Skip to content

feat(ci): trivy image-scan on docker-publish (Phase A — audit only) - #883

Merged
LucasSantana-Dev merged 1 commit into
release/v2.12.0from
feat/trivy-image-scan-audit
May 16, 2026
Merged

LucasSantana-Dev merged 1 commit into
release/v2.12.0from
feat/trivy-image-scan-audit

Conversation

@LucasSantana-Dev

Copy link
Copy Markdown
Owner

Summary

Implements Phase A of the rollout from ADR `docs/decisions/2026-05-16-trivy-image-scan-vs-snyk-in-ci.md` (PR #882).

Adds a Trivy image-scan step to `.github/workflows/docker-publish.yml` that runs against each freshly-pushed image (bot / backend / frontend / nginx). Audit-only — findings land in the repo's Code Scanning tab as SARIF, never blocks CI.

Config (Phase A)

```yaml
severity: MEDIUM,HIGH,CRITICAL
ignore-unfixed: true
exit-code: '0' # audit-only
vuln-type: os,library # OS packages + language deps
```

One SARIF upload per service (`category: trivy-image-`) so the four matrix runs don't overwrite each other.

What this catches that the existing org-reusable Trivy doesn't

Existing org reusable This PR
`scan-type: fs` (filesystem only) `scan-type: image` (built image)
Misses base-image OS CVEs Catches Alpine/Debian package CVEs (the class that hit PR #881)
Filesystem-only IaC + config Image-layer + lang deps

Phase B (≥ 2 weeks from now, after baseline clean)

Will tighten to:

  • `severity: HIGH,CRITICAL`
  • `exit-code: '1'` — blocks publication on critical findings
  • Restructure to load-then-scan-then-push so a critical finding actually prevents the image from reaching ghcr.

Tracked in ADR's "Revisit when" + memory `project_security_scan_policy_2026-05-16.md`.

What does NOT change

  • Org reusable `quality.yml` Trivy job stays `scan-type: fs`
  • No Snyk CLI added to CI
  • Snyk GitHub App continues providing dashboard monitoring

Permissions

Adds `security-events: write` to the job (required for `upload-sarif`). No new secrets.

Test plan

  • CI passes on this PR (workflow change only; nothing actually fires until a publish event triggers `docker-publish.yml`)
  • On next `push: main` event: workflow runs, 4 Trivy scans complete, SARIF uploads to Code Scanning tab
  • After PR fix(security): apk upgrade nginx-alpine base on build to patch CVEs #881 + this PR + a publish: Snyk dashboard's Lucky row drops from 4C / 16H to ≤ 1C tail (whatever remains in non-nginx images)

Implements Phase A of the rollout in
docs/decisions/2026-05-16-trivy-image-scan-vs-snyk-in-ci.md.

Adds a per-image Trivy scan step that runs after build & push for each
service in the matrix (bot, backend, frontend, nginx). Findings upload
to the repo's Code Scanning tab as SARIF, one category per service so
matrix runs don't clobber each other.

Audit-only config (Phase A):
  severity: MEDIUM,HIGH,CRITICAL
  ignore-unfixed: true
  exit-code: '0'         # never blocks CI in Phase A
  vuln-type: os,library  # OS packages + language deps

Phase B (≥ 2 weeks after Phase A, baseline clean):
  severity: HIGH,CRITICAL
  exit-code: '1'         # blocks publish on the next critical

The image is scanned in the registry (post-push) for Phase A simplicity.
When Phase B lands the build will switch to load-then-scan-then-push so
a critical finding actually prevents publication.

Adds security-events: write to the job permissions (required for SARIF
upload).

Pair with: PR #882 (the ADR), PR #881 (Alpine CVE fix that motivated this).
@vercel

vercel Bot commented May 16, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment May 16, 2026 3:11am

Request Review

@coderabbitai

coderabbitai Bot commented May 16, 2026

Copy link
Copy Markdown

Warning

Rate limit exceeded

@LucasSantana-Dev has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 55 minutes and 46 seconds before requesting another review.

