From a8c0761d5d854fa321c03eff75a9c3c8e2d35dd8 Mon Sep 17 00:00:00 2001 From: Advait Patel Date: Mon, 21 Sep 2026 15:19:43 -0500 Subject: [PATCH] docs: document Docker Hub image and fix SARIF upload path in README README and the website now mention owasp/docksec on Docker Hub alongside the GHCR image, since both are published from the same release build. Also fixes the SARIF upload example in README (closes #192): it pointed upload-sarif at ~/.docksec/results, a path inside the Action container rather than on the runner, so the SARIF file was never found and no findings were ever uploaded. Points output_dir and sarif_file at a workspace-relative path instead, and adds a category so multiple DockSec scans in one workflow don't overwrite each other's upload. --- README.md | 22 +++++++++++++++++----- website/docs/evaluation-guide.md | 3 ++- website/docs/getting-started.md | 10 +++++++++- 3 files changed, 28 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index ead237a..6d30e0e 100644 --- a/README.md +++ b/README.md @@ -155,10 +155,20 @@ docker run --rm -v "$PWD:/github/workspace" \ ghcr.io/owasp/docksec:latest ``` -Published multi-arch (amd64 and arm64) on every release. Pin to a specific -version (`ghcr.io/owasp/docksec:2026.9.21`) or a minor series -(`ghcr.io/owasp/docksec:2026.9`) rather than `latest` in CI. Every image carries -a build provenance attestation: +Also published to Docker Hub as `owasp/docksec`: + +```bash +docker run --rm -v "$PWD:/github/workspace" \ + -e INPUT_DOCKERFILE=Dockerfile \ + -e INPUT_SCAN_ONLY=true \ + owasp/docksec:latest +``` + +Published multi-arch (amd64 and arm64) on every release, to both registries +from the same build. Pin to a specific version (`ghcr.io/owasp/docksec:2026.9.21`, +`owasp/docksec:2026.9.21`) or a minor series (`ghcr.io/owasp/docksec:2026.9`) +rather than `latest` in CI. Every GHCR image carries a build provenance +attestation: ```bash gh attestation verify oci://ghcr.io/owasp/docksec:latest --repo OWASP/DockSec @@ -488,12 +498,14 @@ directly on pull requests and in the Security tab: with: dockerfile: 'Dockerfile' sarif: 'true' + output_dir: ${{ github.workspace }}/docksec-results - name: Upload SARIF to GitHub Code Scanning uses: github/codeql-action/upload-sarif@v3 if: always() with: - sarif_file: ~/.docksec/results + sarif_file: docksec-results + category: docksec ``` > `if: always()` is important: without it, the upload step is skipped whenever diff --git a/website/docs/evaluation-guide.md b/website/docs/evaluation-guide.md index 72c7df2..9a90092 100644 --- a/website/docs/evaluation-guide.md +++ b/website/docs/evaluation-guide.md @@ -17,7 +17,8 @@ docker run --rm -v "$PWD:/github/workspace" \ ghcr.io/owasp/docksec:latest ``` -The image bundles pinned Trivy and Hadolint. If you prefer a local install: +Also available on Docker Hub as `owasp/docksec:latest`. The image bundles +pinned Trivy and Hadolint. If you prefer a local install: ```bash pip install docksec diff --git a/website/docs/getting-started.md b/website/docs/getting-started.md index 81c5628..cabc90a 100644 --- a/website/docs/getting-started.md +++ b/website/docs/getting-started.md @@ -22,7 +22,8 @@ DockSec shells out to [Trivy](https://github.com/aquasecurity/trivy) and python -m docksec.setup_external_tools ``` -Prefer no install at all? The container bundles pinned versions of both: +Prefer no install at all? The container bundles pinned versions of both, and is +published to both GHCR and Docker Hub: ```bash docker run --rm -v "$PWD:/github/workspace" \ @@ -31,6 +32,13 @@ docker run --rm -v "$PWD:/github/workspace" \ ghcr.io/owasp/docksec:2026.9.21 ``` +```bash +docker run --rm -v "$PWD:/github/workspace" \ + -e INPUT_DOCKERFILE=Dockerfile \ + -e INPUT_SCAN_ONLY=true \ + owasp/docksec:2026.9.21 +``` + ## First scan ```bash