OpenShift Dev Spaces
Cloud IDE with the Trusted Profile Analyzer client — VS Code extension redhat.fabric8-analytics
(RHDA) — plus a 3-command journey.
TL;DR: This sandbox demo shows how
Red Hat Lightwell Network
remediates vulnerable Java deps via Nexus on OpenShift — for architects and DevSecOps.
Expect ~15–20 minutes: open Dev Spaces, run three tasks, then compare image-scan
CVEs vs Lightwell
.rhlw coordinates
(RHDA
will not go "all green").
The subtle point: Artifact Hub may flag stock commons-io in the WildFly
image scan,
while the app itself builds with Lightwell .rhlw via Nexus — two different planes, both honest.
Primary action — run the demo in the cloud IDE:
Lightwell remediates vulnerable Java deps;
RHDA/TPA
surfaces CVEs in the IDE;
Tekton builds through Nexus→Lightwell on OpenShift. Images land on
Quay (latest / contingency);
GHCR is the public fallback.
Official Red Hat technology icons (console.redhat.com) used for product recognition.
Cloud IDE with the Trusted Profile Analyzer client — VS Code extension redhat.fabric8-analytics
(RHDA) — plus a 3-command journey.
Tekton pipeline builds the WAR via Nexus→Lightwell and deploys the JBoss/WildFly app.
Product page →Primary release registry: GHA pushes latest / contingency to Quay (GHCR is the public fallback).
DevSpaces / Tekton → Nexus → Lightwell registry; GHA → Quay (GHCR fallback) → JBoss console.