Skip to content

add security-scan for CRT (#13627)#13864

Merged
claire-labry merged 1 commit intorelease/1.8.xfrom
backport-sec-scan
Feb 1, 2022
Merged

add security-scan for CRT (#13627)#13864
claire-labry merged 1 commit intorelease/1.8.xfrom
backport-sec-scan

Conversation

@claire-labry
Copy link
Copy Markdown
Collaborator

  • add security-scan

  • updating the alpine version

  • clean up

  • update the alpine version to be more prescriptive

* add security-scan

* updating the alpine version

* clean up

* update the alpine version to be more prescriptive
@claire-labry claire-labry requested a review from mladlow February 1, 2022 15:35
@claire-labry
Copy link
Copy Markdown
Collaborator Author

the security-scan.hcl is a declarative file where the security-scanner (owned by Security) will attempt to find in your repo. In each of the two stanzas container and binary there are options that are set to true/false to allow the scanner to read and detect any vulns/CVEs that may arise. If any of those vulns arise, then the workflows will stop and output the vulnerability.
here’s a link to more in depth explanation for that config file: https://github.com/hashicorp/security-scanner/blob/main/CONFIG.md

@claire-labry claire-labry merged commit bfeb7f1 into release/1.8.x Feb 1, 2022
pull bot pushed a commit to benjivesterby/vault that referenced this pull request Apr 15, 2026
…13924)

Return a templating error if a rendered identity template contains a
glob (*) or directory wildcard (+) .

Co-authored-by: Theron Voran <tvoran@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants