Skip to content
Snippets Groups Projects
Commit cf051139 authored by Nicole Lu's avatar Nicole Lu
Browse files

update ci file and readme

parent ef626757
No related branches found
No related tags found
1 merge request!32container scanning-INPLATFORM-306
......@@ -44,13 +44,5 @@ image_scan:
variables:
CI_TOKEN: $CI_TOKEN
DOCKER_IMAGE: $CI_REGISTRY_IMAGE:$CI_COMMIT_REF_SLUG
rules:
- if: $CI_COMMIT_BRANCH == "master"
changes:
- Dockerfile
- .gitlab-ci.yml
- run-agent.sh
when: on_success
- if: $CI_PIPELINE_SOURCE == "merge_request_event" || $CI_PIPELINE_SOURCE == "schedule"
when: always
when: on_success
allow_failure: false
......@@ -58,13 +58,7 @@ ODBC support has been added to this image, specifically support for SQLite3 and
### Image Scanning
[imagescan]: #image-scanning
The image is scanned by [Qualys](https://qualysguard.qg2.apps.qualys.com/cs/help/get_started/get_started.htm), a container image vulnerability
scanning system, through a Gitlab CI/CD job: `image_scan`. This job is built upon the `qualy_scan` job from the`check-qualys-job.yml` template in [checkQualys](https://git.doit.wisc.edu/interop/checkqualys) tool repository. An `image_scan` job will be created when:
* There are changes in the files: **Dockerfile, .gitlab-ci.yml, run-agent.sh** on master branch;
* A pipeline is scheduled on a regular basis, e.g. Daily;
* A merge request is created/updated.
And a [Gitlab issue](https://git.doit.wisc.edu/interop/iics/iics_secure_agent/-/issues) will be added to this repository for each [CVE vulnerability](https://www.cvedetails.com/) that occurs.
scanning system, through a Gitlab CI/CD job: `image_scan`. This job is built upon the `qualy_scan` job from the`check-qualys-job.yml` template in [checkQualys](https://git.doit.wisc.edu/interop/checkqualys) tool repository. An `image_scan` job will be created and a [Gitlab issue](https://git.doit.wisc.edu/interop/iics/iics_secure_agent/-/issues) will be added to this repository for each [CVE vulnerability](https://www.cvedetails.com/) that occurs.
To enable container image scanning, you need to first check following criteria:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment