Skip to content

Develop Anchore CLI Reports of Images with / without vulnerabilities #1157

Description

@godfreykutumela

Goal:

Prepare reports for a demo at the PI meeting in Johannesburg

Tasks:

  • figure out how to get the most current anchore reports in one place. The best method is likely:
    - [ ] Get CircleCI to automatically add these to releases (similar to the license-scanner summary on the mojaloop/helm repo
    • Write a tool to get all latest reports from a list of given repos in one place
    • upload these reports to the s3 bucket, similar to how we handle the sonarqube output
  • Apply CI/CD Updates for the following repos:
    • bulk-api-adapter [PR]
    • central-event-processor [PR]
    • central-ledger [PR]
    • central-settlement [PR]
    • email-notifier [PR]
    • ml-api-adapter [PR]
    • quoting-service [PR]
    • mojaloop-simulator [PR]
  • compile these reports for the upcoming convening
  • summarize into one or two slides

Acceptance Criteria:

  • Designs are up-to date
  • Unit Tests pass
  • Integration Tests pass
  • Code Style & Coverage meets standards
  • Changes made to config (default.json) are broadcast to team and follow-up tasks added to update helm charts and other deployment config.
  • TBD

Pull Requests:

Follow-up:

  • N/A

Dependencies:

  • N/A

Accountability:

  • Owner: TBC
  • QA/Review: TBC

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions