From 15abd589a8ab529c6d94af1b7dcb28f6e90e91a1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cau=C3=AA=20Faleiros?= Date: Tue, 29 Sep 2026 11:10:58 -0300 Subject: [PATCH] ci: download the vulnerability database once, and tell a failed scan from a finding The CRITICAL scan of dtf-api failed on a 404 from the database mirror and was reported as a CRITICAL vulnerability. The image step now downloads the database once into a cache volume, with three attempts, scans all four times from it, and exits 5 only on findings: a scan that does not run fails with its own message, and nothing is published unscanned. Co-Authored-By: Claude Opus 5.5 --- .gitea/workflows/deploy.yml | 37 ++++++++++++++++++++++++++++++------- 1 file changed, 30 insertions(+), 7 deletions(-) diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index c55b520..043ec34 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -206,24 +206,47 @@ jobs: - name: Image vulnerabilities run: | image="${TRIVY_IMAGE:-aquasec/trivy:0.58.1}" - failed=0 + # One database download for the four scans, kept in a volume between + # runs and retried: a failed download from the mirror used to fail + # the gate as if a CRITICAL vulnerability had been found. + trivy() { docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \ + -v dtf-trivy-cache:/root/.cache/trivy "$image" "$@"; } + for attempt in 1 2 3; do + trivy image --download-db-only --no-progress && break + if [ "$attempt" -eq 3 ]; then + echo "::error::The vulnerability database could not be downloaded; the release images were not scanned." + exit 1 + fi + echo "Database download failed (attempt $attempt); retrying in 30 s." + sleep 30 + done + # Findings exit 5; any other failure means the scan did not run. + found=0; broken=0 for target in \ "gitea.blyzer.com.br/blyzer/dtf-api:${{ gitea.sha }}" \ "gitea.blyzer.com.br/blyzer/dtf-web:${{ gitea.sha }}"; do echo "--- $target (HIGH, reported)" - docker run --rm -v /var/run/docker.sock:/var/run/docker.sock "$image" \ - image --image-src docker --scanners vuln --severity HIGH --no-progress \ + trivy image --skip-db-update --image-src docker --scanners vuln --severity HIGH --no-progress \ --format table --exit-code 0 "$target" || echo "::warning::Could not scan $target for HIGH findings" echo "--- $target (CRITICAL, blocking)" - docker run --rm -v /var/run/docker.sock:/var/run/docker.sock "$image" \ - image --image-src docker --scanners vuln --severity CRITICAL --no-progress \ - --format table --exit-code 1 "$target" || failed=1 + set +e + trivy image --skip-db-update --image-src docker --scanners vuln --severity CRITICAL --no-progress \ + --format table --exit-code 5 "$target" + verdict=$? + set -e + if [ "$verdict" -eq 5 ]; then found=1 + elif [ "$verdict" -ne 0 ]; then broken=1; echo "::error::The CRITICAL scan of $target did not run (exit $verdict)." + fi done - if [ "$failed" -ne 0 ]; then + if [ "$found" -ne 0 ]; then echo "::error::A CRITICAL vulnerability was found in a release image." exit 1 fi + if [ "$broken" -ne 0 ]; then + echo "::error::A release image could not be scanned; nothing is published unscanned." + exit 1 + fi - name: Publish validated images run: |