You’ve run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 0217ede8-b625-4a3f-8744-ef5c3d93b792

📥 Commits

Reviewing files that changed from the base of the PR and between 93f826a and 63ec908.

📒 Files selected for processing (1)
  • .github/workflows/docker-publish.yml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/trivy-image-scan-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LucasSantana-Dev has reached the 50-review limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@github-actions

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit 16b3765 into release/v2.12.0 May 16, 2026
28 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the feat/trivy-image-scan-audit branch May 16, 2026 03:17
LucasSantana-Dev added a commit that referenced this pull request May 21, 2026
## Summary

Cut v2.13.0 of Lucky. Bumps root + 4 workspaces from `2.11.0` → `2.13.0`
(skipping the archived `2.12.0`) and promotes the CHANGELOG
`[Unreleased]` block to `[2.13.0] - 2026-05-21`.

## Headline changes since v2.11.0

**Added**
- Guild Automation Module Executor seam + AutoMessages pilot (#901)
- Sentry React SDK + Router v7 tracing/replay on frontend (#876)
- Prometheus `/metrics` on backend (#875) + bot (#873)
- Guild join/leave history tracking (#872)
- Trivy image-scan on docker-publish, Phase A audit-only (#883)
- Self-hosted developer-tooling register on landing page (#868)

**Changed**
- Backend migrated to Zod 4 API (#919) — unblocked the CVE patch + ended
the lockfile fragility loop
- 3 bot circular-deps clusters broken (#885, #886, #888)

**Fixed**
- brace-expansion DoS + ws uninit-memory CVEs patched (#921)
- nginx-alpine CVEs (#881)
- CI postinstall rate limit + madge actionlint (#878, #905)

Full list in CHANGELOG.md.

## Next steps (after this PR merges)

1. Open `release/v2.13.0 → main` PR with merge-commit method
2. Tag `v2.13.0` on the merge commit
3. Cut next `release` (homelab-style bare branch) — Lucky's bare-release
migration is still pending the user removing protection on
`release/v2.11.0`
@LucasSantana-Dev LucasSantana-Dev mentioned this pull request May 21, 2026
3 tasks
LucasSantana-Dev added a commit that referenced this pull request May 21, 2026
## Release v2.13.0

Promotes \`release/v2.13.0\` to \`main\` for the v2.13.0 cut.

**$AHEAD commits across all merged PRs since v2.11.0 ship.**

(Skipping v2.12.0 — the branch existed but its work was rolled forward
into v2.13.0 alongside this session's Zod migration + CVE patches +
standards adoption.)

## Headline changes

**Added** — Guild Automation Module Executor pilot (#901), Sentry
frontend (#876), Prometheus metrics on bot+backend (#873, #875), guild
membership history (#872), Trivy image-scan Phase A (#883), landing
redesign (#868).

**Changed** — Backend migrated to Zod 4 API (#919), 3 bot circular-deps
clusters broken (#885/#886/#888).

**Fixed** — brace-expansion + ws moderate CVEs (#921), nginx-alpine CVEs
(#881), CI postinstall rate limit (#878), madge actionlint (#905).

**Internal** — shared coverageThreshold gate (#909/#914),
Feature-removal sweep checklist + dangerfile guard (#908/#913),
monitoring network, AI-doc policy, 4 new ADRs.

Full list in [CHANGELOG.md](./CHANGELOG.md).

## Merge method

This PR should land via **merge commit** (NOT squash) to preserve the
individual PR SHAs in main's history. After merge:

1. Tag \`v2.13.0\` on the merge commit
2. Create GitHub release with notes from CHANGELOG.md
3. Fast-forward \`release/v2.13.0\` to match the new main HEAD

## Test plan

- [ ] All 30 checks green except infra (snyk plan cap)
- [ ] Verify \`gh pr view 922 --json mergeCommit\` shows the chore-bump
commit on release tip
- [ ] After merge: confirm \`origin/main\` contains the full $AHEAD
commits

This branch was successfully deployed

1 active deployment
Preview — 63ec908f Deployed May 16, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant