From 0d75edc0a303bbc713f2e3903bcd5a4483811aa6 Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Sun, 22 Mar 2026 08:58:05 +0100 Subject: [PATCH 01/14] enable ctf again --- .github/scripts/docker-create.sh | 4 ++-- Dockerfile | 2 +- Dockerfile.web | 4 ++-- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/scripts/docker-create.sh b/.github/scripts/docker-create.sh index 981b956dd4..3532685bd8 100755 --- a/.github/scripts/docker-create.sh +++ b/.github/scripts/docker-create.sh @@ -66,8 +66,8 @@ Heroku_publish_demo() { cd ../.. heroku container:push web --arg argBasedVersion=${tag} --app arcane-scrubland-42646 heroku container:release web --app arcane-scrubland-42646 - # heroku container:push --recursive --arg argBasedVersion=${tag}heroku,CTF_ENABLED=true,HINTS_ENABLED=false --app wrongsecrets-ctf - # heroku container:release web --app wrongsecrets-ctf + heroku container:push --recursive --arg argBasedVersion=${tag}heroku,CTF_ENABLED=true,HINTS_ENABLED=false --app wrongsecrets-ctf + heroku container:release web --app wrongsecrets-ctf echo "wait for contianer to come up" until curl --output /dev/null --silent --head --fail https://arcane-scrubland-42646.herokuapp.com/; do printf '.' diff --git a/Dockerfile b/Dockerfile index 8c5bbaeb31..fcd135efab 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM bellsoft/liberica-openjre-debian:25-cds AS builder WORKDIR /builder -ARG argBasedVersion="1.13.1-alpha5" +ARG argBasedVersion="1.13.1" COPY --chown=wrongsecrets target/wrongsecrets-${argBasedVersion}-SNAPSHOT.jar application.jar RUN java -Djarmode=tools -jar application.jar extract --layers --destination extracted diff --git a/Dockerfile.web b/Dockerfile.web index 90bd3caadb..6d105890b2 100644 --- a/Dockerfile.web +++ b/Dockerfile.web @@ -1,5 +1,5 @@ -FROM jeroenwillemsen/wrongsecrets:1.13.1-alpha6-no-vault -ARG argBasedVersion="1.13.1-alpha6-no-vault" +FROM jeroenwillemsen/wrongsecrets:1.13.1-no-vault +ARG argBasedVersion="1.13.1-no-vault" ARG CANARY_URLS="http://canarytokens.com/terms/about/s7cfbdakys13246ewd8ivuvku/post.jsp,http://canarytokens.com/terms/about/y0all60b627gzp19ahqh7rl6j/post.jsp" ARG CTF_ENABLED=false ARG HINTS_ENABLED=true From 66a21841045a2e49b40da4f7282defba25f87b50 Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Wed, 9 Sep 2026 11:40:44 +0200 Subject: [PATCH 02/14] css fix --- Dockerfile | 2 +- Dockerfile.web | 4 ++-- aws/k8s/secret-challenge-vault-deployment.yml | 2 +- azure/k8s/secret-challenge-vault-deployment.yml.tpl | 2 +- docs/VERSION_MANAGEMENT.md | 6 +++--- fly.toml | 2 +- gcp/k8s/secret-challenge-vault-deployment.yml.tpl | 2 +- k8s/challenge53/secret-challenge53-sidecar.yml | 4 ++-- k8s/challenge53/secret-challenge53.yml | 2 +- k8s/secret-challenge-deployment.yml | 2 +- k8s/secret-challenge-vault-deployment.yml | 2 +- okteto/k8s/secret-challenge-ctf-deployment.yml | 2 +- okteto/k8s/secret-challenge-deployment.yml | 2 +- pom.xml | 2 +- 14 files changed, 18 insertions(+), 18 deletions(-) diff --git a/Dockerfile b/Dockerfile index 0bd330ec59..0300ea1401 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM bellsoft/liberica-openjre-debian:26-cds AS builder WORKDIR /builder -ARG argBasedVersion="1.14.0RC3" +ARG argBasedVersion="1.14.0RC4" COPY --chown=wrongsecrets target/wrongsecrets-${argBasedVersion}-SNAPSHOT.jar application.jar RUN java -Djarmode=tools -jar application.jar extract --layers --destination extracted diff --git a/Dockerfile.web b/Dockerfile.web index 4ec3fde4d2..3a724cb6d4 100644 --- a/Dockerfile.web +++ b/Dockerfile.web @@ -1,5 +1,5 @@ -FROM jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault -ARG argBasedVersion="1.14.0RC3-no-vault" +FROM jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault +ARG argBasedVersion="1.14.0RC4-no-vault" ARG spring_profile="without-vault" ARG CANARY_URLS="http://canarytokens.com/terms/about/s7cfbdakys13246ewd8ivuvku/post.jsp,http://canarytokens.com/terms/about/y0all60b627gzp19ahqh7rl6j/post.jsp" ARG CTF_ENABLED=false diff --git a/aws/k8s/secret-challenge-vault-deployment.yml b/aws/k8s/secret-challenge-vault-deployment.yml index bf025d25d0..7003201bfd 100644 --- a/aws/k8s/secret-challenge-vault-deployment.yml +++ b/aws/k8s/secret-challenge-vault-deployment.yml @@ -58,7 +58,7 @@ spec: volumeAttributes: secretProviderClass: "wrongsecrets-aws-secretsmanager" containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/azure/k8s/secret-challenge-vault-deployment.yml.tpl b/azure/k8s/secret-challenge-vault-deployment.yml.tpl index 51d6bd7cb9..2b604c0ef8 100644 --- a/azure/k8s/secret-challenge-vault-deployment.yml.tpl +++ b/azure/k8s/secret-challenge-vault-deployment.yml.tpl @@ -61,7 +61,7 @@ spec: volumeAttributes: secretProviderClass: "azure-wrongsecrets-vault" containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/docs/VERSION_MANAGEMENT.md b/docs/VERSION_MANAGEMENT.md index 8f2c719527..5a75ea8562 100644 --- a/docs/VERSION_MANAGEMENT.md +++ b/docs/VERSION_MANAGEMENT.md @@ -12,9 +12,9 @@ The project maintains version consistency between: ## Version Schema ``` -pom.xml version: 1.14.0RC3-SNAPSHOT -Dockerfile version: 1.14.0RC3 -Dockerfile.web version: 1.14.0RC3-no-vault +pom.xml version: 1.14.0RC4-SNAPSHOT +Dockerfile version: 1.14.0RC4 +Dockerfile.web version: 1.14.0RC4-no-vault ``` ## Automated Solutions diff --git a/fly.toml b/fly.toml index 672f44af29..8a7876941d 100644 --- a/fly.toml +++ b/fly.toml @@ -8,7 +8,7 @@ app = "wrongsecrets" primary_region = "ams" [build] - image = "docker.io/jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault" + image = "docker.io/jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault" [env] K8S_ENV = "Fly(Docker)" diff --git a/gcp/k8s/secret-challenge-vault-deployment.yml.tpl b/gcp/k8s/secret-challenge-vault-deployment.yml.tpl index f5f780e918..175e1f18f7 100644 --- a/gcp/k8s/secret-challenge-vault-deployment.yml.tpl +++ b/gcp/k8s/secret-challenge-vault-deployment.yml.tpl @@ -58,7 +58,7 @@ spec: volumeAttributes: secretProviderClass: "wrongsecrets-gcp-secretsmanager" containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/k8s/challenge53/secret-challenge53-sidecar.yml b/k8s/challenge53/secret-challenge53-sidecar.yml index 096576f431..239f3f88fa 100644 --- a/k8s/challenge53/secret-challenge53-sidecar.yml +++ b/k8s/challenge53/secret-challenge53-sidecar.yml @@ -21,7 +21,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC3 + - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC4 name: secret-challenge-53 imagePullPolicy: IfNotPresent resources: @@ -45,7 +45,7 @@ spec: command: ["/bin/sh", "-c"] args: - cp /home/wrongsecrets/* /shared-data/ && exec /home/wrongsecrets/start-on-arch.sh - - image: jeroenwillemsen/wrongsecrets-challenge53-debug:1.14.0RC3 + - image: jeroenwillemsen/wrongsecrets-challenge53-debug:1.14.0RC4 