Skip to content

Add Assignement Proposal : Automated Supply Chain Security and Vulnerability Quality Gate with Syft and Grype - #3105

Merged
ericcornelissen merged 1 commit into
KTH:2026from
s-riviere:demo-week6-ignacys-sebriv
Oct 2, 2026
Merged

ericcornelissen merged 1 commit into
KTH:2026from
s-riviere:demo-week6-ignacys-sebriv

Conversation

@s-riviere

@s-riviere s-riviere commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Assignment Proposal

Title

Automated Supply Chain Security and Vulnerability Quality Gate with Syft and Grype

Names and KTH ID

Deadline

  • Week 6

Category

  • Demo

Description

Container images often bundle operating system packages and language dependencies containing known security vulnerabilities (CVEs), exposing the software supply chain to critical risks. This demo presents an automated DevSecOps quality gate using Syft (for Software Bill of Materials generation) and Grype (for vulnerability scanning) integrated into GitHub Actions. We demonstrate how to automatically detect critical CVEs on Pull Requests, fail the build to prevent vulnerable code from merging, and perform a live fix by updating container base images. Finally, we reflect on practical challenges in DevSecOps such as managing false positives and unpatched upstream vulnerabilities.

Relevance

This demo directly aligns with Week 6 topics (Dependency Management, DevSecOps & Supply Chain Integrity). It illustrates how to shift security left by automatically generating an SBOM and enforcing automated vulnerability quality gates on every Pull Request before code reaches production.

Added README.md for the automated supply chain security demo, detailing the project proposal, team members, deadline, category, and description of the demo's relevance to DevSecOps.
@github-actions github-actions Bot added the demo One of the task categories listed in README.md label Oct 1, 2026
@s-riviere s-riviere changed the title Add Assignement Proposal ignacys-sebriv Add Assignement Proposal : Automated Supply Chain Security and Vulnerability Quality Gate with Syft and Grype Oct 1, 2026
@ericcornelissen ericcornelissen self-assigned this Oct 2, 2026

@ericcornelissen ericcornelissen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The proposal looks good, do make sure to consider some "unique" aspects of Syft+Grype as there's already some related demos (#2990, #3090)

@ericcornelissen
ericcornelissen merged commit e7529cc into KTH:2026 Oct 2, 2026
10 of 11 checks passed
@Padmalaya26

Copy link
Copy Markdown

Hello Ignacy Stępniewski and Sébastien Rivière,

My partner and I would like to give a feedback on your demo.
Shunkang Jia (shunkang@kth.se) and Padmalaya Moharana(moharana@kth.se)

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

demo One of the task categories listed in README.md

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants