Skip to content
34 changes: 34 additions & 0 deletions .github/workflows/vulnerability-scan.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
name: Vulnerability Scan

on:
push:
branches: ["master"]
pull_request:
branches: ["master"]

permissions:
contents: read
security-events: write

jobs:
grype-vulnerability-scan:
name: Grype Vulnerability Scan 🔍
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4

- name: Scan for vulnerabilities
uses: anchore/scan-action@v7
id: scan
with:
path: "."
fail-build: true
severity-cutoff: high
output-format: sarif

- name: Upload SARIF report
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: ${{ steps.scan.outputs.sarif }}
Loading