Skip to content

[INFRA-13215] update security-scan-sast to v2 with Docker Hub auth#96

Closed
vgs-ci-bot[bot] wants to merge 1 commit intomainfrom
infra-13215/add-dockerhub-token
Closed

[INFRA-13215] update security-scan-sast to v2 with Docker Hub auth#96
vgs-ci-bot[bot] wants to merge 1 commit intomainfrom
infra-13215/add-dockerhub-token

Conversation

@vgs-ci-bot
Copy link
Copy Markdown

@vgs-ci-bot vgs-ci-bot Bot commented Mar 30, 2026

Updates the security-scan-sast reusable workflow call:

  • Pins to @security-scan-sast-v2 rolling tag (if not already)
  • Adds DOCKERHUB_TOKEN secret for authenticated Docker Hub pulls
  • Adds SAST_SLACK_WORKFLOW_WEBHOOK secret if missing (required in v2)

This prevents intermittent semgrep failures from stale Docker Hub
credentials and rate limiting on GitHub Actions runners.

See: https://github.com/verygood-ops/cicd-shared/pull/547

@gvisalli-vgs
Copy link
Copy Markdown

Closing — will reopen after fixing semgrep startup_failure (DOCKERHUB_TOKEN must be optional in reusable workflow before callers can pass it)

@gvisalli-vgs gvisalli-vgs reopened this Apr 1, 2026
@gvisalli-vgs
Copy link
Copy Markdown

Closing — switching strategy to pinned tag security-scan-sast-v2.0.13. Teams can opt-in to update their workflow reference when ready. See INFRA-13215.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant