Add Prosper security scan jobs to deploy dependencies

Block deploys if any security scan fails:
- app_deps_scan (dependency vulnerabilities)
- cve_scan (CVE scanning)
- cve_sbom_analysis (SBOM CVE analysis)
- app_sbom_analysis (SBOM analysis)
This commit is contained in:
Mondo Diaz
2026-01-15 20:35:14 +00:00
parent 021ebbb3a3
commit b440cb8dcb

View File

@@ -175,7 +175,7 @@ frontend_tests:
# Shared deploy configuration
.deploy_template: &deploy_template
stage: deploy
needs: [build_image, kics, hadolint, python_tests, frontend_tests, secrets]
needs: [build_image, kics, hadolint, python_tests, frontend_tests, secrets, app_deps_scan, cve_scan, cve_sbom_analysis, app_sbom_analysis]
image: deps.global.bsf.tools/registry-1.docker.io/alpine/k8s:1.29.12
.helm_setup: &helm_setup