This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+1 more
Affected surfaces
Summary
AI summaryAdded Docker image building, multi‑platform support, and Trivy vulnerability scanning to the CI/CD pipeline.
Full changelog
Minor Changes
- #295
4ea3a14- feat: add Docker build and Trivy security scanning to CI/CD pipeline- Add Docker image building and vulnerability scanning to PR workflow for shift-left security
- Build multi-platform Docker images in main workflow and store as artifacts
- Refactor publish workflow to use pre-built images from main for deterministic deployments
- Create reusable Docker workflow for consistent build and scan process
- Add Trivy container scanning with results uploaded to GitHub Security tab
- Control Docker features via single
ENABLE_DOCKER_RELEASErepository variable - Add .dockerignore to optimize build context
- Support for linux/amd64 and linux/arm64 platforms
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About sapientpants/sonarqube-mcp-server
A Model Context Protocol (MCP) server that integrates with SonarQube to provide AI assistants with access to code quality metrics, issues, and quality gate statuses
Beta — feedback welcome: [email protected]