DevOps: Investigate and improve Trivy scans - Schedule Weekly Trivy Scan in CircleCI

Description

Implement a method to distinguish findings from the Trivy scan between OS, dependencies and OpenNMS installation.This may involve

  1. OS vulnerabilities (Vulnerabilities in the operating system packages),

  2. Vulnerabilities in libraries or frameworks for ONMS application uses.

  3. Specific vulnerabilities related to OpenNMS.

  4. Implement a scheduled job in the CircleCI pipeline that runs the Trivy vulnerability scan as part of the coverage pipeline once a week.

Acceptance / Success Criteria

None

Activity

Tahir Abbasi March 6, 2025 at 11:35 AM

Changes have been merged in branch "ta/jira/NMS_16560".

Done

Details

Assignee

Reporter

HB Grooming Date

HB Backlog Status

Sprint

Priority

PagerDuty

Created October 2, 2024 at 11:33 AM
Updated March 10, 2025 at 1:20 PM
Resolved March 6, 2025 at 11:35 AM

Flag notifications