Repository navigation
ci(security): scope release gate to our library deps (report inherited base images) - #36
Merged
Merged
Conversation
…d base images) Triaging the baseline (plane-7fn.4.22) showed the trivy/grype gate was ~95% inherited base-image OS packages (Alpine) + the inherited proxy Go binary (Caddy/stdlib/grpc/golang.org/x/*) — none of which our deps control, so the strict all-package gate would block every release on upstream base-image churn. Re-scope per the chosen posture (gate on OUR code, report the rest): - Trivy is the gate, scoped to LIBRARY packages (TRIVY_PKG_TYPES=library): fails only on fixable HIGH/CRITICAL in our pnpm-workspace + apps/api pip deps. Verified locally: frontend library-only = 0 (was 37 OS), proxy library-only = 46 (inherited Go binary). - matrix `gate` flag makes the proxy (a pure inherited image) report-only. - Grype flips to full report-only over the SBOM (OS + library) so the inherited backlog stays visible in the Security tab; base-image refresh tracked in plane-7fn.4.23, accept-via-VEX in 4.18. Backend's only library vulns (PyJWT, cryptography) are fixed by Dependabot #30/#29. Refs: plane-7fn.4.22 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Implements the chosen posture from
plane-7fn.4.22: gate on our code's deps, report the inherited base images. Triage showed the strict all-package trivy/grype gate was ~95% inherited Alpine OS packages + the inherited proxy Go binary (Caddy/stdlib/grpc/golang.org/x/*) — un-fixable without a base-image refresh — so it would block every release.library(TRIVY_PKG_TYPES=library): fails only on fixable HIGH/CRITICAL in our pnpm-workspace +apps/apipip deps. Verified locally:frontendlibrary-only = 0 (was 37 OS),proxylibrary-only = 46 (inherited Go binary).matrix.gateflag makes the proxy (a pure inherited image, no code of ours) report-only.4.23; VEX-accept in4.18.Backend's only library vulns (
PyJWT,cryptography) are fixed by Dependabot #30/#29 (#29 merged).Type of Change
Test Scenarios
workflow_dispatchdry-run: all 6 images green (JS = 0 library; backend = 0 after chore(deps): bump cryptography from 46.0.7 to 48.0.1 in /apps/api/requirements #29/chore(deps): bump pyjwt from 2.12.0 to 2.13.0 in /apps/api/requirements #30; proxy = report-only). Security tab showstrivy-*(library) +grype-*(full) categories.References
🤖 Generated with Claude Code