Skip to content

Container Security Scan #395

Container Security Scan

Container Security Scan #395

# Copyright AGNTCY Contributors (https://github.com/agntcy)
# SPDX-License-Identifier: Apache-2.0
name: Container Security Scan
on:
workflow_dispatch:
schedule:
- cron: "0 3 * * *" # Daily at 03:00 UTC
permissions:
contents: read
security-events: write # for uploading SARIF
actions: read
issues: write # create issues for critical CVEs
jobs:
image-list:
name: Resolve image list
runs-on: ubuntu-latest
outputs:
matrix: ${{ steps.matrix.outputs.matrix }}
steps:
- name: Checkout code
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- name: Install Task
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Get image list from task
id: matrix
env:
IMAGE_TAG: latest
IMAGE_REPO: ghcr.io/${{ github.repository_owner }}
run: |
matrix=$(task --silent deps:vuln:images:list | jq -R -s -c 'split("\n") | map(select(length > 0)) | {image: .}')
echo "matrix<<EOF" >> $GITHUB_OUTPUT
echo "$matrix" >> $GITHUB_OUTPUT
echo "EOF" >> $GITHUB_OUTPUT
trivy-scan:
name: Trivy Scan
runs-on: ubuntu-latest
needs: [image-list]
strategy:
fail-fast: false
matrix: ${{ fromJson(needs.image-list.outputs.matrix) }}
steps:
- name: Set image name
id: image-name
run: |
# Extract image name from full reference (e.g., ghcr.io/owner/image:tag -> image)
IMAGE_NAME=$(echo "${{ matrix.image }}" | sed -E 's|.*/||; s|[:@].*||')
echo "name=$IMAGE_NAME" >> $GITHUB_OUTPUT
- name: Scan image
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
with:
image-ref: ${{ matrix.image }}
github-pat: ${{ secrets.GITHUB_TOKEN }}
format: sarif
output: trivy-${{ steps.image-name.outputs.name }}.sarif
vuln-type: "os,library"
severity: "CRITICAL,HIGH,MEDIUM"
ignore-unfixed: true
- name: Export image metadata
run: echo "${{ matrix.image }}" > trivy-${{ steps.image-name.outputs.name }}.meta
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
with:
sarif_file: trivy-${{ steps.image-name.outputs.name }}.sarif
category: trivy-${{ steps.image-name.outputs.name }}
- name: Upload report artifacts
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: trivy-report-${{ steps.image-name.outputs.name }}
path: |
trivy-${{ steps.image-name.outputs.name }}.sarif
trivy-${{ steps.image-name.outputs.name }}.meta
retention-days: 7
summarize:
name: Summarize Results
needs: [trivy-scan]
runs-on: ubuntu-latest
if: always()
steps:
- name: Checkout
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- name: Download artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: trivy-report-*
path: trivy-artifacts
- name: Generate summary
run: |
chmod +x .github/workflows/scripts/security/generate_trivy_summary.sh
.github/workflows/scripts/security/generate_trivy_summary.sh
- name: Fail if critical vulns found (optional gate)
if: ${{ github.event_name != 'pull_request' }}
run: |
set -e
found=$(grep -R "CRITICAL" -c trivy-artifacts || true)
if [ "${found}" != "0" ]; then
echo "Critical vulnerabilities detected. (Gate currently informational.)" >&2
fi
- name: Create GitHub issues for critical CVEs
if: ${{ github.event_name != 'pull_request' }}
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REPOSITORY: ${{ github.repository }}
run: |
set -euo pipefail
echo "Installing dependencies for issue creation script";
npm init -y >/dev/null 2>&1 || true
npm install @octokit/rest@21 glob >/dev/null 2>&1
node .github/workflows/scripts/security/create_critical_cve_issues.js