From 4bc4594d6a2ee6cb5c13a65d87e1c3f10f77f789 Mon Sep 17 00:00:00 2001 From: "SUSE Observability AI (POC)" Date: Mon, 5 Oct 2026 08:09:03 +0000 Subject: [PATCH 1/3] Keep CVEs reporting-only and require valid scan evidence --- .github/workflows/ci.yml | 20 ++++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 252d3363..cb65009e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -181,10 +181,13 @@ jobs: healthcheck="$(docker image inspect --format '{{json .Config.Healthcheck.Test}}' "${image}")" grep -F '/probe.sh' <<< "${healthcheck}" - - name: Scan image with VEX-aware Trivy and Grype + - name: Report Trivy and Grype CVEs; gate secrets and scan errors uses: StackVista/image-pipeline/.github/actions/scan-image@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 + env: + TRIVY_SEVERITY: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL with: image: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} + # CVEs are reporting-only; secrets and scanner/evaluator errors still fail. mode: inform severity: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL with-grype: true @@ -192,13 +195,26 @@ jobs: upload-sarif: false sarif-category: process-agent-${{ matrix.arch }} + - name: Validate required scan reports + run: | + set -euo pipefail + for report in reports/trivy-secrets.json reports/trivy.json; do + jq -e ' + .SchemaVersion == 2 and + (.ArtifactName | type == "string" and length > 0) and + (.Results == null or (.Results | type == "array")) + ' "${report}" > /dev/null + done + jq -e 'type == "object" and (.matches | type == "array")' reports/grype.json > /dev/null + jq -e '.version == "2.1.0" and (.runs | type == "array" and length > 0)' reports/image-pipeline.sarif > /dev/null + - name: Upload image scan evidence if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: process-agent-scan-${{ matrix.arch }} path: reports/ - if-no-files-found: warn + if-no-files-found: error retention-days: 14 publish-image: From cdb5122412f5257f7721d11ea5e7efa3f5c15948 Mon Sep 17 00:00:00 2001 From: "SUSE Observability AI (POC)" Date: Mon, 5 Oct 2026 09:01:29 +0000 Subject: [PATCH 2/3] Remove explanatory scan-policy YAML comment --- .github/workflows/ci.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index cb65009e..b1eb1ce6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -187,7 +187,6 @@ jobs: TRIVY_SEVERITY: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL with: image: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} - # CVEs are reporting-only; secrets and scanner/evaluator errors still fail. mode: inform severity: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL with-grype: true From 676402d9557d1d41c96ce6c96e577859f5b41e9c Mon Sep 17 00:00:00 2001 From: "SUSE Observability AI (POC)" Date: Mon, 5 Oct 2026 09:14:42 +0000 Subject: [PATCH 3/3] Restore existing inform workflow and withdraw report hardening --- .github/workflows/ci.yml | 19 ++----------------- 1 file changed, 2 insertions(+), 17 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b1eb1ce6..252d3363 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -181,10 +181,8 @@ jobs: healthcheck="$(docker image inspect --format '{{json .Config.Healthcheck.Test}}' "${image}")" grep -F '/probe.sh' <<< "${healthcheck}" - - name: Report Trivy and Grype CVEs; gate secrets and scan errors + - name: Scan image with VEX-aware Trivy and Grype uses: StackVista/image-pipeline/.github/actions/scan-image@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 - env: - TRIVY_SEVERITY: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL with: image: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} mode: inform @@ -194,26 +192,13 @@ jobs: upload-sarif: false sarif-category: process-agent-${{ matrix.arch }} - - name: Validate required scan reports - run: | - set -euo pipefail - for report in reports/trivy-secrets.json reports/trivy.json; do - jq -e ' - .SchemaVersion == 2 and - (.ArtifactName | type == "string" and length > 0) and - (.Results == null or (.Results | type == "array")) - ' "${report}" > /dev/null - done - jq -e 'type == "object" and (.matches | type == "array")' reports/grype.json > /dev/null - jq -e '.version == "2.1.0" and (.runs | type == "array" and length > 0)' reports/image-pipeline.sarif > /dev/null - - name: Upload image scan evidence if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: process-agent-scan-${{ matrix.arch }} path: reports/ - if-no-files-found: error + if-no-files-found: warn retention-days: 14 publish-image: