Skip to content

chore: enable Snyk scan for orchestrator-infra chart#136

Merged
openshift-merge-bot[bot] merged 3 commits intoredhat-developer:mainfrom
Fortune-Ndlovu:snyk-scan-orchestrator-chart
Apr 24, 2025
Merged

chore: enable Snyk scan for orchestrator-infra chart#136
openshift-merge-bot[bot] merged 3 commits intoredhat-developer:mainfrom
Fortune-Ndlovu:snyk-scan-orchestrator-chart

Conversation

@Fortune-Ndlovu
Copy link
Copy Markdown
Member

Description of the change

This PR updates the snyk.yaml GitHub Actions workflow to include IaC scanning of the orchestrator-infra Helm chart in addition to the existing backstage chart.

Existing or Associated Issue(s)

https://issues.redhat.com/browse/RHIDP-6630

Additional Information

Added helm dependency build and helm template for charts/orchestrator-infra.
Added a separate Snyk IaC scan step targeting the rendered output of orchestrator-infra.
Ensures both backstage and orchestrator-infra templates are scanned weekly for infrastructure vulnerabilities.

Checklist

  • Chart version bumped in Chart.yaml according to semver.
  • Variables are documented in the values.yaml and added to the README.md. The pre-commit utility can be used to generate the necessary content. Use pre-commit run -a to apply changes.
  • JSON Schema template updated and re-generated the raw schema via pre-commit hook.
  • List tests pass for Chart using the Chart Testing tool and the ct lint command.

Signed-off-by: Fortune-Ndlovu <fndlovu@redhat.com>
@openshift-ci openshift-ci Bot requested review from gazarenkov and nickboldt April 24, 2025 15:26
@Fortune-Ndlovu
Copy link
Copy Markdown
Member Author

cc/ @coreydaley , @rm3l

Comment thread .github/workflows/snyk.yaml Outdated
Signed-off-by: Fortune-Ndlovu <fndlovu@redhat.com>
Comment thread .github/workflows/snyk.yaml Outdated
Signed-off-by: Fortune-Ndlovu <fndlovu@redhat.com>
@Fortune-Ndlovu Fortune-Ndlovu force-pushed the snyk-scan-orchestrator-chart branch from aed463c to 831c593 Compare April 24, 2025 15:55
@sonarqubecloud
Copy link
Copy Markdown

@coreydaley
Copy link
Copy Markdown

/lgtm
I will let @rm3l give the approval

@openshift-ci openshift-ci Bot added the lgtm label Apr 24, 2025
@openshift-merge-bot openshift-merge-bot Bot merged commit eb94968 into redhat-developer:main Apr 24, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants