Skip to content

[Tech Debt] Audit containers for HIGH/CRITICAL vulnerabilities #29

@smagala

Description

@smagala

Description

Audit all OAMD containers used by the denver pipeline to ensure they have no HIGH or CRITICAL vulnerabilities.

Scope

Containers to audit:

  • oamd-bio-fastqc
  • oamd-bio-multiqc
  • oamd-bio-bwa
  • oamd-bio-samtools
  • oamd-bio-ivar
  • oamd-bio-bedtools
  • oamd-bio-nextclade
  • oamd-bio-mafft

Approach

Use docker-btp ecosystem tooling for vulnerability scanning. Details to be provided when task is prioritized.

Acceptance Criteria

  • All containers scanned for vulnerabilities
  • No HIGH or CRITICAL vulnerabilities present
  • Scanning integrated into container build CI/CD
  • Documentation updated with security scanning process

Related

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions