Skip to content

dev: add devcontainers setup - #17

Open
qboileau wants to merge 1 commit into
mainfrom
setup-devcontainers
Open

dev: add devcontainers setup#17
qboileau wants to merge 1 commit into
mainfrom
setup-devcontainers

Conversation

@qboileau

Copy link
Copy Markdown
Member

Add alternative to Nix to setup dev environment with devcontainers that reuse nix to setup dev environment.

@github-actions

Copy link
Copy Markdown

Container image CVE report

base-jre-25

Scanner Critical Critical+High Total
Trivy ✅ 0 ✅ 0 0
Grype ✅ 0 ⚠️ 3 3
Grype critical+high by component
Component Findings
libcrypto3 3.6.3-r4 1
libssl3 3.6.3-r4 1
openssl 3.6.3-r4 1

base-monitoring

Scanner Critical Critical+High Total
Trivy ✅ 0 ✅ 0 0
Grype ✅ 0 ⚠️ 3 7
Grype critical+high by component
Component Findings
libcrypto3 3.6.3-r4 1
libssl3 3.6.3-r4 1
openssl 3.6.3-r4 1

base-os

Scanner Critical Critical+High Total
Trivy ✅ 0 ✅ 0 0
Grype ✅ 0 ✅ 0 0

debug

Scanner Critical Critical+High Total
Trivy ✅ 0 ✅ 0 0
Grype ✅ 0 ⚠️ 17 35
Grype critical+high by component
Component Findings
stdlib go1.25.12 6
jackson-databind 2.21.2 2
jline-remote-telnet 3.30.4 2
golang.org/x/net v0.55.0 1
golang.org/x/text v0.37.0 1
jackson-core 2.21.2 1
jetty-security 12.0.34 1
libcrypto3 3.6.3-r4 1

Trivy counts fixed vulnerabilities only; Grype includes unfixed, so its totals run higher. Full reports are in the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant