Skip to content

CHEF-33010 Added grype scan config#113

Merged
Nik08 merged 1 commit intomainfrom
nm/grype-scan-flags-inspec7
Apr 8, 2026
Merged

CHEF-33010 Added grype scan config#113
Nik08 merged 1 commit intomainfrom
nm/grype-scan-flags-inspec7

Conversation

@Nik08
Copy link
Copy Markdown
Contributor

@Nik08 Nik08 commented Mar 26, 2026

This PR updates the CI workflow configuration to enable Grype vulnerability scanning and renames the stub file to remove the version suffix.

  • Renamed versioned stub to ci-main-pull-request-stub.yml
  • Enabled Grype vulnerability scanning (perform-grype-scan: true)
  • Configured build failure on high/critical vulnerabilities
  • Added run-bundle-install: true to generate Gemfile.lock at runtime for the SBOM/BlackDuck SCA pipeline

@Nik08 Nik08 added Expeditor: Skip All Used to skip all merge_actions. Expeditor: Skip Version Bump Used to skip built_in:bump_version labels Mar 26, 2026
@Nik08 Nik08 force-pushed the nm/grype-scan-flags-inspec7 branch from 22bc1a9 to 3b41148 Compare April 8, 2026 16:03
Signed-off-by: Nikita Mathur <nikita.mathur@progress.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Nik08 Nik08 force-pushed the nm/grype-scan-flags-inspec7 branch from 3b41148 to d76f754 Compare April 8, 2026 16:07
@Nik08 Nik08 merged commit 53a2c34 into main Apr 8, 2026
23 of 24 checks passed
@Nik08 Nik08 deleted the nm/grype-scan-flags-inspec7 branch April 8, 2026 16:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Expeditor: Skip All Used to skip all merge_actions. Expeditor: Skip Version Bump Used to skip built_in:bump_version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant