-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
governanceProject governance and repo configurationProject governance and repo configuration
Description
Pre-1.0 security item (ADR-0021)
Define base image policy and set up vulnerability scanning for container images.
Covers two related items
- Base image policy: distroless/minimal, pinned by digest
- Image scanning: Trivy/Grype in CI before publishing
When to action
When aces-provider-docker exists and builds container images.
What the spec needs to cover
- Approved base images and update cadence
- Scanning tool choice and CI integration
- Exemption process for intentionally vulnerable aces-stdlib images
- No-secrets-in-images enforcement
References
- STANDARDS.md §10.8
- ADR-0021 Layer 4 (Runtime and Container Security)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
governanceProject governance and repo configurationProject governance and repo configuration