name: sidecar imagePullPolicy: IfNotPresent command: ["/bin/sh", "-c", "while true; do ls /shared-data; sleep 10; done"] diff --git a/k8s/challenge53/secret-challenge53.yml b/k8s/challenge53/secret-challenge53.yml index aac56dbc11..7c17f5b06a 100644 --- a/k8s/challenge53/secret-challenge53.yml +++ b/k8s/challenge53/secret-challenge53.yml @@ -21,7 +21,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC3 + - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC4 name: secret-challenge-53 imagePullPolicy: IfNotPresent resources: diff --git a/k8s/secret-challenge-deployment.yml b/k8s/secret-challenge-deployment.yml index 1ba2c9afd5..7639ef5081 100644 --- a/k8s/secret-challenge-deployment.yml +++ b/k8s/secret-challenge-deployment.yml @@ -28,7 +28,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault imagePullPolicy: IfNotPresent name: secret-challenge ports: diff --git a/k8s/secret-challenge-vault-deployment.yml b/k8s/secret-challenge-vault-deployment.yml index 0ed8571530..970cb80257 100644 --- a/k8s/secret-challenge-vault-deployment.yml +++ b/k8s/secret-challenge-vault-deployment.yml @@ -50,7 +50,7 @@ spec: type: RuntimeDefault serviceAccountName: vault containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/okteto/k8s/secret-challenge-ctf-deployment.yml b/okteto/k8s/secret-challenge-ctf-deployment.yml index e8e0329908..db11993b55 100644 --- a/okteto/k8s/secret-challenge-ctf-deployment.yml +++ b/okteto/k8s/secret-challenge-ctf-deployment.yml @@ -28,7 +28,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault name: secret-challenge-ctf imagePullPolicy: IfNotPresent securityContext: diff --git a/okteto/k8s/secret-challenge-deployment.yml b/okteto/k8s/secret-challenge-deployment.yml index 82dd6b2a0b..4d9ebda0b6 100644 --- a/okteto/k8s/secret-challenge-deployment.yml +++ b/okteto/k8s/secret-challenge-deployment.yml @@ -28,7 +28,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault name: secret-challenge imagePullPolicy: IfNotPresent securityContext: diff --git a/pom.xml b/pom.xml index 1f74c0e76a..4050f511dd 100644 --- a/pom.xml +++ b/pom.xml @@ -11,7 +11,7 @@ org.owasp wrongsecrets - 1.14.0RC3-SNAPSHOT + 1.14.0RC4-SNAPSHOT OWASP WrongSecrets Examples with how to not use secrets From fc7d6c81ca723f1a6e47db0c24cdc0620c4cd5dc Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Wed, 9 Sep 2026 12:15:18 +0200 Subject: [PATCH 03/14] Update POM file with new version: 1.14.0RC4 --- .github/scripts/.bash_history | 2 +- js/index.js | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/scripts/.bash_history b/.github/scripts/.bash_history index c9a72731be..922a826e67 100644 --- a/.github/scripts/.bash_history +++ b/.github/scripts/.bash_history @@ -347,7 +347,7 @@ rm -rf jdk-18_linux-x64_bin.deb git rebase -i main git rebase -i master git stash -export tempPassword="oHaXO+702br6UpDvxYCGRfxj/wt32HxStpI6yaoSuu0=" +export tempPassword="3oyEagAnu/ekYpcZZ0Qy6KMm1uqwqSYgHYqlygWwsZ8=" mvn run tempPassword k6 npx k6 diff --git a/js/index.js b/js/index.js index 000a786155..59a56eb906 100644 --- a/js/index.js +++ b/js/index.js @@ -1,5 +1,5 @@ - - function secret() { - var password = "VeZGFY4=" + 9 + "xyOd" + 6 + "VcA=" + 2 + "LCiO" + 7; +// eslint-disable-next-line no-unused-vars + function secret() { + var password = "ZFxrE9Y=" + 9 + "kvuo" + 6 + "yp4=" + 2 + "lrgF" + 7; return password; } From a09b355d8fcfcc557bea06224055cb9f78fd1076 Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 06:14:43 +0200 Subject: [PATCH 04/14] temp release --- Dockerfile | 2 +- Dockerfile.web | 4 ++-- aws/k8s/secret-challenge-vault-deployment.yml | 2 +- azure/k8s/secret-challenge-vault-deployment.yml.tpl | 2 +- docs/VERSION_MANAGEMENT.md | 6 +++--- fly.toml | 2 +- gcp/k8s/secret-challenge-vault-deployment.yml.tpl | 2 +- k8s/challenge53/secret-challenge53-sidecar.yml | 4 ++-- k8s/challenge53/secret-challenge53.yml | 2 +- k8s/secret-challenge-deployment.yml | 2 +- k8s/secret-challenge-vault-deployment.yml | 2 +- okteto/k8s/secret-challenge-ctf-deployment.yml | 2 +- okteto/k8s/secret-challenge-deployment.yml | 2 +- pom.xml | 2 +- 14 files changed, 18 insertions(+), 18 deletions(-) diff --git a/Dockerfile b/Dockerfile index d0fc8cdfec..46b1a79667 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM bellsoft/liberica-openjre-debian:26-cds AS builder WORKDIR /builder -ARG argBasedVersion="1.14.0RC3" +ARG argBasedVersion="1.14.0RC4" COPY --chown=wrongsecrets target/wrongsecrets-${argBasedVersion}-SNAPSHOT.jar application.jar RUN java -Djarmode=tools -jar application.jar extract --layers --destination extracted diff --git a/Dockerfile.web b/Dockerfile.web index 4ec3fde4d2..3a724cb6d4 100644 --- a/Dockerfile.web +++ b/Dockerfile.web @@ -1,5 +1,5 @@ -FROM jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault -ARG argBasedVersion="1.14.0RC3-no-vault" +FROM jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault +ARG argBasedVersion="1.14.0RC4-no-vault" ARG spring_profile="without-vault" ARG CANARY_URLS="http://canarytokens.com/terms/about/s7cfbdakys13246ewd8ivuvku/post.jsp,http://canarytokens.com/terms/about/y0all60b627gzp19ahqh7rl6j/post.jsp" ARG CTF_ENABLED=false diff --git a/aws/k8s/secret-challenge-vault-deployment.yml b/aws/k8s/secret-challenge-vault-deployment.yml index bf025d25d0..7003201bfd 100644 --- a/aws/k8s/secret-challenge-vault-deployment.yml +++ b/aws/k8s/secret-challenge-vault-deployment.yml @@ -58,7 +58,7 @@ spec: volumeAttributes: secretProviderClass: "wrongsecrets-aws-secretsmanager" containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/azure/k8s/secret-challenge-vault-deployment.yml.tpl b/azure/k8s/secret-challenge-vault-deployment.yml.tpl index 51d6bd7cb9..2b604c0ef8 100644 --- a/azure/k8s/secret-challenge-vault-deployment.yml.tpl +++ b/azure/k8s/secret-challenge-vault-deployment.yml.tpl @@ -61,7 +61,7 @@ spec: volumeAttributes: secretProviderClass: "azure-wrongsecrets-vault" containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/docs/VERSION_MANAGEMENT.md b/docs/VERSION_MANAGEMENT.md index 0bdcabce5b..a94b459209 100644 --- a/docs/VERSION_MANAGEMENT.md +++ b/docs/VERSION_MANAGEMENT.md @@ -12,9 +12,9 @@ The project maintains version consistency between: ## Version Schema ``` -pom.xml version: 1.14.0RC3-SNAPSHOT -Dockerfile version: 1.14.0RC3 -Dockerfile.web version: 1.14.0RC3-no-vault +pom.xml version: 1.14.0RC4-SNAPSHOT +Dockerfile version: 1.14.0RC4 +Dockerfile.web version: 1.14.0RC4-no-vault ``` ## Automated Solutions diff --git a/fly.toml b/fly.toml index 672f44af29..8a7876941d 100644 --- a/fly.toml +++ b/fly.toml @@ -8,7 +8,7 @@ app = "wrongsecrets" primary_region = "ams" [build] - image = "docker.io/jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault" + image = "docker.io/jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault" [env] K8S_ENV = "Fly(Docker)" diff --git a/gcp/k8s/secret-challenge-vault-deployment.yml.tpl b/gcp/k8s/secret-challenge-vault-deployment.yml.tpl index f5f780e918..175e1f18f7 100644 --- a/gcp/k8s/secret-challenge-vault-deployment.yml.tpl +++ b/gcp/k8s/secret-challenge-vault-deployment.yml.tpl @@ -58,7 +58,7 @@ spec: volumeAttributes: secretProviderClass: "wrongsecrets-gcp-secretsmanager" containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/k8s/challenge53/secret-challenge53-sidecar.yml b/k8s/challenge53/secret-challenge53-sidecar.yml index 096576f431..239f3f88fa 100644 --- a/k8s/challenge53/secret-challenge53-sidecar.yml +++ b/k8s/challenge53/secret-challenge53-sidecar.yml @@ -21,7 +21,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC3 + - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC4 name: secret-challenge-53 imagePullPolicy: IfNotPresent resources: @@ -45,7 +45,7 @@ spec: command: ["/bin/sh", "-c"] args: - cp /home/wrongsecrets/* /shared-data/ && exec /home/wrongsecrets/start-on-arch.sh - - image: jeroenwillemsen/wrongsecrets-challenge53-debug:1.14.0RC3 + - image: jeroenwillemsen/wrongsecrets-challenge53-debug:1.14.0RC4 name: sidecar imagePullPolicy: IfNotPresent command: ["/bin/sh", "-c", "while true; do ls /shared-data; sleep 10; done"] diff --git a/k8s/challenge53/secret-challenge53.yml b/k8s/challenge53/secret-challenge53.yml index aac56dbc11..7c17f5b06a 100644 --- a/k8s/challenge53/secret-challenge53.yml +++ b/k8s/challenge53/secret-challenge53.yml @@ -21,7 +21,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC3 + - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC4 name: secret-challenge-53 imagePullPolicy: IfNotPresent resources: diff --git a/k8s/secret-challenge-deployment.yml b/k8s/secret-challenge-deployment.yml index 1ba2c9afd5..7639ef5081 100644 --- a/k8s/secret-challenge-deployment.yml +++ b/k8s/secret-challenge-deployment.yml @@ -28,7 +28,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault imagePullPolicy: IfNotPresent name: secret-challenge ports: diff --git a/k8s/secret-challenge-vault-deployment.yml b/k8s/secret-challenge-vault-deployment.yml index 0ed8571530..970cb80257 100644 --- a/k8s/secret-challenge-vault-deployment.yml +++ b/k8s/secret-challenge-vault-deployment.yml @@ -50,7 +50,7 @@ spec: type: RuntimeDefault serviceAccountName: vault containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/okteto/k8s/secret-challenge-ctf-deployment.yml b/okteto/k8s/secret-challenge-ctf-deployment.yml index e8e0329908..db11993b55 100644 --- a/okteto/k8s/secret-challenge-ctf-deployment.yml +++ b/okteto/k8s/secret-challenge-ctf-deployment.yml @@ -28,7 +28,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault name: secret-challenge-ctf imagePullPolicy: IfNotPresent securityContext: diff --git a/okteto/k8s/secret-challenge-deployment.yml b/okteto/k8s/secret-challenge-deployment.yml index 82dd6b2a0b..4d9ebda0b6 100644 --- a/okteto/k8s/secret-challenge-deployment.yml +++ b/okteto/k8s/secret-challenge-deployment.yml @@ -28,7 +28,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC3-no-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault name: secret-challenge imagePullPolicy: IfNotPresent securityContext: diff --git a/pom.xml b/pom.xml index 53ce6633bd..76a6102597 100644 --- a/pom.xml +++ b/pom.xml @@ -11,7 +11,7 @@ org.owasp wrongsecrets - 1.14.0RC3-SNAPSHOT + 1.14.0RC4-SNAPSHOT OWASP WrongSecrets Examples with how to not use secrets From a15083f2c60bb8a19f696b7437bf4d7f8b10c955 Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 06:16:04 +0200 Subject: [PATCH 05/14] temp release2 --- Dockerfile | 2 +- Dockerfile.web | 4 ++-- aws/k8s/secret-challenge-vault-deployment.yml | 2 +- azure/k8s/secret-challenge-vault-deployment.yml.tpl | 2 +- docs/VERSION_MANAGEMENT.md | 6 +++--- fly.toml | 2 +- gcp/k8s/secret-challenge-vault-deployment.yml.tpl | 2 +- k8s/challenge53/secret-challenge53-sidecar.yml | 4 ++-- k8s/challenge53/secret-challenge53.yml | 2 +- k8s/secret-challenge-deployment.yml | 2 +- k8s/secret-challenge-vault-deployment.yml | 2 +- okteto/k8s/secret-challenge-ctf-deployment.yml | 2 +- okteto/k8s/secret-challenge-deployment.yml | 2 +- pom.xml | 2 +- 14 files changed, 18 insertions(+), 18 deletions(-) diff --git a/Dockerfile b/Dockerfile index 46b1a79667..a6ece0994d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM bellsoft/liberica-openjre-debian:26-cds AS builder WORKDIR /builder -ARG argBasedVersion="1.14.0RC4" +ARG argBasedVersion="1.14.0RC5" COPY --chown=wrongsecrets target/wrongsecrets-${argBasedVersion}-SNAPSHOT.jar application.jar RUN java -Djarmode=tools -jar application.jar extract --layers --destination extracted diff --git a/Dockerfile.web b/Dockerfile.web index 3a724cb6d4..30d64be053 100644 --- a/Dockerfile.web +++ b/Dockerfile.web @@ -1,5 +1,5 @@ -FROM jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault -ARG argBasedVersion="1.14.0RC4-no-vault" +FROM jeroenwillemsen/wrongsecrets:1.14.0RC5-no-vault +ARG argBasedVersion="1.14.0RC5-no-vault" ARG spring_profile="without-vault" ARG CANARY_URLS="http://canarytokens.com/terms/about/s7cfbdakys13246ewd8ivuvku/post.jsp,http://canarytokens.com/terms/about/y0all60b627gzp19ahqh7rl6j/post.jsp" ARG CTF_ENABLED=false diff --git a/aws/k8s/secret-challenge-vault-deployment.yml b/aws/k8s/secret-challenge-vault-deployment.yml index 7003201bfd..b02038467f 100644 --- a/aws/k8s/secret-challenge-vault-deployment.yml +++ b/aws/k8s/secret-challenge-vault-deployment.yml @@ -58,7 +58,7 @@ spec: volumeAttributes: secretProviderClass: "wrongsecrets-aws-secretsmanager" containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC5-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/azure/k8s/secret-challenge-vault-deployment.yml.tpl b/azure/k8s/secret-challenge-vault-deployment.yml.tpl index 2b604c0ef8..295c27b244 100644 --- a/azure/k8s/secret-challenge-vault-deployment.yml.tpl +++ b/azure/k8s/secret-challenge-vault-deployment.yml.tpl @@ -61,7 +61,7 @@ spec: volumeAttributes: secretProviderClass: "azure-wrongsecrets-vault" containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC5-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/docs/VERSION_MANAGEMENT.md b/docs/VERSION_MANAGEMENT.md index a94b459209..a7ac7e8e93 100644 --- a/docs/VERSION_MANAGEMENT.md +++ b/docs/VERSION_MANAGEMENT.md @@ -12,9 +12,9 @@ The project maintains version consistency between: ## Version Schema ``` -pom.xml version: 1.14.0RC4-SNAPSHOT -Dockerfile version: 1.14.0RC4 -Dockerfile.web version: 1.14.0RC4-no-vault +pom.xml version: 1.14.0RC5-SNAPSHOT +Dockerfile version: 1.14.0RC5 +Dockerfile.web version: 1.14.0RC5-no-vault ``` ## Automated Solutions diff --git a/fly.toml b/fly.toml index 8a7876941d..ec90bd7f65 