|
|
|
|
@ -4164,14 +4164,34 @@ platform: |
|
|
|
|
arch: amd64 |
|
|
|
|
os: linux |
|
|
|
|
steps: |
|
|
|
|
- commands: |
|
|
|
|
- echo $${GCR_CREDENTIALS} | docker login -u _json_key --password-stdin https://us.gcr.io |
|
|
|
|
environment: |
|
|
|
|
GCR_CREDENTIALS: |
|
|
|
|
from_secret: gcr_credentials |
|
|
|
|
image: docker:dind |
|
|
|
|
name: authenticate-gcr |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM grafana/grafana:latest |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-unknown-low-medium-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 1 --severity HIGH,CRITICAL grafana/grafana:latest |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-high-critical-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- image: plugins/slack |
|
|
|
|
name: slack-notify-failure |
|
|
|
|
settings: |
|
|
|
|
@ -4185,6 +4205,10 @@ trigger: |
|
|
|
|
cron: nightly |
|
|
|
|
event: cron |
|
|
|
|
type: docker |
|
|
|
|
volumes: |
|
|
|
|
- host: |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
name: docker |
|
|
|
|
--- |
|
|
|
|
clone: |
|
|
|
|
retries: 3 |
|
|
|
|
@ -4194,14 +4218,34 @@ platform: |
|
|
|
|
arch: amd64 |
|
|
|
|
os: linux |
|
|
|
|
steps: |
|
|
|
|
- commands: |
|
|
|
|
- echo $${GCR_CREDENTIALS} | docker login -u _json_key --password-stdin https://us.gcr.io |
|
|
|
|
environment: |
|
|
|
|
GCR_CREDENTIALS: |
|
|
|
|
from_secret: gcr_credentials |
|
|
|
|
image: docker:dind |
|
|
|
|
name: authenticate-gcr |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM grafana/grafana:main |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-unknown-low-medium-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 1 --severity HIGH,CRITICAL grafana/grafana:main |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-high-critical-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- image: plugins/slack |
|
|
|
|
name: slack-notify-failure |
|
|
|
|
settings: |
|
|
|
|
@ -4215,6 +4259,10 @@ trigger: |
|
|
|
|
cron: nightly |
|
|
|
|
event: cron |
|
|
|
|
type: docker |
|
|
|
|
volumes: |
|
|
|
|
- host: |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
name: docker |
|
|
|
|
--- |
|
|
|
|
clone: |
|
|
|
|
retries: 3 |
|
|
|
|
@ -4224,14 +4272,34 @@ platform: |
|
|
|
|
arch: amd64 |
|
|
|
|
os: linux |
|
|
|
|
steps: |
|
|
|
|
- commands: |
|
|
|
|
- echo $${GCR_CREDENTIALS} | docker login -u _json_key --password-stdin https://us.gcr.io |
|
|
|
|
environment: |
|
|
|
|
GCR_CREDENTIALS: |
|
|
|
|
from_secret: gcr_credentials |
|
|
|
|
image: docker:dind |
|
|
|
|
name: authenticate-gcr |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM grafana/grafana:latest-ubuntu |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-unknown-low-medium-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 1 --severity HIGH,CRITICAL grafana/grafana:latest-ubuntu |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-high-critical-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- image: plugins/slack |
|
|
|
|
name: slack-notify-failure |
|
|
|
|
settings: |
|
|
|
|
@ -4246,6 +4314,10 @@ trigger: |
|
|
|
|
cron: nightly |
|
|
|
|
event: cron |
|
|
|
|
type: docker |
|
|
|
|
volumes: |
|
|
|
|
- host: |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
name: docker |
|
|
|
|
--- |
|
|
|
|
clone: |
|
|
|
|
retries: 3 |
|
|
|
|
@ -4255,14 +4327,34 @@ platform: |
|
|
|
|
arch: amd64 |
|
|
|
|
os: linux |
|
|
|
|
steps: |
|
|
|
|
- commands: |
|
|
|
|
- echo $${GCR_CREDENTIALS} | docker login -u _json_key --password-stdin https://us.gcr.io |
|
|
|
|
environment: |
|
|
|
|
GCR_CREDENTIALS: |
|
|
|
|
from_secret: gcr_credentials |
|
|
|
|
image: docker:dind |
|
|
|
|
name: authenticate-gcr |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM grafana/grafana:main-ubuntu |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-unknown-low-medium-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 1 --severity HIGH,CRITICAL grafana/grafana:main-ubuntu |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-high-critical-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- image: plugins/slack |
|
|
|
|
name: slack-notify-failure |
|
|
|
|
settings: |
|
|
|
|
@ -4277,6 +4369,10 @@ trigger: |
|
|
|
|
cron: nightly |
|
|
|
|
event: cron |
|
|
|
|
type: docker |
|
|
|
|
volumes: |
|
|
|
|
- host: |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
name: docker |
|
|
|
|
--- |
|
|
|
|
clone: |
|
|
|
|
retries: 3 |
|
|
|
|
@ -4286,6 +4382,16 @@ platform: |
|
|
|
|
arch: amd64 |
|
|
|
|
os: linux |
|
|
|
|
steps: |
|
|
|
|
- commands: |
|
|
|
|
- echo $${GCR_CREDENTIALS} | docker login -u _json_key --password-stdin https://us.gcr.io |
|
|
|
|
environment: |
|
|
|
|
GCR_CREDENTIALS: |
|
|
|
|
from_secret: gcr_credentials |
|
|
|
|
image: docker:dind |
|
|
|
|
name: authenticate-gcr |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM google/cloud-sdk:431.0.0 |
|
|
|
|
- trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM grafana/build-container:1.7.5 |
|
|
|
|
@ -4306,8 +4412,13 @@ steps: |
|
|
|
|
- trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM grafana/docs-base:dbd975af06 |
|
|
|
|
- trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM cypress/included:9.5.1-node16.14.0-slim-chrome99-ff97 |
|
|
|
|
- trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM us-docker.pkg.dev/grafanalabs-dev/cloud-data-sources/e2e:latest |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-unknown-low-medium-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- commands: |
|
|
|
|
- trivy --exit-code 1 --severity HIGH,CRITICAL google/cloud-sdk:431.0.0 |
|
|
|
|
- trivy --exit-code 1 --severity HIGH,CRITICAL grafana/build-container:1.7.5 |
|
|
|
|
@ -4328,8 +4439,13 @@ steps: |
|
|
|
|
- trivy --exit-code 1 --severity HIGH,CRITICAL grafana/docs-base:dbd975af06 |
|
|
|
|
- trivy --exit-code 1 --severity HIGH,CRITICAL cypress/included:9.5.1-node16.14.0-slim-chrome99-ff97 |
|
|
|
|
- trivy --exit-code 1 --severity HIGH,CRITICAL us-docker.pkg.dev/grafanalabs-dev/cloud-data-sources/e2e:latest |
|
|
|
|
depends_on: |
|
|
|
|
- authenticate-gcr |
|
|
|
|
image: aquasec/trivy:0.21.0 |
|
|
|
|
name: scan-high-critical-vulnerabilities |
|
|
|
|
volumes: |
|
|
|
|
- name: docker |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
- image: plugins/slack |
|
|
|
|
name: slack-notify-failure |
|
|
|
|
settings: |
|
|
|
|
@ -4343,6 +4459,10 @@ trigger: |
|
|
|
|
cron: nightly |
|
|
|
|
event: cron |
|
|
|
|
type: docker |
|
|
|
|
volumes: |
|
|
|
|
- host: |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
name: docker |
|
|
|
|
--- |
|
|
|
|
clone: |
|
|
|
|
retries: 3 |
|
|
|
|
@ -4374,6 +4494,10 @@ trigger: |
|
|
|
|
cron: grafana-com-nightly |
|
|
|
|
event: cron |
|
|
|
|
type: docker |
|
|
|
|
volumes: |
|
|
|
|
- host: |
|
|
|
|
path: /var/run/docker.sock |
|
|
|
|
name: docker |
|
|
|
|
--- |
|
|
|
|
get: |
|
|
|
|
name: credentials.json |
|
|
|
|
@ -4543,7 +4667,13 @@ get: |
|
|
|
|
kind: secret |
|
|
|
|
name: delivery-bot-app-private-key |
|
|
|
|
--- |
|
|
|
|
get: |
|
|
|
|
name: service-account |
|
|
|
|
path: secret/data/common/gcr |
|
|
|
|
kind: secret |
|
|
|
|
name: gcr_credentials |
|
|
|
|
--- |
|
|
|
|
kind: signature |
|
|
|
|
hmac: 303fb59b2da9a39e5bc46dcb962894895697c46477d0c94b2a65c290e87ea57e |
|
|
|
|
hmac: 37c8cdea5d79479014c2bee1b93433549ba5f8d5f2eef4f599247312c661118c |
|
|
|
|
|
|
|
|
|
... |
|
|
|
|
|