabilities: new CVEs surface in
|
# already-released images (mostly via the base image), without any change in this repository.
|
name: Docker Scan
|
|
on:
|
schedule:
|
- cron: '30 5 * * 1'
|
workflow_dispatch:
|
|
permissions:
|
contents: read
|
|
jobs:
|
scan:
|
# Do not run the scheduled scan in forks; manual runs are always allowed.
|
if: github.event_name == 'workflow_dispatch' || github.repository == 'OpenIdentityPlatform/OpenDJ'
|
runs-on: ubuntu-latest
|
permissions:
|
contents: read
|
security-events: write
|
strategy:
|
fail-fast: false
|
matrix:
|
tag: [ 'latest', 'alpine' ]
|
steps:
|
- uses: actions/checkout@v6
|
- name: Scan openidentityplatform/opendj:${{ matrix.tag }} (Trivy)
|
# unlike the build.yml gate, unfixed CVEs are reported too: surfacing them in
|
# already-released images is the point of this workflow
|
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
|
with:
|
image-ref: openidentityplatform/opendj:${{ matrix.tag }}
|
format: sarif
|
output: trivy-${{ matrix.tag }}.sarif
|
severity: CRITICAL,HIGH
|
limit-severities-for-sarif: true
|
scanners: vuln
|
cache: false
|
- name: Upload report to GitHub Security
|
uses: github/codeql-action/upload-sarif@v4
|
# upload even if a preceding step failed, but not without a report to upload
|
if: ${{ always() && hashFiles(format('trivy-{0}.sarif', matrix.tag)) != '' }}
|
with:
|
sarif_file: trivy-${{ matrix.tag }}.sarif
|
category: trivy-image-${{ matrix.tag }}
|