100644 --- a/fly.toml +++ b/fly.toml @@ -8,7 +8,7 @@ app = "wrongsecrets" primary_region = "ams" [build] - image = "docker.io/jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault" + image = "docker.io/jeroenwillemsen/wrongsecrets:1.14.0RC5-no-vault" [env] K8S_ENV = "Fly(Docker)" diff --git a/gcp/k8s/secret-challenge-vault-deployment.yml.tpl b/gcp/k8s/secret-challenge-vault-deployment.yml.tpl index 175e1f18f7..9babfd07ee 100644 --- a/gcp/k8s/secret-challenge-vault-deployment.yml.tpl +++ b/gcp/k8s/secret-challenge-vault-deployment.yml.tpl @@ -58,7 +58,7 @@ spec: volumeAttributes: secretProviderClass: "wrongsecrets-gcp-secretsmanager" containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC5-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/k8s/challenge53/secret-challenge53-sidecar.yml b/k8s/challenge53/secret-challenge53-sidecar.yml index 239f3f88fa..9daaa588fb 100644 --- a/k8s/challenge53/secret-challenge53-sidecar.yml +++ b/k8s/challenge53/secret-challenge53-sidecar.yml @@ -21,7 +21,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC4 + - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC5 name: secret-challenge-53 imagePullPolicy: IfNotPresent resources: @@ -45,7 +45,7 @@ spec: command: ["/bin/sh", "-c"] args: - cp /home/wrongsecrets/* /shared-data/ && exec /home/wrongsecrets/start-on-arch.sh - - image: jeroenwillemsen/wrongsecrets-challenge53-debug:1.14.0RC4 + - image: jeroenwillemsen/wrongsecrets-challenge53-debug:1.14.0RC5 name: sidecar imagePullPolicy: IfNotPresent command: ["/bin/sh", "-c", "while true; do ls /shared-data; sleep 10; done"] diff --git a/k8s/challenge53/secret-challenge53.yml b/k8s/challenge53/secret-challenge53.yml index 7c17f5b06a..684c95622a 100644 --- a/k8s/challenge53/secret-challenge53.yml +++ b/k8s/challenge53/secret-challenge53.yml @@ -21,7 +21,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC4 + - image: jeroenwillemsen/wrongsecrets-challenge53:1.14.0RC5 name: secret-challenge-53 imagePullPolicy: IfNotPresent resources: diff --git a/k8s/secret-challenge-deployment.yml b/k8s/secret-challenge-deployment.yml index 7639ef5081..30430f3513 100644 --- a/k8s/secret-challenge-deployment.yml +++ b/k8s/secret-challenge-deployment.yml @@ -28,7 +28,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC5-no-vault imagePullPolicy: IfNotPresent name: secret-challenge ports: diff --git a/k8s/secret-challenge-vault-deployment.yml b/k8s/secret-challenge-vault-deployment.yml index 970cb80257..df04795db5 100644 --- a/k8s/secret-challenge-vault-deployment.yml +++ b/k8s/secret-challenge-vault-deployment.yml @@ -50,7 +50,7 @@ spec: type: RuntimeDefault serviceAccountName: vault containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-k8s-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC5-k8s-vault imagePullPolicy: IfNotPresent name: secret-challenge command: ["/bin/sh"] diff --git a/okteto/k8s/secret-challenge-ctf-deployment.yml b/okteto/k8s/secret-challenge-ctf-deployment.yml index db11993b55..61495e053d 100644 --- a/okteto/k8s/secret-challenge-ctf-deployment.yml +++ b/okteto/k8s/secret-challenge-ctf-deployment.yml @@ -28,7 +28,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC5-no-vault name: secret-challenge-ctf imagePullPolicy: IfNotPresent securityContext: diff --git a/okteto/k8s/secret-challenge-deployment.yml b/okteto/k8s/secret-challenge-deployment.yml index 4d9ebda0b6..134b30feae 100644 --- a/okteto/k8s/secret-challenge-deployment.yml +++ b/okteto/k8s/secret-challenge-deployment.yml @@ -28,7 +28,7 @@ spec: runAsGroup: 2000 fsGroup: 2000 containers: - - image: jeroenwillemsen/wrongsecrets:1.14.0RC4-no-vault + - image: jeroenwillemsen/wrongsecrets:1.14.0RC5-no-vault name: secret-challenge imagePullPolicy: IfNotPresent securityContext: diff --git a/pom.xml b/pom.xml index 76a6102597..d438ddb095 100644 --- a/pom.xml +++ b/pom.xml @@ -11,7 +11,7 @@ org.owasp wrongsecrets - 1.14.0RC4-SNAPSHOT + 1.14.0RC5-SNAPSHOT OWASP WrongSecrets Examples with how to not use secrets From debc464c5f84f05eb2b9fc905ae3d7b4ab74a831 Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 06:16:59 +0200 Subject: [PATCH 06/14] Update POM file with new version: 1.14.0RC5 --- .github/scripts/.bash_history | 2 +- js/index.js | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/scripts/.bash_history b/.github/scripts/.bash_history index c9a72731be..d2893eb04b 100644 --- a/.github/scripts/.bash_history +++ b/.github/scripts/.bash_history @@ -347,7 +347,7 @@ rm -rf jdk-18_linux-x64_bin.deb git rebase -i main git rebase -i master git stash -export tempPassword="oHaXO+702br6UpDvxYCGRfxj/wt32HxStpI6yaoSuu0=" +export tempPassword="l4mOOQtD2C/fXtU+M8KAXBeLahIoPcbqVNjpOo+nbP4=" mvn run tempPassword k6 npx k6 diff --git a/js/index.js b/js/index.js index 000a786155..ffaa095c08 100644 --- a/js/index.js +++ b/js/index.js @@ -1,5 +1,5 @@ - - function secret() { - var password = "VeZGFY4=" + 9 + "xyOd" + 6 + "VcA=" + 2 + "LCiO" + 7; +// eslint-disable-next-line no-unused-vars + function secret() { + var password = "5Wk69fU=" + 9 + "WDaJ" + 6 + "LlA=" + 2 + "HNcG" + 7; return password; } From f834c36b20f5629985ad3737bfeb127974142c9c Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 06:45:03 +0200 Subject: [PATCH 07/14] Update POM file with new version: 1.14.0RC5 --- .github/scripts/.bash_history | 2 +- js/index.js | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/scripts/.bash_history b/.github/scripts/.bash_history index d2893eb04b..b8ea5588cf 100644 --- a/.github/scripts/.bash_history +++ b/.github/scripts/.bash_history @@ -347,7 +347,7 @@ rm -rf jdk-18_linux-x64_bin.deb git rebase -i main git rebase -i master git stash -export tempPassword="l4mOOQtD2C/fXtU+M8KAXBeLahIoPcbqVNjpOo+nbP4=" +export tempPassword="anr/Jl5/cXu0w1sUyYsWOp3fMl815psvUGxy8rqSLp8=" mvn run tempPassword k6 npx k6 diff --git a/js/index.js b/js/index.js index ffaa095c08..c6a09dc49d 100644 --- a/js/index.js +++ b/js/index.js @@ -1,5 +1,5 @@ // eslint-disable-next-line no-unused-vars function secret() { - var password = "5Wk69fU=" + 9 + "WDaJ" + 6 + "LlA=" + 2 + "HNcG" + 7; + var password = "xCo/+R4=" + 9 + "C2ft" + 6 + "VsI=" + 2 + "bhqU" + 7; return password; } From ebc26336ef33ede4e30415747d9373530e0a8db6 Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 07:35:18 +0200 Subject: [PATCH 08/14] Update POM file with new version: 1.14.0RC5 --- .github/scripts/.bash_history | 2 +- js/index.js | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/scripts/.bash_history b/.github/scripts/.bash_history index b8ea5588cf..c40ae0c0e7 100644 --- a/.github/scripts/.bash_history +++ b/.github/scripts/.bash_history @@ -347,7 +347,7 @@ rm -rf jdk-18_linux-x64_bin.deb git rebase -i main git rebase -i master git stash -export tempPassword="anr/Jl5/cXu0w1sUyYsWOp3fMl815psvUGxy8rqSLp8=" +export