Skip to Content
Secure Projects with vulnerability scanning in Github
video

Secure Projects with vulnerability scanning in Github

by Alfredo Deza, Noah Gift
February 2021
Intermediate
54m
English
Pragmatic AI Labs

Overview

Get started with security vulnerability scanning and integrating that with Github, Github Actions and automated security checks in pull requests.
Learn how to scan reported vulnerabilities in projects and Docker containers, so that you can publish images to Docker hub or merge pull requests while knowing that changes in dependencies are secure.
Topics include:
* Install and run locally a security vulnerability scanner
* Catalog a project with an SBOM (Software Bill Of Materials) so that the scanner can do vulnerability matching.
* Setup a Github Action to automatically scan vulnerabilities in a project and optionally fail a build to prevent a merge.
* Scan a Docker container image that is built locally against the latest vulnerabilities, based on any CVE reported publicly

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Watch now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Deploying containerized and serverless apps with Terraform

Deploying containerized and serverless apps with Terraform

Christie Koehler
DevOps with Azure

DevOps with Azure

Allen ONeill

Publisher Resources

ISBN: 50107VIDEOPAIMLOtherOtherOther