Skip to content

CHEF-33010 Added grype scan config#738

Open
Nik08 wants to merge 1 commit intomainfrom
nm/grype-scan-flags-inspec7
Open

CHEF-33010 Added grype scan config#738
Nik08 wants to merge 1 commit intomainfrom
nm/grype-scan-flags-inspec7

Conversation

@Nik08
Copy link
Copy Markdown
Contributor

@Nik08 Nik08 commented Mar 26, 2026

This PR updates the CI workflow configuration to enable Grype vulnerability scanning and renames the stub file to remove the version suffix.

  • Renamed versioned stub to ci-main-pull-request-stub.yml
  • Enabled Grype vulnerability scanning (perform-grype-scan: true)
  • Configured build failure on high/critical vulnerabilities
  • Added run-bundle-install: true to generate Gemfile.lock at runtime for the SBOM/BlackDuck SCA pipeline

Signed-off-by: Nikita Mathur <nikita.mathur@progress.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Nik08 Nik08 requested a review from a team as a code owner March 26, 2026 18:39
@Nik08 Nik08 added the Expeditor: Skip All Used to skip all merge_actions label Mar 26, 2026
@netlify
Copy link
Copy Markdown

netlify bot commented Mar 26, 2026

Deploy Preview for inspec-azure canceled.

Name Link
🔨 Latest commit 0c1a45c
🔍 Latest deploy log https://app.netlify.com/projects/inspec-azure/deploys/69c57d512113b200081debc7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Expeditor: Skip All Used to skip all merge_actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant