Skip to content

CHEF-33010 Added grype scan config#228

Merged
Nik08 merged 2 commits intomainfrom
nm/grype-scan-flags-inspec7
Mar 31, 2026
Merged

CHEF-33010 Added grype scan config#228
Nik08 merged 2 commits intomainfrom
nm/grype-scan-flags-inspec7

Conversation

@Nik08
Copy link
Copy Markdown
Collaborator

@Nik08 Nik08 commented Mar 26, 2026

This PR updates the CI workflow configuration to enable Grype vulnerability scanning and renames the stub file to remove the version suffix.

  • Renamed versioned stub to ci-main-pull-request-stub.yml
  • Enabled Grype vulnerability scanning (perform-grype-scan: true)
  • Configured build failure on high/critical vulnerabilities
  • Added run-bundle-install: true to generate Gemfile.lock at runtime for the SBOM/BlackDuck SCA pipeline

Signed-off-by: Nikita Mathur <nikita.mathur@progress.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Nik08 Nik08 added Expeditor: Skip Version Bump Skip the bumping of version Expeditor: Skip All Skip all expeditor CI merge actions labels Mar 26, 2026
@Nik08 Nik08 merged commit 671cdf8 into main Mar 31, 2026
12 of 17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Expeditor: Skip All Skip all expeditor CI merge actions Expeditor: Skip Version Bump Skip the bumping of version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant