PORTAINER.md and SECURITY_REPORT.md described a pipeline that required regressions, HIGH/CRITICAL secret, misconfiguration and image gates, and stated that the source preflight stopped this application from publishing. None of it ran: the workflow built and called the webhook unconditionally. Add a blocking Trivy secret scan. Verified both ways: a planted AWS key pair, GitHub token and private key block the job, and the repository passes clean. Note that Trivy allowlists documented example credentials, so this gate is a backstop, not permission to commit secrets. The source preflight now runs on every push and always prints its verdict, but enforces only when ENFORCE_PRODUCTION_PREFLIGHT is true. Enforcing it today would block every deployment, because it refuses a release while the payment and messaging adapters are fake, which is the deliberate state the stack runs in. Set the variable when real adapters land. Image vulnerabilities are reported after each build rather than enforced. The current bases carry 56 HIGH and 3 CRITICAL findings, only 15 of them with an upstream fix, so failing on them would stop releases without making anything safer. Pinning digests and triaging the fixable ones is ROADMAP 2.6. Both documents now carry a table of what gates and what does not, instead of describing checks that did not exist. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
7.8 KiB
7.8 KiB