Some checks are pending
CD Preprod / Deploy to Preprod (push) Blocked by required conditions
CD Preprod / Notify Success (push) Blocked by required conditions
CD Preprod / Notify Failure (push) Blocked by required conditions
CD Preprod / Security gate (push) Successful in 29s
CD Preprod / Backend — Lint (push) Successful in 1m3s
CD Preprod / Frontend — Lint & Type-check (push) Successful in 1m9s
CD Preprod / Backend — Unit Tests (push) Successful in 1m5s
CD Preprod / Frontend — Unit Tests (push) Successful in 43s
CD Preprod / Backend — Integration Tests (push) Successful in 46s
CD Preprod / Build Frontend (push) Successful in 35s
CD Preprod / Build Backend (push) Successful in 1m3s
CD Preprod / Build Log Exporter (push) Successful in 34s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (amd64, backend) (push) Successful in 25s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (amd64, frontend) (push) Successful in 25s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (amd64, log-exporter) (push) Successful in 21s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (arm64, backend) (push) Successful in 24s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (arm64, frontend) (push) Successful in 23s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (arm64, log-exporter) (push) Successful in 22s
33 lines
1.3 KiB
Python
33 lines
1.3 KiB
Python
"""Show actionable image findings even when the blocking Trivy step failed."""
|
|
import json
|
|
import os
|
|
from pathlib import Path
|
|
|
|
|
|
def summarize(path):
|
|
try:
|
|
report = json.loads(path.read_text())
|
|
if not isinstance(report, dict) or not isinstance(report.get('Results'), list):
|
|
raise ValueError('Missing scan results')
|
|
except (OSError, ValueError):
|
|
print('Image report missing or invalid: inspect the Trivy step; scan not verified.')
|
|
return 1
|
|
|
|
count = 0
|
|
for result in report['Results']:
|
|
for finding in result.get('Vulnerabilities') or []:
|
|
if finding.get('Severity') not in ('HIGH', 'CRITICAL'):
|
|
continue
|
|
count += 1
|
|
print(f'{finding["Severity"]} {finding.get("VulnerabilityID", "unknown")}: '
|
|
f'{finding.get("PkgName", "unknown")} '
|
|
f'{finding.get("InstalledVersion", "unknown")} -> '
|
|
f'{finding.get("FixedVersion") or "no fixed version published"}')
|
|
print(f' Path: {finding.get("PkgPath") or result.get("Target", "unknown")}')
|
|
print(f'{count} HIGH/CRITICAL image findings. Full details: image-security artifact.')
|
|
return int(count > 0)
|
|
|
|
|
|
if __name__ == '__main__':
|
|
raise SystemExit(summarize(Path(os.environ['RUNNER_TEMP']) / 'image-security.json'))
|