Skip to content

ci: scan the most recently pushed image with Trivy - #118

Open
rsubrama83 wants to merge 1 commit into
mainfrom
ci/trivy-scan-latest-image
Open

rsubrama83 wants to merge 1 commit into
mainfrom
ci/trivy-scan-latest-image

Conversation

@rsubrama83

Copy link
Copy Markdown
Collaborator

Fixes #80.

Problems

  • Stale image: the scan targeted ghcr.io/lm-development/aks-sample/aks-sample:latest, but no workflow pushes :latest anymore. routine-buildimage.yml tags images with a content hash. Recent green runs were scanning an old image, not what's deployed.
  • 2024 failures: the intermittent failures in Trivy scan is currently broken #80 (Sep/Oct 2024) match the GHCR rate-limiting of trivy-db downloads that hit many repos at the time. That's likely, but unconfirmed because the old logs are gone.
  • Setup: Trivy was installed via the deprecated apt-key, there was no verbose option (requested in Trivy scan is currently broken #80), and the "check result" step never failed anything.

Changes

  • Resolve the newest tag of vars.CR_NAMESPACE_REPOSITORY through the GHCR packages API (packages: read). An image-tag dispatch input can override it.
  • Use aquasecurity/trivy-action@v0.36.0, with TRIVY_DB_REPOSITORY mirrors (mirror.gcr.io, public.ecr.aws, ghcr.io) as a fallback for rate limits.
  • debug dispatch input (TRIVY_DEBUG) for verbose logs.
  • SARIF upload with codeql-action/upload-sarif@v4, plus a HIGH/CRITICAL table in the job log.
  • Explicit minimal permissions.

Verified

Dispatched on this branch: https://github.com/LM-Development/OmniBot/actions/runs/37466044512. It succeeded and scanned aks-sample:775002f1.

HIGH findings (no CRITICAL):

Package CVE Installed Fixed
Microsoft.Bcl.Memory CVE-2026-26127 9.0.0 9.0.14, 10.0.4
Microsoft.Kiota.Abstractions CVE-2026-44503 1.17.1 1.22.0

These are not addressed in this PR.

Note

Scan - Trivy, Continuous Integration and Scan - CodeQL had been auto-disabled by GitHub for inactivity (no commits since 2026-05-08). They have been re-enabled.

🤖 Generated with Claude Code

The scan targeted the :latest tag, which no workflow pushes anymore
(images are tagged with a content hash), so it scanned a stale image.

- Resolve the newest tag of vars.CR_NAMESPACE_REPOSITORY via the GHCR
  packages API, or use the image-tag dispatch input
- Use aquasecurity/trivy-action with DB mirrors to avoid ghcr.io rate
  limits on the vulnerability database
- Add a debug dispatch input and a HIGH/CRITICAL table summary in the log
- Upload SARIF with codeql-action v4

Fixes #80

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Trivy scan is currently broken

1 participant