diff --git a/.github/workflows/docker-build.yaml b/.github/workflows/docker-build.yaml new file mode 100644 index 0000000..c9c14e8 --- /dev/null +++ b/.github/workflows/docker-build.yaml @@ -0,0 +1,61 @@ +name: docker-build + +on: + push: + tags: + - 'v*' + +env: + REGISTRY: docker.io + IMAGE_NAME: 42crunch/scand-manager + +jobs: + docker: + runs-on: ubuntu-latest + steps: + - + name: Checkout + uses: actions/checkout@v3 + - + name: Set up Docker Buildx + uses: docker/setup-buildx-action@v2 + - + name: Login to Registry ${{ env.REGISTRY }} + uses: docker/login-action@v2 + with: + registry: ${{ env.REGISTRY }} + username: ${{ secrets.DOCKER_USERNAME }} + password: ${{ secrets.DOCKER_PASSWORD }} + - + name: Docker meta + id: meta + uses: docker/metadata-action@v4 + with: + images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} + - + name: Build and export to Docker + uses: docker/build-push-action@v4 + with: + context: . + load: true + tags: ${{ steps.meta.outputs.tags }} + cache-from: type=gha + cache-to: type=gha,mode=max + - + name: Scan image + id: scan + uses: Azure/container-scan@v0 + with: + image-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest + severity-threshold: CRITICAL + run-quality-checks: true + - + name: Build and push + if: success() + uses: docker/build-push-action@v4 + with: + context: . + push: true + tags: ${{ steps.meta.outputs.tags }} + cache-from: type=gha + cache-to: type=gha,mode=max diff --git a/.github/workflows/docker-scan.yaml b/.github/workflows/docker-scan.yaml new file mode 100644 index 0000000..28ab8fc --- /dev/null +++ b/.github/workflows/docker-scan.yaml @@ -0,0 +1,42 @@ +name: docker-scan + +on: + schedule: + - cron: '30 2 * * *' + +env: + REGISTRY: docker.io + IMAGE_NAME: 42crunch/scand-manager + +jobs: + docker: + runs-on: ubuntu-latest + steps: + - + name: Scan image + id: scan + uses: Azure/container-scan@v0 + with: + image-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest + severity-threshold: CRITICAL + run-quality-checks: true + - + name: Send mail + if: failure() + run: | + cat < email.txt + From: No Reply + To: Security + Subject: Container Scan Report of ${{ github.repository }} + Date: $(date) + + $(cat ${{ steps.scan.outputs.scan-report-path }}) + $(cat ${{ steps.scan.outputs.check-run-url }}) + EOF + + curl \ + --ssl-reqd smtp://smtp.gmail.com \ + --mail-from no-reply@42crunch.com \ + --mail-rcpt security@42crunch.com \ + --upload-file email.txt \ + --user ${{ secrets.MAIL_USERNAME }}:${{ secrets.MAIL_PASSWORD }}