xpeditis2.0/scripts/ci/summarize-image-security.py
David 450f1ffc18
Some checks are pending
CD Preprod / Deploy to Preprod (push) Blocked by required conditions
CD Preprod / Notify Success (push) Blocked by required conditions
CD Preprod / Notify Failure (push) Blocked by required conditions
CD Preprod / Security gate (push) Successful in 29s
CD Preprod / Backend — Lint (push) Successful in 1m3s
CD Preprod / Frontend — Lint & Type-check (push) Successful in 1m9s
CD Preprod / Backend — Unit Tests (push) Successful in 1m5s
CD Preprod / Frontend — Unit Tests (push) Successful in 43s
CD Preprod / Backend — Integration Tests (push) Successful in 46s
CD Preprod / Build Frontend (push) Successful in 35s
CD Preprod / Build Backend (push) Successful in 1m3s
CD Preprod / Build Log Exporter (push) Successful in 34s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (amd64, backend) (push) Successful in 25s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (amd64, frontend) (push) Successful in 25s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (amd64, log-exporter) (push) Successful in 21s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (arm64, backend) (push) Successful in 24s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (arm64, frontend) (push) Successful in 23s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (arm64, log-exporter) (push) Successful in 22s
fix
2026-09-25 16:59:38 +02:00

33 lines
1.3 KiB
Python

"""Show actionable image findings even when the blocking Trivy step failed."""
import json
import os
from pathlib import Path
def summarize(path):
try:
report = json.loads(path.read_text())
if not isinstance(report, dict) or not isinstance(report.get('Results'), list):
raise ValueError('Missing scan results')
except (OSError, ValueError):
print('Image report missing or invalid: inspect the Trivy step; scan not verified.')
return 1
count = 0
for result in report['Results']:
for finding in result.get('Vulnerabilities') or []:
if finding.get('Severity') not in ('HIGH', 'CRITICAL'):
continue
count += 1
print(f'{finding["Severity"]} {finding.get("VulnerabilityID", "unknown")}: '
f'{finding.get("PkgName", "unknown")} '
f'{finding.get("InstalledVersion", "unknown")} -> '
f'{finding.get("FixedVersion") or "no fixed version published"}')
print(f' Path: {finding.get("PkgPath") or result.get("Target", "unknown")}')
print(f'{count} HIGH/CRITICAL image findings. Full details: image-security artifact.')
return int(count > 0)
if __name__ == '__main__':
raise SystemExit(summarize(Path(os.environ['RUNNER_TEMP']) / 'image-security.json'))