Skip to content

Commit ba7ed6c

Browse files
committed
Trivy scan setup
1 parent 3d9a241 commit ba7ed6c

File tree

3 files changed

+10
-47
lines changed

3 files changed

+10
-47
lines changed

.semaphore/project.yml

Lines changed: 0 additions & 43 deletions
This file was deleted.

.semaphore/semaphore.yml

Lines changed: 9 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -37,10 +37,15 @@ blocks:
3737
jobs:
3838
- name: Test
3939
commands:
40-
- pip install confluent-release-tools -q
4140
- . sem-pint
42-
- mvn -Dcloud -Pjenkins -U -Dmaven.wagon.http.retryHandler.count=10 --batch-mode --no-transfer-progress clean verify install dependency:analyze validate
43-
- cve-scan
41+
- mvn -Dcloud -Pjenkins -U -Dmaven.wagon.http.retryHandler.count=10 -Ddependency.check.skip=true --batch-mode --no-transfer-progress clean verify install dependency:analyze validate
42+
- export TRIVY_DISABLE_VEX_NOTICE=true
43+
- trivy version
44+
- echo "Check go/connector-dev-vuln-remediation for fixing or suppressing vulnerabilities found by trivy"
45+
- trivy --skip-files "*.zip" rootfs --scanners vuln --db-repository public.ecr.aws/aquasecurity/trivy-db --java-db-repository public.ecr.aws/aquasecurity/trivy-java-db --ignore-unfixed --ignorefile
46+
.trivyignore --exit-code 1 --severity CRITICAL target/components/packages
47+
- trivy --skip-files "*.zip" rootfs --scanners vuln --db-repository public.ecr.aws/aquasecurity/trivy-db --java-db-repository public.ecr.aws/aquasecurity/trivy-java-db --ignore-unfixed --ignorefile
48+
.trivyignore --severity HIGH,LOW,MEDIUM target/components/packages
4449
- . cache-maven store
4550
epilogue:
4651
always:
@@ -57,7 +62,7 @@ blocks:
5762
jobs:
5863
- name: Release
5964
commands:
60-
- mvn -Dcloud -Pjenkins -U -Dmaven.wagon.http.retryHandler.count=10 --batch-mode -DaltDeploymentRepository=confluent-codeartifact-internal::default::https://confluent-519856050701.d.codeartifact.us-west-2.amazonaws.com/maven/maven-snapshots/
65+
- mvn -Dcloud -Pjenkins -U -Dmaven.wagon.http.retryHandler.count=10 -Ddependency.check.skip=true --batch-mode -DaltDeploymentRepository=confluent-codeartifact-internal::default::https://confluent-519856050701.d.codeartifact.us-west-2.amazonaws.com/maven/maven-snapshots/
6166
-DrepositoryId=confluent-codeartifact-internal deploy -DskipTests
6267
- name: Release Notes
6368
dependencies: []

sonar-project.properties

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
### service-bot sonarqube plugin managed file
22
sonar.coverage.exclusions=**/test/**/*,**/tests/**/*,**/mock/**/*,**/mocks/**/*,**/*mock*,**/*test*
33
sonar.coverage.jacoco.xmlReportPaths=**/jacoco.xml
4+
sonar.cpd.exclusions=**/test/**/*,**/tests/**/*,**/mock/**/*,**/mocks/**/*,**/*mock*,**/*test*
45
sonar.exclusions=**/*.pb.*,**/mk-include/**/*
56
sonar.java.binaries=.
67
sonar.language=java

0 commit comments

Comments
 (0)