mirror of
https://github.com/bitnami/containers.git
synced 2026-02-10 03:15:53 +08:00
[bitnami/*] Add vuln. scan note in the README (#1553)
* [bitnami/*] Add vuln. scan note in the README Signed-off-by: Carlos Rodríguez Hernández <carlosrh@vmware.com> * Update README.md Co-authored-by: Pablo Galego <pablogalegocarro@gmail.com> * Update README.md Signed-off-by: Carlos Rodríguez Hernández <carlosrh@vmware.com> Co-authored-by: Pablo Galego <pablogalegocarro@gmail.com>
This commit is contained in:
committed by
GitHub
parent
e0d6cbbdbf
commit
dd761bc53f
@@ -49,6 +49,15 @@ $ docker-compose up -d
|
||||
|
||||
> Remember to replace the `APP` placeholder in the example command above with the correct value.
|
||||
|
||||
## Vulnerability scan in Bitnami container images
|
||||
|
||||
As part of the release process, the Bitnami container images are analyzed for vulnerabilities. At this moment, we are using two different tools:
|
||||
|
||||
* [Trivy](https://github.com/aquasecurity/trivy)
|
||||
* [Grype](https://github.com/anchore/grype)
|
||||
|
||||
This scanning process is triggered via a GH action for every PR affecting the source code of the containers, regardless of its nature or origin.
|
||||
|
||||
## Contributing
|
||||
|
||||
We'd love for you to contribute to those container images. You can request new features by creating an [issue](https://github.com/bitnami/containers/issues/new/choose), or submit a [pull request](https://github.com/bitnami/containers/pulls) with your contribution.
|
||||
|
||||
Reference in New Issue
Block a user