diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index c55b520..043ec34 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -206,24 +206,47 @@ jobs: - name: Image vulnerabilities run: | image="${TRIVY_IMAGE:-aquasec/trivy:0.58.1}" - failed=0 + # One database download for the four scans, kept in a volume between + # runs and retried: a failed download from the mirror used to fail + # the gate as if a CRITICAL vulnerability had been found. + trivy() { docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \ + -v dtf-trivy-cache:/root/.cache/trivy "$image" "$@"; } + for attempt in 1 2 3; do + trivy image --download-db-only --no-progress && break + if [ "$attempt" -eq 3 ]; then + echo "::error::The vulnerability database could not be downloaded; the release images were not scanned." + exit 1 + fi + echo "Database download failed (attempt $attempt); retrying in 30 s." + sleep 30 + done + # Findings exit 5; any other failure means the scan did not run. + found=0; broken=0 for target in \ "gitea.blyzer.com.br/blyzer/dtf-api:${{ gitea.sha }}" \ "gitea.blyzer.com.br/blyzer/dtf-web:${{ gitea.sha }}"; do echo "--- $target (HIGH, reported)" - docker run --rm -v /var/run/docker.sock:/var/run/docker.sock "$image" \ - image --image-src docker --scanners vuln --severity HIGH --no-progress \ + trivy image --skip-db-update --image-src docker --scanners vuln --severity HIGH --no-progress \ --format table --exit-code 0 "$target" || echo "::warning::Could not scan $target for HIGH findings" echo "--- $target (CRITICAL, blocking)" - docker run --rm -v /var/run/docker.sock:/var/run/docker.sock "$image" \ - image --image-src docker --scanners vuln --severity CRITICAL --no-progress \ - --format table --exit-code 1 "$target" || failed=1 + set +e + trivy image --skip-db-update --image-src docker --scanners vuln --severity CRITICAL --no-progress \ + --format table --exit-code 5 "$target" + verdict=$? + set -e + if [ "$verdict" -eq 5 ]; then found=1 + elif [ "$verdict" -ne 0 ]; then broken=1; echo "::error::The CRITICAL scan of $target did not run (exit $verdict)." + fi done - if [ "$failed" -ne 0 ]; then + if [ "$found" -ne 0 ]; then echo "::error::A CRITICAL vulnerability was found in a release image." exit 1 fi + if [ "$broken" -ne 0 ]; then + echo "::error::A release image could not be scanned; nothing is published unscanned." + exit 1 + fi - name: Publish validated images run: |