Skip to content

ci: move image vulnerability scanning out of CI to a weekly scan of published images #1006

Description

@mforce

AMENDED 2026-10-02 — re-scoped by the owner. This issue now tracks
redesigning how CI handles container image vulnerability scanning, prompted
by the CVE described below:

  • Remove the Trivy scan from CI. It no longer runs on pull requests or on
    pushes to main, and it no longer gates publish. The image job keeps
    building and boot-testing both architectures, and those still gate publish.
  • Scan published images weekly, plus on demand with workflow_dispatch.
    Report findings to the Security tab and file one issue per
    vulnerability
    , updated by later runs rather than duplicated.
  • No ignore or accepted-risk file.

The PR implementing this closes this issue. It does not fix
CVE-2026-84782 itself. The weekly scan's first run files that as its own
issue, which closes when Microsoft ships a fixed aspnet:10.0 and the pin is
bumped.

Why: on 2026-10-01 this CVE in Microsoft's base image — unexploitable
here, see the comments below — turned every code PR's image check red and
stopped publish on every push to main. The last published image is
ad258d8f, and release v0.1.5 (#993) could not be promoted. Widely used
projects (Keycloak, Harbor, Kyverno) scan on a schedule and report rather
than block.

The original description is kept below for history.


The image job's Trivy gate now fails on every pull request that changes app code, because Microsoft's pinned .NET runtime image ships an OpenSSL with a fixable HIGH vulnerability.

Upstream: dotnet/dotnet-docker#7384 tracks Microsoft's rebuild. Its title names 10.0-noble-chiseled-extra, but the thread confirms the regular Ubuntu images we use are affected too. Ubuntu's fix is USN-8847. This closes when Microsoft ships a fixed aspnet:10.0 and we bump the pin.

What fails

ci.yml → Image build + Trivy scan → Scan image for HIGH/CRITICAL vulnerabilities:

Package CVE Severity Installed Fixed in
libssl3t64 CVE-2026-84782 HIGH 3.0.13-0ubuntu3.15 3.0.13-0ubuntu3.16
openssl CVE-2026-84782 HIGH 3.0.13-0ubuntu3.15 3.0.13-0ubuntu3.16

Title: openssl: Information disclosure via DTLS handshake retransmission. Both rows come from the runtime base mcr.microsoft.com/dotnet/aspnet:10.0@sha256:2d584d8147faddb0d678c5748d47953e5b8e18621ed4fb7049a91381d9d7746f (Ubuntu 24.04).

First seen on #985, run 36800931106, and reproduced on a rerun. main passed the same job with the same pinned digest at ad258d8f about 15 minutes earlier, so this comes from Trivy's vulnerability database learning about the fix, not from any change in this repo. The gate uses ignore-unfixed: true on purpose, so it fails only because Ubuntu has already shipped the fix.

Unrelated noise in the same log: an NU1004 restore error appears just before the scan. That is the deliberate #315 locked-mode drift check, which breaks the lock in a throwaway copy and expects the build to fail. It passed.

Impact

Decision

Wait for Microsoft to republish aspnet:10.0 with the fixed OpenSSL, then bump the pin. Declined for now:

To close this

  1. Watch for a new aspnet:10.0 digest:
    sg docker -c 'docker buildx imagetools inspect mcr.microsoft.com/dotnet/aspnet:10.0'
    The digest differing from 2d584d81… is the signal.
  2. Bump the pinned digest in src/Cluckwork.Api/Dockerfile. Dependabot's docker ecosystem is on a weekly schedule, so it may lag Microsoft by up to a week; bumping by hand, or triggering Dependabot, is fine. The sdk:10.0 build image may move in the same release and should be bumped alongside it.
  3. Confirm the image job's Trivy step passes on that PR, then rerun the failed jobs on any PR that was blocked (build: enforce file-scoped namespaces and using placement at build time #985 at time of filing).

If Microsoft has not shipped a fixed image within a week, revisit the declined options above.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency filedockerPull requests that update docker code

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions