# We violate this rule because we add kubectl from a remote location
# Instead of building it from source/copying it.
# Until we change our practices (e.g. have Dockerfile build kubectl
# in a multi-staged manner), we should skip this check
- CIS-DI-0009
# This should not be made a mandatory test
# It is only used to make us aware of any potential security failure, that
# should trigger a bump of the image in build/.
name: "Image vulnerability scan"
on: [push, pull_request]
runs-on: ubuntu-latest
- uses: actions/checkout@master
- run: make DH_ORG="${{ github.repository_owner }}" VERSION="${{ github.sha }}" image
- uses: Azure/container-scan@v0
image-name: docker.io/${{ github.repository_owner }}/kured:${{ github.sha }}
