ci: download the vulnerability database once, and tell a failed scan from a finding
All checks were successful
Build and deploy / Validate source (push) Successful in 5s
Build and deploy / Integration suite on a real stack (push) Successful in 2m22s
Build and deploy / Secret scan and release gate (push) Successful in 6s
Build and deploy / Publish images (push) Successful in 55s
All checks were successful
Build and deploy / Validate source (push) Successful in 5s
Build and deploy / Integration suite on a real stack (push) Successful in 2m22s
Build and deploy / Secret scan and release gate (push) Successful in 6s
Build and deploy / Publish images (push) Successful in 55s
The CRITICAL scan of dtf-api failed on a 404 from the database mirror and was reported as a CRITICAL vulnerability. The image step now downloads the database once into a cache volume, with three attempts, scans all four times from it, and exits 5 only on findings: a scan that does not run fails with its own message, and nothing is published unscanned. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -206,24 +206,47 @@ jobs:
|
|||||||
- name: Image vulnerabilities
|
- name: Image vulnerabilities
|
||||||
run: |
|
run: |
|
||||||
image="${TRIVY_IMAGE:-aquasec/trivy:0.58.1}"
|
image="${TRIVY_IMAGE:-aquasec/trivy:0.58.1}"
|
||||||
failed=0
|
# One database download for the four scans, kept in a volume between
|
||||||
|
# runs and retried: a failed download from the mirror used to fail
|
||||||
|
# the gate as if a CRITICAL vulnerability had been found.
|
||||||
|
trivy() { docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
|
||||||
|
-v dtf-trivy-cache:/root/.cache/trivy "$image" "$@"; }
|
||||||
|
for attempt in 1 2 3; do
|
||||||
|
trivy image --download-db-only --no-progress && break
|
||||||
|
if [ "$attempt" -eq 3 ]; then
|
||||||
|
echo "::error::The vulnerability database could not be downloaded; the release images were not scanned."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "Database download failed (attempt $attempt); retrying in 30 s."
|
||||||
|
sleep 30
|
||||||
|
done
|
||||||
|
# Findings exit 5; any other failure means the scan did not run.
|
||||||
|
found=0; broken=0
|
||||||
for target in \
|
for target in \
|
||||||
"gitea.blyzer.com.br/blyzer/dtf-api:${{ gitea.sha }}" \
|
"gitea.blyzer.com.br/blyzer/dtf-api:${{ gitea.sha }}" \
|
||||||
"gitea.blyzer.com.br/blyzer/dtf-web:${{ gitea.sha }}"; do
|
"gitea.blyzer.com.br/blyzer/dtf-web:${{ gitea.sha }}"; do
|
||||||
echo "--- $target (HIGH, reported)"
|
echo "--- $target (HIGH, reported)"
|
||||||
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock "$image" \
|
trivy image --skip-db-update --image-src docker --scanners vuln --severity HIGH --no-progress \
|
||||||
image --image-src docker --scanners vuln --severity HIGH --no-progress \
|
|
||||||
--format table --exit-code 0 "$target" ||
|
--format table --exit-code 0 "$target" ||
|
||||||
echo "::warning::Could not scan $target for HIGH findings"
|
echo "::warning::Could not scan $target for HIGH findings"
|
||||||
echo "--- $target (CRITICAL, blocking)"
|
echo "--- $target (CRITICAL, blocking)"
|
||||||
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock "$image" \
|
set +e
|
||||||
image --image-src docker --scanners vuln --severity CRITICAL --no-progress \
|
trivy image --skip-db-update --image-src docker --scanners vuln --severity CRITICAL --no-progress \
|
||||||
--format table --exit-code 1 "$target" || failed=1
|
--format table --exit-code 5 "$target"
|
||||||
|
verdict=$?
|
||||||
|
set -e
|
||||||
|
if [ "$verdict" -eq 5 ]; then found=1
|
||||||
|
elif [ "$verdict" -ne 0 ]; then broken=1; echo "::error::The CRITICAL scan of $target did not run (exit $verdict)."
|
||||||
|
fi
|
||||||
done
|
done
|
||||||
if [ "$failed" -ne 0 ]; then
|
if [ "$found" -ne 0 ]; then
|
||||||
echo "::error::A CRITICAL vulnerability was found in a release image."
|
echo "::error::A CRITICAL vulnerability was found in a release image."
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
if [ "$broken" -ne 0 ]; then
|
||||||
|
echo "::error::A release image could not be scanned; nothing is published unscanned."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Publish validated images
|
- name: Publish validated images
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
Reference in New Issue
Block a user