Skip to content

feat: introduce re-usable pipelines - #18

Open
moghit-eou wants to merge 16 commits into
Medical-Informatics-Platform:masterfrom
moghit-eou:feat/dev
Open

moghit-eou wants to merge 16 commits into
Medical-Informatics-Platform:masterfrom
moghit-eou:feat/dev

Conversation

@moghit-eou

Copy link
Copy Markdown

Reusable Pipelines

Introduces reusable pipeline patterns enabling consistent security scanning across multiple projects and stacks. Includes SAST, SCA, and container-scan workflows that operate at both root and per-folder levels.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

1 similar comment
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

moghit-eou and others added 15 commits September 11, 2026 18:37
github.workspace is empty when strategy.matrix is expanded (no runner yet)
Matrix now holds {0} placeholders, filled via format() in job-level env.
All images ran their entrypoint as root, flagged by Semgrep missing-user-entrypoint
(ERROR, CWE-250 / CWE-269). Each now drops to an unprivileged
account before CMD/ENTRYPOINT.

Ownership is set with COPY --chown instead of RUN chown -R. A RUN chown
rewrites every touched file into a new layer while the original copy stays
in the layer below, so the payload is stored twice.
Measured: backend 868MB vs 696MB,
frontend 113MB vs 107MB unique.

Ref: https://medium.com/@mmornati/docker-images-and-files-chown-40d2f7248fcc
Base image ships openssl 3.5.7-r0 (10 CVEs), Alpine 3.24 has a fixed build.

dockerize bundles golang.org/x/crypto 0.57.0 (1 CVE, no fix available yet).
apt upgrade + pip upgrade on the python:3.12.14-slim base.
Criticals 6 -> 0
total 91 -> 59.
Remainder are Debian packages with no fix available upstream.
hadolint DL4000. MAINTAINER has been deprecated.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants