From 64bdc67de7feff8f8cf545886bfa3e5a3579e325 Mon Sep 17 00:00:00 2001 From: Advait Patel Date: Mon, 21 Sep 2026 22:10:35 -0500 Subject: [PATCH] ci: add DockSec container scan with SARIF upload Scans the Dockerfile with DockSec and uploads the results to code scanning as SARIF, so container findings are annotated on pull requests. Runs scan-only, so no API key is required and no gate is added to the build. All actions are pinned to a commit SHA. Signed-off-by: Advait Patel --- .github/workflows/docksec.yml | 49 +++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 .github/workflows/docksec.yml diff --git a/.github/workflows/docksec.yml b/.github/workflows/docksec.yml new file mode 100644 index 0000000..4f29211 --- /dev/null +++ b/.github/workflows/docksec.yml @@ -0,0 +1,49 @@ +name: DockSec + +on: + push: + branches: [main] + paths: + - 'Dockerfile' + - '.github/workflows/docksec.yml' + pull_request: + paths: + - 'Dockerfile' + - '.github/workflows/docksec.yml' + schedule: + - cron: '0 6 * * 1' + +permissions: + contents: read + +jobs: + scan: + name: Scan Dockerfile + runs-on: ubuntu-latest + timeout-minutes: 15 + permissions: + contents: read + security-events: write + steps: + - name: Checkout + uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 + with: + persist-credentials: false + + - name: Run DockSec + uses: OWASP/DockSec@d52c8e928552dc39003abda21ac6bc4662b06c39 # v2026.9.21 + with: + dockerfile: Dockerfile + scan_only: 'true' + sarif: 'true' + output_dir: ${{ github.workspace }}/docksec-results + + - name: Upload SARIF to Code Scanning + # Not `if: always()`: on a fork pull_request, GITHUB_TOKEN is read-only and this + # upload would fail every time, turning a routine fork contribution into a red + # required check. Skip it there instead of forcing a failure. + if: always() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) + uses: github/codeql-action/upload-sarif@3ea06614dafe36dec890db3446326e0d40ce53d4 # v3 + with: + sarif_file: docksec-results + category: docksec