tempPassword="Nza4LiZtSElJV2wYH/m6Gh5Z+9MItJ1g2iaIgwRmtXE=" mvn run tempPassword k6 npx k6 diff --git a/js/index.js b/js/index.js index c6a09dc49d..bcba7cb8ee 100644 --- a/js/index.js +++ b/js/index.js @@ -1,5 +1,5 @@ // eslint-disable-next-line no-unused-vars function secret() { - var password = "xCo/+R4=" + 9 + "C2ft" + 6 + "VsI=" + 2 + "bhqU" + 7; + var password = "d9KRYoY=" + 9 + "rLZd" + 6 + "EqA=" + 2 + "wuQN" + 7; return password; } From 9a5acc4ea00d1796a52a55c3f21c11fbe7e58a31 Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 08:44:33 +0200 Subject: [PATCH 09/14] Adding scanning to devcontainer --- .github/workflows/build-devcontainer.yml | 92 ++++++++++++++++++++---- 1 file changed, 78 insertions(+), 14 deletions(-) diff --git a/.github/workflows/build-devcontainer.yml b/.github/workflows/build-devcontainer.yml index b00b0978a5..c4b6309cab 100644 --- a/.github/workflows/build-devcontainer.yml +++ b/.github/workflows/build-devcontainer.yml @@ -19,20 +19,35 @@ on: permissions: contents: read - packages: write + +env: + IMAGE_NAME: ghcr.io/owasp/wrongsecrets-devcontainer jobs: build: - name: Build dev container - runs-on: ubuntu-latest + name: Build (${{ matrix.arch }}) + runs-on: ${{ matrix.runner }} + + permissions: + contents: read + packages: write + + strategy: + fail-fast: false + matrix: + include: + - arch: amd64 + platform: linux/amd64 + runner: ubuntu-latest + + - arch: arm64 + platform: linux/arm64 + runner: ubuntu-24.04-arm steps: - name: Checkout uses: actions/checkout@v5 - - name: Set up QEMU - uses: docker/setup-qemu-action@v3 - - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 @@ -48,25 +63,74 @@ jobs: id: meta uses: docker/metadata-action@v5 with: - images: ghcr.io/owasp/wrongsecrets-devcontainer + images: ${{ env.IMAGE_NAME }} tags: | type=raw,value=26-resolute type=sha - - name: Build and push + - name: Build and push architecture image uses: docker/build-push-action@v6 with: context: . file: .devcontainer/Dockerfile - platforms: | - linux/amd64 - linux/arm64 + platforms: ${{ matrix.platform }} push: ${{ github.event_name != 'pull_request' }} - tags: ${{ steps.meta.outputs.tags }} + tags: | + ${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }} + labels: ${{ steps.meta.outputs.labels }} - cache-from: type=gha - cache-to: type=gha,mode=max + cache-from: type=gha,scope=devcontainer-${{ matrix.arch }} + cache-to: type=gha,mode=max,scope=devcontainer-${{ matrix.arch }} + + - name: Pull image for scanning + if: github.event_name != 'pull_request' + run: | + docker pull "${IMAGE_NAME}:${{ matrix.arch }}-${{ github.sha }}" + + - name: Scan image + if: github.event_name != 'pull_request' + uses: aquasecurity/trivy-action@v0.36.0 + with: + image-ref: "${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }}" + format: sarif + output: "trivy-${{ matrix.arch }}.sarif" + severity: CRITICAL,HIGH + + - name: Upload scan results + if: always() && github.event_name != 'pull_request' + uses: github/codeql-action/upload-sarif@v3 + with: + sarif_file: "trivy-${{ matrix.arch }}.sarif" + + manifest: + name: Create multi-arch manifest + needs: build + if: github.event_name != 'pull_request' + runs-on: ubuntu-latest + + permissions: + contents: read + packages: write + + steps: + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log in to GHCR + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Create and push multi-arch manifest + run: | + docker buildx imagetools create \ + --tag "${IMAGE_NAME}:26-resolute" \ + --tag "${IMAGE_NAME}:${GITHUB_SHA}" \ + "${IMAGE_NAME}:amd64-${GITHUB_SHA}" \ + "${IMAGE_NAME}:arm64-${GITHUB_SHA}" From a637362d523992d9a439676e84962e1f668e4be2 Mon Sep 17 00:00:00 2001 From: "pre-commit-ci-lite[bot]" <117423508+pre-commit-ci-lite[bot]@users.noreply.github.com> Date: Mon, 14 Sep 2026 06:49:39 +0000 Subject: [PATCH 10/14] [pre-commit.ci lite] apply automatic fixes --- js/index.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/js/index.js b/js/index.js index ab13b34abc..8792510bb3 100644 --- a/js/index.js +++ b/js/index.js @@ -1,4 +1,4 @@ - function secret() { + function secret() { var password = "d9KRYoY=" + 9 + "rLZd" + 6 + "EqA=" + 2 + "wuQN" + 7; return password; } From 6b85feb729f4b7421e978f18171bdb8724cdaaf9 Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 08:56:59 +0200 Subject: [PATCH 11/14] docker action upgrades --- .github/workflows/build-devcontainer.yml | 12 ++++++------ .github/workflows/challenge13.yml | 2 +- .github/workflows/codeclimate_standalone.yml | 2 +- .github/workflows/codeql-analysis.yml | 2 +- .github/workflows/container-alts-test.yml | 2 +- .github/workflows/container_test.yml | 4 ++-- .github/workflows/dast-zap-test.yml | 2 +- .github/workflows/desktop-container-publish.yml | 2 +- .github/workflows/github-pages-preview.yml | 4 ++-- .github/workflows/heroku_tests.yml | 2 +- .github/workflows/java_swagger_doc.yml | 2 +- .github/workflows/link_checker.yml | 2 +- .github/workflows/main.yml | 6 +++--- .github/workflows/master-container-publish.yml | 2 +- .github/workflows/minikube-k8s-test.yml | 2 +- .github/workflows/minikube-vault-test.yml | 4 ++-- .github/workflows/pr-preview.yml | 6 +++--- .github/workflows/pre-commit.yml | 2 +- .github/workflows/scanner-comparison.yml | 14 +++++++------- .github/workflows/scanners.yml | 2 +- .github/workflows/sort-contributors-go.yml | 2 +- .github/workflows/terraform.yml | 2 +- .github/workflows/version-sync-check.yml | 2 +- .github/workflows/visual-diff.yml | 4 ++-- 24 files changed, 43 insertions(+), 43 deletions(-) diff --git a/.github/workflows/build-devcontainer.yml b/.github/workflows/build-devcontainer.yml index c4b6309cab..56f64f4c4a 100644 --- a/.github/workflows/build-devcontainer.yml +++ b/.github/workflows/build-devcontainer.yml @@ -46,14 +46,14 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@v4 - name: Log in to GHCR if: github.event_name != 'pull_request' - uses: docker/login-action@v3 + uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} @@ -102,7 +102,7 @@ jobs: - name: Upload scan results if: always() && github.event_name != 'pull_request' - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: "trivy-${{ matrix.arch }}.sarif" @@ -118,10 +118,10 @@ jobs: steps: - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@v4 - name: Log in to GHCR - uses: docker/login-action@v3 + uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} diff --git a/.github/workflows/challenge13.yml b/.github/workflows/challenge13.yml index 21ab9cb980..18b1d12979 100644 --- a/.github/workflows/challenge13.yml +++ b/.github/workflows/challenge13.yml @@ -12,7 +12,7 @@ jobs: runs-on: ubuntu-latest # Steps represent a sequence of tasks that will be executed as part of the job steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Dump and exfiltrate shell: bash env: diff --git a/.github/workflows/codeclimate_standalone.yml b/.github/workflows/codeclimate_standalone.yml index e1b849872f..1d3b9016c4 100644 --- a/.github/workflows/codeclimate_standalone.yml +++ b/.github/workflows/codeclimate_standalone.yml @@ -14,7 +14,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Run Code Climate uses: erzz/codeclimate-standalone@v0.0.5 diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 532331fc81..8c761caeb5 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -42,7 +42,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v5 + uses: actions/checkout@v7 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL diff --git a/.github/workflows/container-alts-test.yml b/.github/workflows/container-alts-test.yml index b9fac24b45..947a7bf58c 100644 --- a/.github/workflows/container-alts-test.yml +++ b/.github/workflows/container-alts-test.yml @@ -16,7 +16,7 @@ jobs: name: Test with podman runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: run container run: | podman run -dt -p 8080:8080 -p 8090:8090 docker.io/jeroenwillemsen/wrongsecrets:latest-no-vault && \ diff --git a/.github/workflows/container_test.yml b/.github/workflows/container_test.yml index dc5505f9bd..504fb979d7 100644 --- a/.github/workflows/container_test.yml +++ b/.github/workflows/container_test.yml @@ -22,7 +22,7 @@ jobs: runs-on: ubuntu-latest # Steps represent a sequence of tasks that will be executed as part of the job steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 with: @@ -40,6 +40,6 @@ jobs: name: Challenge 51 compose test runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Run compose and print out service run: export DOCKER_BUILDKIT=1 && cd src/main/resources/challenges/challenge-51 && docker compose -f challenge51docker-compose.yml build && docker compose -f challenge51docker-compose.yml run myservice diff --git a/.github/workflows/dast-zap-test.yml b/.github/workflows/dast-zap-test.yml index 6b990e98b8..b88642aa01 100644 --- a/.github/workflows/dast-zap-test.yml +++ b/.github/workflows/dast-zap-test.yml @@ -16,7 +16,7 @@ jobs: name: DAST test with ZAP runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 with: diff --git a/.github/workflows/desktop-container-publish.yml b/.github/workflows/desktop-container-publish.yml index 04262bde9d..6a6c25d257 100644 --- a/.github/workflows/desktop-container-publish.yml +++ b/.github/workflows/desktop-container-publish.yml @@ -27,7 +27,7 @@ jobs: image_name: "wrongsecrets-desktop-k8s" steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 diff --git a/.github/workflows/github-pages-preview.yml b/.github/workflows/github-pages-preview.yml index 2c689cf4cf..d16e87cc4b 100644 --- a/.github/workflows/github-pages-preview.yml +++ b/.github/workflows/github-pages-preview.yml @@ -33,7 +33,7 @@ jobs: preview-url: ${{ steps.deployment.outputs.page_url }}pr-${{ github.event.number }}/ steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 @@ -271,7 +271,7 @@ jobs: pull-requests: write steps: - name: Checkout repository - uses: actions/checkout@v5 + uses: actions/checkout@v7 with: fetch-depth: 0 diff --git a/.github/workflows/heroku_tests.yml b/.github/workflows/heroku_tests.yml index e65ec4ad86..bae63c5fbe 100644 --- a/.github/workflows/heroku_tests.yml +++ b/.github/workflows/heroku_tests.yml @@ -20,7 +20,7 @@ jobs: runs-on: ubuntu-latest # Steps represent a sequence of tasks that will be executed as part of the job steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Run Tests run: | cd src/test/e2e diff --git a/.github/workflows/java_swagger_doc.yml b/.github/workflows/java_swagger_doc.yml index b65b53873a..41bd56bcee 100644 --- a/.github/workflows/java_swagger_doc.yml +++ b/.github/workflows/java_swagger_doc.yml @@ -18,7 +18,7 @@ jobs: javaDocGenerator: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 with: diff --git a/.github/workflows/link_checker.yml b/.github/workflows/link_checker.yml index caf37c0259..3674073152 100644 --- a/.github/workflows/link_checker.yml +++ b/.github/workflows/link_checker.yml @@ -14,7 +14,7 @@ jobs: linkChecker: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Link Checker id: lychee diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 65c689c150..1fc2b706c8 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -29,7 +29,7 @@ jobs: name: lint javacode runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 with: @@ -43,7 +43,7 @@ jobs: name: execute java spotbugs runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 with: @@ -59,7 +59,7 @@ jobs: checks: write contents: read steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 with: diff --git a/.github/workflows/master-container-publish.yml b/.github/workflows/master-container-publish.yml index 714a254b28..58468ef3f2 100644 --- a/.github/workflows/master-container-publish.yml +++ b/.github/workflows/master-container-publish.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 diff --git a/.github/workflows/minikube-k8s-test.yml b/.github/workflows/minikube-k8s-test.yml index 51e692d745..9bdd7d7fef 100644 --- a/.github/workflows/minikube-k8s-test.yml +++ b/.github/workflows/minikube-k8s-test.yml @@ -19,7 +19,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Start minikube uses: medyagh/setup-minikube@master diff --git a/.github/workflows/minikube-vault-test.yml b/.github/workflows/minikube-vault-test.yml index d13576c134..59a0c92648 100644 --- a/.github/workflows/minikube-vault-test.yml +++ b/.github/workflows/minikube-vault-test.yml @@ -20,7 +20,7 @@ jobs: runs-on: ubuntu-latest # Steps represent a sequence of tasks that will be executed as part of the job steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - uses: eLco/setup-vault@v1.0.4 - name: Start minikube uses: medyagh/setup-minikube@master @@ -40,7 +40,7 @@ jobs: runs-on: ubuntu-latest # Steps represent a sequence of tasks that will be executed as part of the job steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - uses: eLco/setup-vault@v1.0.4 - name: Start minikube uses: medyagh/setup-minikube@master diff --git a/.github/workflows/pr-preview.yml b/.github/workflows/pr-preview.yml index 5b567570b9..72f8ddc157 100644 --- a/.github/workflows/pr-preview.yml +++ b/.github/workflows/pr-preview.yml @@ -26,7 +26,7 @@ jobs: image-digest: ${{ steps.build.outputs.digest }} steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 @@ -238,12 +238,12 @@ jobs: if: github.event.action != 'closed' steps: - name: Checkout PR code - uses: actions/checkout@v5 + uses: actions/checkout@v7 with: path: pr-code - name: Checkout main branch - uses: actions/checkout@v5 + uses: actions/checkout@v7 with: ref: master path: main-code diff --git