Skip to content

chore(ci): add grype vulnerability scan on every PR - #8

Merged
initializ-mk merged 3 commits into
mainfrom
chore/grype-ci
Sep 14, 2026
Merged

initializ-mk merged 3 commits into
mainfrom
chore/grype-ci

Conversation

@initializ-mk

Copy link
Copy Markdown
Contributor

Adds workspace-standard grype CI (.github/workflows/security-scan.yml, anchore/scan-action on every PR + integration-branch push): fails on a High/Critical vuln that has a fix (only-fixed — no-fix advisories don't block), SARIF to the Security tab.

.grype.yaml excludes node_modules — prebuilt tool binaries (esbuild) throw un-actionable Go-stdlib CVEs; the real dependency surface is cataloged from the lockfiles / go.mod. This repo currently has no High/Critical (with a fix), so the gate starts green.

🤖 Generated with Claude Code

grype (anchore/scan-action) on each PR + integration-branch push: fail on a
HIGH/CRITICAL vuln that has a fix (only-fixed), SARIF to the Security tab.
.grype.yaml excludes node_modules — prebuilt tool binaries (esbuild) generate
un-actionable stdlib CVEs; the real dependency surface is cataloged from the
lockfiles/go.mod.
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Upload SARIF needs GHAS code scanning, which private repos lack — the always()-upload failed the whole grype check on a clean scan. continue-on-error keeps grype fail-build as the real gate.
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

🔎 Grype — no fixable vulnerabilities ✅

Install grype (pinned) and render --only-fixed as a table, then upsert one sticky PR comment via marocchino/sticky-pull-request-comment (SHA-pinned to v3.0.5). Best-effort (continue-on-error) so it never gates the check; gives finding visibility on private repos without GHAS code scanning.
@initializ-mk
initializ-mk merged commit eda3bdb into main Sep 14, 2026
2 checks passed
@initializ-mk
initializ-mk deleted the chore/grype-ci branch September 14, 2026 17:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants