From 3f828fc2cd99aabacf83e564e6a1ded99ce5806c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9bastien=20Rivi=C3=A8re?= <59322235+s-riviere@users.noreply.github.com> Date: Thu, 1 Oct 2026 22:37:27 +0200 Subject: [PATCH] Add Assignement Proposal ignacys-sebriv Added README.md for the automated supply chain security demo, detailing the project proposal, team members, deadline, category, and description of the demo's relevance to DevSecOps. --- .../demo/week6/ignacys-sebriv/README.md | 26 +++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 contributions/demo/week6/ignacys-sebriv/README.md diff --git a/contributions/demo/week6/ignacys-sebriv/README.md b/contributions/demo/week6/ignacys-sebriv/README.md new file mode 100644 index 0000000000..758a026856 --- /dev/null +++ b/contributions/demo/week6/ignacys-sebriv/README.md @@ -0,0 +1,26 @@ +# Assignment Proposal + +## Title + +Automated Supply Chain Security and Vulnerability Quality Gate with Syft and Grype + +## Names and KTH ID + +- Ignacy Stępniewski (ignacys@kth.se) +- Sébastien Rivière (sebriv@kth.se) + +## Deadline + +- Week 6 + +## Category + +- Demo + +## Description + +Container images often bundle operating system packages and language dependencies containing known security vulnerabilities (CVEs), exposing the software supply chain to critical risks. This demo presents an automated DevSecOps quality gate using **Syft** (for Software Bill of Materials generation) and **Grype** (for vulnerability scanning) integrated into GitHub Actions. We demonstrate how to automatically detect critical CVEs on Pull Requests, fail the build to prevent vulnerable code from merging, and perform a live fix by updating container base images. Finally, we reflect on practical challenges in DevSecOps such as managing false positives and unpatched upstream vulnerabilities. + +**Relevance** + +This demo directly aligns with Week 6 topics (Dependency Management, DevSecOps & Supply Chain Integrity). It illustrates how to shift security left by automatically generating an SBOM and enforcing automated vulnerability quality gates on every Pull Request before code reaches production.