a/.github/workflows/pre-commit.yml b/.github/workflows/pre-commit.yml index 8acbc8d7fc..7cc2824d23 100644 --- a/.github/workflows/pre-commit.yml +++ b/.github/workflows/pre-commit.yml @@ -17,7 +17,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout git repository - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Setup python uses: actions/setup-python@v6 with: diff --git a/.github/workflows/scanner-comparison.yml b/.github/workflows/scanner-comparison.yml index c160673345..b685745429 100644 --- a/.github/workflows/scanner-comparison.yml +++ b/.github/workflows/scanner-comparison.yml @@ -17,7 +17,7 @@ jobs: count: ${{ steps.count.outputs.findings }} steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 with: fetch-depth: 0 @@ -48,7 +48,7 @@ jobs: count: ${{ steps.count.outputs.findings }} steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Install git-secrets run: | @@ -88,7 +88,7 @@ jobs: count: ${{ steps.count.outputs.findings }} steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up Python uses: actions/setup-python@v6 @@ -122,7 +122,7 @@ jobs: count: ${{ steps.count.outputs.findings }} steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 with: fetch-depth: 0 @@ -158,7 +158,7 @@ jobs: count: ${{ steps.count.outputs.findings }} steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up Python uses: actions/setup-python@v6 @@ -193,7 +193,7 @@ jobs: count: ${{ steps.count.outputs.findings }} steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up Python uses: actions/setup-python@v6 @@ -234,7 +234,7 @@ jobs: count: ${{ steps.count.outputs.findings }} steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up Python uses: actions/setup-python@v6 diff --git a/.github/workflows/scanners.yml b/.github/workflows/scanners.yml index f7c73b00c8..caa745e1bb 100644 --- a/.github/workflows/scanners.yml +++ b/.github/workflows/scanners.yml @@ -8,7 +8,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 with: fetch-depth: 0 - name: TruffleHog OSS diff --git a/.github/workflows/sort-contributors-go.yml b/.github/workflows/sort-contributors-go.yml index f09cd97e15..18c7f42c4d 100644 --- a/.github/workflows/sort-contributors-go.yml +++ b/.github/workflows/sort-contributors-go.yml @@ -27,7 +27,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Setup Go uses: actions/setup-go@v7 diff --git a/.github/workflows/terraform.yml b/.github/workflows/terraform.yml index 9d3c4a560b..03b42e0b61 100644 --- a/.github/workflows/terraform.yml +++ b/.github/workflows/terraform.yml @@ -23,7 +23,7 @@ jobs: name: terraform-fmt runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - uses: hashicorp/setup-terraform@v3 with: terraform_version: 1.9.8 diff --git a/.github/workflows/version-sync-check.yml b/.github/workflows/version-sync-check.yml index 0a5ddc8946..ea0fce3d97 100644 --- a/.github/workflows/version-sync-check.yml +++ b/.github/workflows/version-sync-check.yml @@ -14,7 +14,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout code - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up JDK 26 uses: actions/setup-java@v5 diff --git a/.github/workflows/visual-diff.yml b/.github/workflows/visual-diff.yml index c043bdeb47..083e9bd530 100644 --- a/.github/workflows/visual-diff.yml +++ b/.github/workflows/visual-diff.yml @@ -15,12 +15,12 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout PR code - uses: actions/checkout@v5 + uses: actions/checkout@v7 with: path: pr-code - name: Checkout main branch - uses: actions/checkout@v5 + uses: actions/checkout@v7 with: ref: master path: main-code From e446dc63fa82f38058574736ed200c17913c7f8f Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 08:59:15 +0200 Subject: [PATCH 12/14] Always scan before push --- .github/workflows/build-devcontainer.yml | 22 +++++++++------------- 1 file changed, 9 insertions(+), 13 deletions(-) diff --git a/.github/workflows/build-devcontainer.yml b/.github/workflows/build-devcontainer.yml index 56f64f4c4a..6a14eca8b6 100644 --- a/.github/workflows/build-devcontainer.yml +++ b/.github/workflows/build-devcontainer.yml @@ -25,12 +25,13 @@ env: jobs: build: - name: Build (${{ matrix.arch }}) + name: Build and scan (${{ matrix.arch }}) runs-on: ${{ matrix.runner }} permissions: contents: read packages: write + security-events: write strategy: fail-fast: false @@ -61,22 +62,22 @@ jobs: - name: Docker metadata id: meta - uses: docker/metadata-action@v5 + uses: docker/metadata-action@v6 with: images: ${{ env.IMAGE_NAME }} tags: | type=raw,value=26-resolute type=sha - - name: Build and push architecture image - uses: docker/build-push-action@v6 + - name: Build image + uses: docker/build-push-action@v7 with: context: . file: .devcontainer/Dockerfile - platforms: ${{ matrix.platform }} push: ${{ github.event_name != 'pull_request' }} + load: ${{ github.event_name == 'pull_request' }} tags: | ${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }} @@ -86,23 +87,18 @@ jobs: cache-from: type=gha,scope=devcontainer-${{ matrix.arch }} cache-to: type=gha,mode=max,scope=devcontainer-${{ matrix.arch }} - - name: Pull image for scanning - if: github.event_name != 'pull_request' - run: | - docker pull "${IMAGE_NAME}:${{ matrix.arch }}-${{ github.sha }}" - - name: Scan image - if: github.event_name != 'pull_request' uses: aquasecurity/trivy-action@v0.36.0 with: image-ref: "${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }}" format: sarif output: "trivy-${{ matrix.arch }}.sarif" severity: CRITICAL,HIGH + exit-code: 1 - name: Upload scan results - if: always() && github.event_name != 'pull_request' - uses: github/codeql-action/upload-sarif@v4 + if: always() + uses: github/codeql-action/upload-sarif@v3 with: sarif_file: "trivy-${{ matrix.arch }}.sarif" From 9cc3ccdbef47e39385248398b746a8f3a472e312 Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 09:09:08 +0200 Subject: [PATCH 13/14] Upgrading devcontainer by having a split base and container image --- .devcontainer/devcontainer.json | 2 +- .github/workflows/build-devcontainer.yml | 79 ++++++++++++++++-------- 2 files changed, 54 insertions(+), 27 deletions(-) diff --git a/.devcontainer/devcontainer.json b/.devcontainer/devcontainer.json index 3c22675e58..37efcb1575 100644 --- a/.devcontainer/devcontainer.json +++ b/.devcontainer/devcontainer.json @@ -1,7 +1,7 @@ { "name": "WrongSecrets", - "image": "ghcr.io/owasp/wrongsecrets-devcontainer:26-resolute", + "image": "ghcr.io/owasp/wrongsecrets-devcontainer:26-resolute-base", "workspaceFolder": "/workspaces", diff --git a/.github/workflows/build-devcontainer.yml b/.github/workflows/build-devcontainer.yml index 6a14eca8b6..cddf9d64c3 100644 --- a/.github/workflows/build-devcontainer.yml +++ b/.github/workflows/build-devcontainer.yml @@ -7,12 +7,15 @@ on: paths: - ".devcontainer/Dockerfile" - ".devcontainer/devcontainer.json" + - ".devcontainer/post-create.sh" - ".github/workflows/build-devcontainer.yml" pull_request: paths: + - ".devcontainer/Dockerfile" - ".devcontainer/devcontainer.json" + - ".devcontainer/post-create.sh" - ".github/workflows/build-devcontainer.yml" workflow_dispatch: @@ -24,7 +27,7 @@ env: IMAGE_NAME: ghcr.io/owasp/wrongsecrets-devcontainer jobs: - build: + build-and-scan: name: Build and scan (${{ matrix.arch }}) runs-on: ${{ matrix.runner }} @@ -60,39 +63,45 @@ jobs: username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - name: Docker metadata - id: meta - uses: docker/metadata-action@v6 - with: - images: ${{ env.IMAGE_NAME }} - tags: | - type=raw,value=26-resolute - type=sha - - - name: Build image + # Build the base image from the Dockerfile. + - name: Build base image uses: docker/build-push-action@v7 with: context: . file: .devcontainer/Dockerfile platforms: ${{ matrix.platform }} - - push: ${{ github.event_name != 'pull_request' }} - load: ${{ github.event_name == 'pull_request' }} - + load: true tags: | - ${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }} + ${{ env.IMAGE_NAME }}:26-resolute-base-${{ matrix.arch }}-${{ github.sha }} + cache-from: type=gha,scope=devcontainer-base-${{ matrix.arch }} + cache-to: type=gha,mode=max,scope=devcontainer-base-${{ matrix.arch }} - labels: ${{ steps.meta.outputs.labels }} - - cache-from: type=gha,scope=devcontainer-${{ matrix.arch }} - cache-to: type=gha,mode=max,scope=devcontainer-${{ matrix.arch }} + # Make the base image available under the name used by + # devcontainer.json. + - name: Tag base image + run: | + docker tag \ + "${IMAGE_NAME}:26-resolute-base-${{ matrix.arch }}-${{ github.sha }}" \ + "${IMAGE_NAME}:26-resolute-base" + + # Build the ACTUAL Dev Container. + # + # This reads .devcontainer/devcontainer.json, + # installs the configured features and produces the + # final Dev Container image. + - name: Build Dev Container + uses: devcontainers/ci@v0.3 + with: + imageName: ${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }} + push: false - - name: Scan image + # Scan the FINAL Dev Container, not the Dockerfile base image. + - name: Scan Dev Container uses: aquasecurity/trivy-action@v0.36.0 with: - image-ref: "${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }}" + image-ref: ${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }} format: sarif - output: "trivy-${{ matrix.arch }}.sarif" + output: trivy-${{ matrix.arch }}.sarif severity: CRITICAL,HIGH exit-code: 1 @@ -100,11 +109,29 @@ jobs: if: always() uses: github/codeql-action/upload-sarif@v3 with: - sarif_file: "trivy-${{ matrix.arch }}.sarif" + sarif_file: trivy-${{ matrix.arch }}.sarif + + # Only publish after the final image has passed Trivy. + - name: Push final Dev Container + if: github.event_name != 'pull_request' + run: | + docker push \ + "${IMAGE_NAME}:${{ matrix.arch }}-${{ github.sha }}" + + # Publish the base image separately. + - name: Push base image + if: github.event_name != 'pull_request' + run: | + docker tag \ + "${IMAGE_NAME}:26-resolute-base-${{ matrix.arch }}-${{ github.sha }}" \ + "${IMAGE_NAME}:26-resolute-base-${{ matrix.arch }}" + + docker push \ + "${IMAGE_NAME}:26-resolute-base-${{ matrix.arch }}" manifest: name: Create multi-arch manifest - needs: build + needs: build-and-scan if: github.event_name != 'pull_request' runs-on: ubuntu-latest @@ -123,7 +150,7 @@ jobs: username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - name: Create and push multi-arch manifest + - name: Create final Dev Container manifest run: | docker buildx imagetools create \ --tag "${IMAGE_NAME}:26-resolute" \ From 86003f321f57ad0eb68e5613c24fcbf74e8a682e Mon Sep 17 00:00:00 2001 From: Jeroen Willemsen Date: Mon, 14 Sep 2026 09:14:11 +0200 Subject: [PATCH 14/14] Upgrading devcontainer by having a split base and container image --- .github/workflows/build-devcontainer.yml | 42 +++++++++++++++--------- 1 file changed, 26 insertions(+), 16 deletions(-) diff --git a/.github/workflows/build-devcontainer.yml b/.github/workflows/build-devcontainer.yml index cddf9d64c3..c19428299c 100644 --- a/.github/workflows/build-devcontainer.yml +++ b/.github/workflows/build-devcontainer.yml @@ -12,7 +12,6 @@ on: pull_request: paths: - - ".devcontainer/Dockerfile" - ".devcontainer/devcontainer.json" - ".devcontainer/post-create.sh" @@ -76,42 +75,53 @@ jobs: cache-from: type=gha,scope=devcontainer-base-${{ matrix.arch }} cache-to: type=gha,mode=max,scope=devcontainer-base-${{ matrix.arch }} - # Make the base image available under the name used by - # devcontainer.json. + # The devcontainer.json refers to 26-resolute-base. + # Make the architecture-specific base image available + # locally under that exact name. - name: Tag base image run: | docker tag \ "${IMAGE_NAME}:26-resolute-base-${{ matrix.arch }}-${{ github.sha }}" \ "${IMAGE_NAME}:26-resolute-base" - # Build the ACTUAL Dev Container. + # Build the actual Dev Container. # - # This reads .devcontainer/devcontainer.json, - # installs the configured features and produces the - # final Dev Container image. + # devcontainers/ci automatically adds :latest to imageName, + # so DO NOT put a tag in imageName here. - name: Build Dev Container uses: devcontainers/ci@v0.3 with: - imageName: ${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }} - push: false + imageName: devcontainer-${{ matrix.arch }}-${{ github.sha }} + push: never + + # devcontainers/ci produced: + # + # devcontainer-${arch}-${sha}:latest + # + # Retag it with the image name we actually want to publish/scan. + - name: Tag final Dev Container + run: | + docker tag \ + "devcontainer-${{ matrix.arch }}-${{ github.sha }}:latest" \ + "${IMAGE_NAME}:${{ matrix.arch }}-${{ github.sha }}" - # Scan the FINAL Dev Container, not the Dockerfile base image. + # Scan the FINAL Dev Container, including all features. - name: Scan Dev Container uses: aquasecurity/trivy-action@v0.36.0 with: - image-ref: ${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }} + image-ref: "${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }}" format: sarif - output: trivy-${{ matrix.arch }}.sarif + output: "trivy-${{ matrix.arch }}.sarif" severity: CRITICAL,HIGH exit-code: 1 - name: Upload scan results - if: always() - uses: github/codeql-action/upload-sarif@v3 + if: always() && hashFiles(format('trivy-{0}.sarif', matrix.arch)) != '' + uses: github/codeql-action/upload-sarif@v4 with: - sarif_file: trivy-${{ matrix.arch }}.sarif + sarif_file: "trivy-${{ matrix.arch }}.sarif" - # Only publish after the final image has passed Trivy. + # Only publish the final Dev Container after it passed Trivy. - name: Push final Dev Container if: github.event_name != 'pull_request' run: |