ci: download the vulnerability database once, and tell a failed scan from a finding
All checks were successful
Build and deploy / Validate source (push) Successful in 5s
Build and deploy / Integration suite on a real stack (push) Successful in 2m22s
Build and deploy / Secret scan and release gate (push) Successful in 6s
Build and deploy / Publish images (push) Successful in 55s

The CRITICAL scan of dtf-api failed on a 404 from the database mirror and
was reported as a CRITICAL vulnerability. The image step now downloads the
database once into a cache volume, with three attempts, scans all four
times from it, and exits 5 only on findings: a scan that does not run fails
with its own message, and nothing is published unscanned.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-29 11:10:58 -03:00
parent 32c060e1b0
commit 15abd589a8

View File

@@ -206,24 +206,47 @@ jobs:
- name: Image vulnerabilities - name: Image vulnerabilities
run: | run: |
image="${TRIVY_IMAGE:-aquasec/trivy:0.58.1}" image="${TRIVY_IMAGE:-aquasec/trivy:0.58.1}"
failed=0 # One database download for the four scans, kept in a volume between
# runs and retried: a failed download from the mirror used to fail
# the gate as if a CRITICAL vulnerability had been found.
trivy() { docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
-v dtf-trivy-cache:/root/.cache/trivy "$image" "$@"; }
for attempt in 1 2 3; do
trivy image --download-db-only --no-progress && break
if [ "$attempt" -eq 3 ]; then
echo "::error::The vulnerability database could not be downloaded; the release images were not scanned."
exit 1
fi
echo "Database download failed (attempt $attempt); retrying in 30 s."
sleep 30
done
# Findings exit 5; any other failure means the scan did not run.
found=0; broken=0
for target in \ for target in \
"gitea.blyzer.com.br/blyzer/dtf-api:${{ gitea.sha }}" \ "gitea.blyzer.com.br/blyzer/dtf-api:${{ gitea.sha }}" \
"gitea.blyzer.com.br/blyzer/dtf-web:${{ gitea.sha }}"; do "gitea.blyzer.com.br/blyzer/dtf-web:${{ gitea.sha }}"; do
echo "--- $target (HIGH, reported)" echo "--- $target (HIGH, reported)"
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock "$image" \ trivy image --skip-db-update --image-src docker --scanners vuln --severity HIGH --no-progress \
image --image-src docker --scanners vuln --severity HIGH --no-progress \
--format table --exit-code 0 "$target" || --format table --exit-code 0 "$target" ||
echo "::warning::Could not scan $target for HIGH findings" echo "::warning::Could not scan $target for HIGH findings"
echo "--- $target (CRITICAL, blocking)" echo "--- $target (CRITICAL, blocking)"
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock "$image" \ set +e
image --image-src docker --scanners vuln --severity CRITICAL --no-progress \ trivy image --skip-db-update --image-src docker --scanners vuln --severity CRITICAL --no-progress \
--format table --exit-code 1 "$target" || failed=1 --format table --exit-code 5 "$target"
verdict=$?
set -e
if [ "$verdict" -eq 5 ]; then found=1
elif [ "$verdict" -ne 0 ]; then broken=1; echo "::error::The CRITICAL scan of $target did not run (exit $verdict)."
fi
done done
if [ "$failed" -ne 0 ]; then if [ "$found" -ne 0 ]; then
echo "::error::A CRITICAL vulnerability was found in a release image." echo "::error::A CRITICAL vulnerability was found in a release image."
exit 1 exit 1
fi fi
if [ "$broken" -ne 0 ]; then
echo "::error::A release image could not be scanned; nothing is published unscanned."
exit 1
fi
- name: Publish validated images - name: Publish validated images
run: | run: |