Files
service-catalog/scripts/pipeline/Dockerfile
T
wbsong111 a168a3c7e6 docs(image-authoring): CoverageProbe cov= 확인 지시 제거 + Dockerfile 경로 주석 정정
scan-sbom.sh 에 커버리지 자가진단이 없는데도 체크리스트가 cov= 확인을 지시해
같은 문서 104-106줄과 모순됐다. 실제 동작(findings 0건 시 보수적 실패)과 판단
방법으로 교체. Dockerfile 헤더 주석의 doc/scripts/ 경로도 scripts/pipeline/ 로
갱신(경로 이전 시 누락됨).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 11:25:20 +09:00

36 lines
1.6 KiB
Docker

# =============================================================================
# SBOM 파이프라인 실행 이미지
#
# .github/workflows/sbom.yml 의 `container:` (Repo Variable SBOM_PIPELINE_IMAGE)
# 로 사용되는 이미지. scripts/pipeline/*.sh 를 컨테이너 내부에서 직접 실행한다.
# 상세: doc/sbom-pipeline.md
#
# 도구: helm(v3) + trivy + python3 + bash + git
# 베이스: debian(glibc) — GitHub Actions container 안에서 node 기반 액션
# (actions/checkout, upload-artifact)이 동작하려면 glibc 필요.
# (alpine/musl 은 node 실행 실패 가능 → debian 사용)
#
# 빌드 & 푸시 (amd64 필수 — GitHub 러너가 amd64):
# docker buildx build --platform linux/amd64 \
# -t docker.io/<org>/sbom-pipeline:latest -f scripts/pipeline/Dockerfile --push scripts/pipeline
# # 이후: gh variable set SBOM_PIPELINE_IMAGE --body docker.io/<org>/sbom-pipeline:latest
# =============================================================================
FROM debian:stable-slim
RUN apt-get update && apt-get install -y --no-install-recommends \
curl ca-certificates git python3 bash \
&& rm -rf /var/lib/apt/lists/*
# helm v3
RUN curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
# trivy (최신)
RUN curl -fsSL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh \
| sh -s -- -b /usr/local/bin
# 설치 확인 (빌드 시 도구 누락 조기 감지)
RUN helm version --short && trivy --version | head -1 && python3 --version && git --version
ENTRYPOINT []
CMD ["bash"]