Repository navigation
feat(ci): trivy image-scan on docker-publish (Phase A — audit only) - #883
Conversation
Implements Phase A of the rollout in docs/decisions/2026-05-16-trivy-image-scan-vs-snyk-in-ci.md. Adds a per-image Trivy scan step that runs after build & push for each service in the matrix (bot, backend, frontend, nginx). Findings upload to the repo's Code Scanning tab as SARIF, one category per service so matrix runs don't clobber each other. Audit-only config (Phase A): severity: MEDIUM,HIGH,CRITICAL ignore-unfixed: true exit-code: '0' # never blocks CI in Phase A vuln-type: os,library # OS packages + language deps Phase B (≥ 2 weeks after Phase A, baseline clean): severity: HIGH,CRITICAL exit-code: '1' # blocks publish on the next critical The image is scanned in the registry (post-push) for Phase A simplicity. When Phase B lands the build will switch to load-then-scan-then-push so a critical finding actually prevents publication. Adds security-events: write to the job permissions (required for SARIF upload). Pair with: PR #882 (the ADR), PR #881 (Alpine CVE fix that motivated this).
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Warning Rate limit exceeded
You’ve run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
LucasSantana-Dev has reached the 50-review limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Failed to generate code suggestions for PR |
|
## Summary Cut v2.13.0 of Lucky. Bumps root + 4 workspaces from `2.11.0` → `2.13.0` (skipping the archived `2.12.0`) and promotes the CHANGELOG `[Unreleased]` block to `[2.13.0] - 2026-05-21`. ## Headline changes since v2.11.0 **Added** - Guild Automation Module Executor seam + AutoMessages pilot (#901) - Sentry React SDK + Router v7 tracing/replay on frontend (#876) - Prometheus `/metrics` on backend (#875) + bot (#873) - Guild join/leave history tracking (#872) - Trivy image-scan on docker-publish, Phase A audit-only (#883) - Self-hosted developer-tooling register on landing page (#868) **Changed** - Backend migrated to Zod 4 API (#919) — unblocked the CVE patch + ended the lockfile fragility loop - 3 bot circular-deps clusters broken (#885, #886, #888) **Fixed** - brace-expansion DoS + ws uninit-memory CVEs patched (#921) - nginx-alpine CVEs (#881) - CI postinstall rate limit + madge actionlint (#878, #905) Full list in CHANGELOG.md. ## Next steps (after this PR merges) 1. Open `release/v2.13.0 → main` PR with merge-commit method 2. Tag `v2.13.0` on the merge commit 3. Cut next `release` (homelab-style bare branch) — Lucky's bare-release migration is still pending the user removing protection on `release/v2.11.0`
## Release v2.13.0 Promotes \`release/v2.13.0\` to \`main\` for the v2.13.0 cut. **$AHEAD commits across all merged PRs since v2.11.0 ship.** (Skipping v2.12.0 — the branch existed but its work was rolled forward into v2.13.0 alongside this session's Zod migration + CVE patches + standards adoption.) ## Headline changes **Added** — Guild Automation Module Executor pilot (#901), Sentry frontend (#876), Prometheus metrics on bot+backend (#873, #875), guild membership history (#872), Trivy image-scan Phase A (#883), landing redesign (#868). **Changed** — Backend migrated to Zod 4 API (#919), 3 bot circular-deps clusters broken (#885/#886/#888). **Fixed** — brace-expansion + ws moderate CVEs (#921), nginx-alpine CVEs (#881), CI postinstall rate limit (#878), madge actionlint (#905). **Internal** — shared coverageThreshold gate (#909/#914), Feature-removal sweep checklist + dangerfile guard (#908/#913), monitoring network, AI-doc policy, 4 new ADRs. Full list in [CHANGELOG.md](./CHANGELOG.md). ## Merge method This PR should land via **merge commit** (NOT squash) to preserve the individual PR SHAs in main's history. After merge: 1. Tag \`v2.13.0\` on the merge commit 2. Create GitHub release with notes from CHANGELOG.md 3. Fast-forward \`release/v2.13.0\` to match the new main HEAD ## Test plan - [ ] All 30 checks green except infra (snyk plan cap) - [ ] Verify \`gh pr view 922 --json mergeCommit\` shows the chore-bump commit on release tip - [ ] After merge: confirm \`origin/main\` contains the full $AHEAD commits



Summary
Implements Phase A of the rollout from ADR `docs/decisions/2026-05-16-trivy-image-scan-vs-snyk-in-ci.md` (PR #882).
Adds a Trivy image-scan step to `.github/workflows/docker-publish.yml` that runs against each freshly-pushed image (bot / backend / frontend / nginx). Audit-only — findings land in the repo's Code Scanning tab as SARIF, never blocks CI.
Config (Phase A)
```yaml
severity: MEDIUM,HIGH,CRITICAL
ignore-unfixed: true
exit-code: '0' # audit-only
vuln-type: os,library # OS packages + language deps
```
One SARIF upload per service (`category: trivy-image-`) so the four matrix runs don't overwrite each other.
What this catches that the existing org-reusable Trivy doesn't
Phase B (≥ 2 weeks from now, after baseline clean)
Will tighten to:
Tracked in ADR's "Revisit when" + memory `project_security_scan_policy_2026-05-16.md`.
What does NOT change
Permissions
Adds `security-events: write` to the job (required for `upload-sarif`). No new secrets.
Test plan