Sign inSign up

vitalifyasia/vfa-shield

By vitalifyasia

•Updated 4 days ago

VFA Governance Core - CLI for local check.

Image
Security
Developer tools
0

986

vitalifyasia/vfa-shield repository overview

Run vfa-shield Local:

docker run --rm -e TRIVY_INSECURE=true -v "$PWD":/work vitalifyasia/vfa-shield:latest check

CI configuration:

name: VFA Gate (Docker)

on:
  pull_request:
    branches: [develop, master]
  push:
    branches: ['feature/**']
  workflow_dispatch:

# A new push supersedes the previous run on the same ref.
concurrency:
  group: vfa-gate-${{ github.ref }}
  cancel-in-progress: true

permissions:
  contents: read

env:
  # Pin a released tag (e.g. :1.2.0) instead of :latest so gate results are
  # reproducible and a new image cannot break merges without a commit.
  VFA_SHIELD_IMAGE: vitalifyasia/vfa-shield:latest

jobs:
  vfa-gate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v7

      # ubuntu-latest already ships Docker Engine + the compose v2 plugin,
      # so there is nothing to install here.
      - name: Docker version
        run: docker --version

      - name: Pull vfa-shield
        run: docker pull "$VFA_SHIELD_IMAGE"

      # The project root is mounted at /work (the image's WORKDIR). The CLI reads
      # vfa-adapter.yml + vfa-policy.yml from there and writes both scan reports
      # back into the workspace. Exit code 1 = a gate failed = this step fails.
      - name: Run VFA gate
        run: |
          docker run --rm \
            -v "$PWD":/work \
            "$VFA_SHIELD_IMAGE" check

          # Useful variants:
          #   ... check --no-scan                    # coverage gate only
          #   ... check --only coverage,secrets       # subset of gates
          #   -e DEMO_COVERAGE=65 ... check           # inject a coverage value
          #   --env-file .env ... check               # pass project env to adapter cmds
          #   --network host ... check                # reach services on the runner host
          #   --user "$(id -u):$(id -g)" -e HOME=/tmp # avoid root-owned files (self-hosted)

      - name: Upload reports
        if: ${{ !cancelled() }}
        uses: actions/upload-artifact@v4
        with:
          name: vfa-security-reports
          path: |
            trivy-report.json
            gitleaks-report.json
          if-no-files-found: warn
          retention-days: 30

Tag summary

Content type

Image

Digest

sha256:3d906f612…

Size

172.8 MB

Last updated

4 days ago

docker pull vitalifyasia/vfa-shield