feat(governance): add external attestations envelope and veip poc (#89) #264
security-scan.yml
on: push
Python Dependency Vulnerability Scan (Universal — NIST RA-5/SI-2 reporting: US_FED only)
1m 6s
Matrix: Container Image Vulnerability Scan — Trivy (Universal — NIST RA-5/CM-8 reporting: US_FED only)
Dependency Lockfile Validation (Universal — NIST SI-2/CM-8 reporting: US_FED only)
32s
OPA Rego Policy Lint and Test (Universal — NIST CM-6/SI-7 reporting: US_FED only)
7s
Secret Scanning (Gitleaks)
7s
Generate and Validate SBOM (Universal — NIST CM-8/POAM-006 reporting: US_FED only)
0s
NIST SP 800-53 Compliance Gate (US_FED only)
Annotations
1 error
|
Python Dependency Vulnerability Scan (Universal — NIST RA-5/SI-2 reporting: US_FED only)
Process completed with exit code 1.
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
dependency-snapshot
|
1.01 KB |
sha256:3c79236d65d4726daac5c499e61f539253e625dd931fafbd2fbd53b33d9ff3a6
|
|
|
pip-audit-results
|
3.74 KB |
sha256:f97bd4f85c55e95055fcdf0833089af3a1d14455d8c2fe76301966ba287be71b
|
|
|
sbom-0
|
13.3 KB |
sha256:1f748f359cd5a3c968c9081509d3327202224ebd7fbb03e399d49c6b205d25f8
|
|
|
sbom-1
|
13.3 KB |
sha256:b7c5333a8daebdf0d8f7152794805c01d800f5f58d6d647ae4bdfa377141df6b
|
|
|
sbom-2
|
13.3 KB |
sha256:be8a25aefcfb4352c7d7006ceb8c2eee6de0968a4ef2e0f7038a0e790ca26b3f
|
|