docs: record base image pinning and the CRITICAL image gate
Some checks failed
Build and deploy / Validate source (push) Successful in 6s
Build and deploy / Integration suite on a real stack (push) Failing after 6s
Build and deploy / Secret scan and release gate (push) Successful in 11s
Build and deploy / Publish images and notify Portainer (push) Has been skipped
Some checks failed
Build and deploy / Validate source (push) Successful in 6s
Build and deploy / Integration suite on a real stack (push) Failing after 6s
Build and deploy / Secret scan and release gate (push) Successful in 11s
Build and deploy / Publish images and notify Portainer (push) Has been skipped
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
25
ROADMAP.md
25
ROADMAP.md
@@ -7,9 +7,9 @@
|
||||
> Update the **Current step** line and the item status every time something moves.
|
||||
> Add new findings at the bottom of the relevant block rather than rewriting history.
|
||||
|
||||
**Current step:** Block 0 closed, plus 2.1–2.5 and 5.1. Next: 2.6 (pin base image
|
||||
digests and triage the fixable image findings, which is what would let the image
|
||||
scan gate), then 2.7–2.11. Block 1 still waits on client inputs for 1.1/1.2.
|
||||
**Current step:** Block 0 closed, plus 2.1–2.6 and 5.1. Next: 2.7 (vendor or
|
||||
integrity-pin pdf.js), then 2.8–2.11. Block 1 still waits on client inputs for
|
||||
1.1/1.2.
|
||||
|
||||
**Last audit:** 2026-09-18, full read of `local/`, `dtf-site.html`, `deploy/`,
|
||||
`.gitea/`, docs and legacy prototypes. Findings below carry their audit IDs.
|
||||
@@ -222,7 +222,7 @@ refactor: `'This runtime only supports APP_ENV=local'`,
|
||||
- Replace marker matching with behavioural assertions (import the module, assert
|
||||
the adapter classes in use).
|
||||
|
||||
### `[ ]` 2.6 — Base images are not pinned `(F10)`
|
||||
### `[x]` 2.6 — Base images are not pinned `(F10)`
|
||||
|
||||
Dockerfiles default to mutable `python:3.12-slim` / `nginx:1.28-alpine`, the
|
||||
workflow passes no digest build-args, and `--pull` makes builds non-reproducible —
|
||||
@@ -441,6 +441,23 @@ charges. Fix as part of 1.1.
|
||||
`SECURITY_REPORT.md` now carry a table of what gates and what does not, replacing
|
||||
descriptions of checks that never ran.
|
||||
|
||||
- `[x]` 2.6 — Both bases pinned by digest, OS packages upgraded in the production
|
||||
images, and the web image moved off the nginx 1.28 line.
|
||||
|
||||
| Image | Before | After |
|
||||
|---|---|---|
|
||||
| API | 56 HIGH, 3 CRITICAL (15 fixable) | 46 HIGH, 0 CRITICAL |
|
||||
| Web | 5 HIGH, all unfixable in place | 0 HIGH, 0 CRITICAL |
|
||||
|
||||
The 1.28 nginx pins `nginx=1.28.3-r1` in `/etc/apk/world`, so `apk upgrade`
|
||||
cannot patch it even though Alpine ships `-r7`; `nginx:alpine` (1.31.6) is clean
|
||||
while `1.29-alpine` scans worse at 37 HIGH. The two remaining "fixable" API
|
||||
findings are `msgpack` and `setuptools`, which I confirmed are absent from the
|
||||
built image rather than trusting the earlier report. Local images now share the
|
||||
pinned bases, so the integration suite exercises what ships; full suite passes on
|
||||
nginx 1.31.6. With both images at zero CRITICAL, the image scan now **gates on
|
||||
CRITICAL** and reports HIGH.
|
||||
|
||||
### Reporting
|
||||
|
||||
- `[x]` Week-1 client report (`Relatorio-Semana-1-DTF.docx`), corrected 2026-09-18 to
|
||||
|
||||
Reference in New Issue
Block a user