# The contents of this file are subject to the terms of the Common Development and # Distribution License (the License). You may not use this file except in compliance with the # License. # # You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the # specific language governing permission and limitations under the License. # # When distributing Covered Software, include this CDDL Header Notice in each file and include # the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL # Header, with the fields enclosed by brackets [] replaced by your own identifying # information: "Portions copyright [year] [name of copyright owner]". # # Copyright 2026 3A Systems, LLC. # Scans the published Docker images for known vulnerabilities: new CVEs surface in # already-released images (mostly via the base image), without any change in this repository. name: Docker Scan on: schedule: - cron: '30 5 * * 1' workflow_dispatch: permissions: contents: read jobs: scan: # Do not run the scheduled scan in forks; manual runs are always allowed. if: github.event_name == 'workflow_dispatch' || github.repository == 'OpenIdentityPlatform/OpenDJ' runs-on: ubuntu-latest permissions: contents: read security-events: write strategy: fail-fast: false matrix: tag: [ 'latest', 'alpine' ] steps: - uses: actions/checkout@v6 - name: Scan openidentityplatform/opendj:${{ matrix.tag }} (Trivy) # unlike the build.yml gate, unfixed CVEs are reported too: surfacing them in # already-released images is the point of this workflow uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 with: image-ref: openidentityplatform/opendj:${{ matrix.tag }} format: sarif output: trivy-${{ matrix.tag }}.sarif severity: CRITICAL,HIGH limit-severities-for-sarif: true scanners: vuln cache: false - name: Upload report to GitHub Security uses: github/codeql-action/upload-sarif@v4 # upload even if a preceding step failed, but not without a report to upload if: ${{ always() && hashFiles(format('trivy-{0}.sarif', matrix.tag)) != '' }} with: sarif_file: trivy-${{ matrix.tag }}.sarif category: trivy-image-${{ matrix.tag }}