Skip to content

ci(security): scope release gate to our library deps (report inherited base images) - #36

Merged
aRustyDev merged 1 commit into
mainfrom
woven/scope-gate-library
Jul 28, 2026
Merged

aRustyDev merged 1 commit into
mainfrom
woven/scope-gate-library

Conversation

@aRustyDev

Copy link
Copy Markdown
Owner

Description

Implements the chosen posture from plane-7fn.4.22: gate on our code's deps, report the inherited base images. Triage showed the strict all-package trivy/grype gate was ~95% inherited Alpine OS packages + the inherited proxy Go binary (Caddy/stdlib/grpc/golang.org/x/*) — un-fixable without a base-image refresh — so it would block every release.

  • Trivy = the gate, scoped to library (TRIVY_PKG_TYPES=library): fails only on fixable HIGH/CRITICAL in our pnpm-workspace + apps/api pip deps. Verified locally: frontend library-only = 0 (was 37 OS), proxy library-only = 46 (inherited Go binary).
  • matrix.gate flag makes the proxy (a pure inherited image, no code of ours) report-only.
  • Grype → full report-only over the SBOM (OS + library) so the inherited backlog stays visible in the Security tab. Base-image refresh tracked in 4.23; VEX-accept in 4.18.

Backend's only library vulns (PyJWT, cryptography) are fixed by Dependabot #30/#29 (#29 merged).

Type of Change

  • Improvement (change that would cause existing functionality to not work as expected)

Test Scenarios

References

  • Refs: plane-7fn.4.22

🤖 Generated with Claude Code

…d base images)

Triaging the baseline (plane-7fn.4.22) showed the trivy/grype gate was ~95%
inherited base-image OS packages (Alpine) + the inherited proxy Go binary
(Caddy/stdlib/grpc/golang.org/x/*) — none of which our deps control, so the
strict all-package gate would block every release on upstream base-image churn.

Re-scope per the chosen posture (gate on OUR code, report the rest):
- Trivy is the gate, scoped to LIBRARY packages (TRIVY_PKG_TYPES=library): fails
  only on fixable HIGH/CRITICAL in our pnpm-workspace + apps/api pip deps.
  Verified locally: frontend library-only = 0 (was 37 OS), proxy library-only =
  46 (inherited Go binary).
- matrix `gate` flag makes the proxy (a pure inherited image) report-only.
- Grype flips to full report-only over the SBOM (OS + library) so the inherited
  backlog stays visible in the Security tab; base-image refresh tracked in
  plane-7fn.4.23, accept-via-VEX in 4.18.

Backend's only library vulns (PyJWT, cryptography) are fixed by Dependabot
#30/#29.

Refs: plane-7fn.4.22
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@aRustyDev
aRustyDev merged commit 76429d3 into main Jul 28, 2026
14 checks passed
@aRustyDev
aRustyDev deleted the woven/scope-gate-library branch July 28, 2026 05:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant