docs: record base image pinning and the CRITICAL image gate
Some checks failed
Build and deploy / Validate source (push) Successful in 6s
Build and deploy / Integration suite on a real stack (push) Failing after 6s
Build and deploy / Secret scan and release gate (push) Successful in 11s
Build and deploy / Publish images and notify Portainer (push) Has been skipped

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-21 11:58:46 -03:00
parent 4c9fa2436e
commit 010c2a162f

View File

@@ -7,9 +7,9 @@
> Update the **Current step** line and the item status every time something moves. > Update the **Current step** line and the item status every time something moves.
> Add new findings at the bottom of the relevant block rather than rewriting history. > Add new findings at the bottom of the relevant block rather than rewriting history.
**Current step:** Block 0 closed, plus 2.1–2.5 and 5.1. Next: 2.6 (pin base image **Current step:** Block 0 closed, plus 2.1–2.6 and 5.1. Next: 2.7 (vendor or
digests and triage the fixable image findings, which is what would let the image integrity-pin pdf.js), then 2.8–2.11. Block 1 still waits on client inputs for
scan gate), then 2.7–2.11. Block 1 still waits on client inputs for 1.1/1.2. 1.1/1.2.
**Last audit:** 2026-09-18, full read of `local/`, `dtf-site.html`, `deploy/`, **Last audit:** 2026-09-18, full read of `local/`, `dtf-site.html`, `deploy/`,
`.gitea/`, docs and legacy prototypes. Findings below carry their audit IDs. `.gitea/`, docs and legacy prototypes. Findings below carry their audit IDs.
@@ -222,7 +222,7 @@ refactor: `'This runtime only supports APP_ENV=local'`,
- Replace marker matching with behavioural assertions (import the module, assert - Replace marker matching with behavioural assertions (import the module, assert
the adapter classes in use). the adapter classes in use).
### `[ ]` 2.6 — Base images are not pinned `(F10)` ### `[x]` 2.6 — Base images are not pinned `(F10)`
Dockerfiles default to mutable `python:3.12-slim` / `nginx:1.28-alpine`, the Dockerfiles default to mutable `python:3.12-slim` / `nginx:1.28-alpine`, the
workflow passes no digest build-args, and `--pull` makes builds non-reproducible — workflow passes no digest build-args, and `--pull` makes builds non-reproducible —
@@ -441,6 +441,23 @@ charges. Fix as part of 1.1.
`SECURITY_REPORT.md` now carry a table of what gates and what does not, replacing `SECURITY_REPORT.md` now carry a table of what gates and what does not, replacing
descriptions of checks that never ran. descriptions of checks that never ran.
- `[x]` 2.6 — Both bases pinned by digest, OS packages upgraded in the production
images, and the web image moved off the nginx 1.28 line.
| Image | Before | After |
|---|---|---|
| API | 56 HIGH, 3 CRITICAL (15 fixable) | 46 HIGH, 0 CRITICAL |
| Web | 5 HIGH, all unfixable in place | 0 HIGH, 0 CRITICAL |
The 1.28 nginx pins `nginx=1.28.3-r1` in `/etc/apk/world`, so `apk upgrade`
cannot patch it even though Alpine ships `-r7`; `nginx:alpine` (1.31.6) is clean
while `1.29-alpine` scans worse at 37 HIGH. The two remaining "fixable" API
findings are `msgpack` and `setuptools`, which I confirmed are absent from the
built image rather than trusting the earlier report. Local images now share the
pinned bases, so the integration suite exercises what ships; full suite passes on
nginx 1.31.6. With both images at zero CRITICAL, the image scan now **gates on
CRITICAL** and reports HIGH.
### Reporting ### Reporting
- `[x]` Week-1 client report (`Relatorio-Semana-1-DTF.docx`), corrected 2026-09-18 to - `[x]` Week-1 client report (`Relatorio-Semana-1-DTF.docx`), corrected 2026-09-18 to