ci: migrate to sps - #2714
Conversation
| @@ -0,0 +1,10 @@ | |||
| [ | |||
| { | |||
| "cve": "CVE-2025-14505", | |||
There was a problem hiding this comment.
elliptic CVE-2025-14505: Skipped for now due to its low severity and the absence of an upstream patched version. The vulnerability affects elliptic versions up to 6.6.1, which is currently the latest available version.
| "alwaysOmit": true | ||
| }, | ||
| { | ||
| "cve": "CVE-2021-32822", |
There was a problem hiding this comment.
hbs CVE-2021-32822: Skipped for now due to its moderate severity and the absence of an upstream patched version. The vulnerability affects hbs versions up to 4.1.2, and there is currently no fix available.
hbs is a dependency of admin pkg, which is a development dependency of us
| native-dep-packs | ||
| packages/collector/test/apps | ||
| packages/aws-lambda/lambdas/serverless-framework | ||
| packages/aws-fargate/images/inspector/Dockerfile |
There was a problem hiding this comment.
CRA scan fails on Dockerfiles using build args for image tags (e.g. FROM node:${NODEJS_VERSION}-alpine) because the variable cannot be resolved during the scan, causing invalid reference format and cra:bom-generate to exit with code 1.
The Node.js version is intentionally passed during the actual build.
| "@types/morgan": "1.9.3", | ||
| "@types/node": "24.7.0", | ||
| "@types/proxyquire": "1.3.28", | ||
| "@types/rimraf": "3.0.2", |
There was a problem hiding this comment.
rimraf not required types anymore
SPS Pipeline Setup
.secrets.baseline.pipeline-config.yamlinstana-eng-node-js-tracer-citoolchainnpm installCompliance & CVE
package-lock.jsonis not excludedBranch Protection
tekton/code-branch-protectiontekton/code-unit-teststekton/code-vulnerability-scantekton/code-detect-secretsRegistry pull
Test Migration
Pipe Design
npm install/npm ciSecrets & Access
Pipeline Triggers & Automation
Cleanup & Documentation
ref: https://ibm.ent.box.com/notes/2405458268781