feat: add weekly security scan workflow - #320
Conversation
Add a weekly Trivy security scan that runs every Monday at 12:00 UTC across all active branches (main, backplane-2.11, backplane-2.17, backplane-5.0, backplane-5.1). The workflow scans for vulnerabilities, uploads SARIF results to the Security tab, and auto-creates GitHub issues when vulnerabilities are found. This aligns ASO with the security scanning already in place for CAPZ. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughAdds a new GitHub Actions workflow that runs Trivy weekly and on-demand across a branch matrix, validates and counts SARIF findings, uploads SARIF/artifacts to the Security tab, and creates or updates GitHub issues when vulnerabilities are detected. ChangesAutomated Weekly Security Scanning
Sequence DiagramsequenceDiagram
autonumber
participant S as Scheduler
participant R as Runner
participant T as Trivy
participant A as SARIF API
participant G as GH CLI
S->>R: scheduled or manual job (branch matrix)
R->>T: checkout branch and run scans
R->>R: validate SARIF and count severities
R->>A: upload SARIF to Security tab
alt vulnerabilities found and not a PR
R->>G: find open issue by labels
G-->>R: issue found or not
R->>G: post comment or create issue with counts and output
end
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/weekly-security-scan.yaml:
- Around line 15-22: The Trivy scan job ("scan") can run concurrently across
matrix entries and create duplicate GH issues; add a job-level concurrency block
under the scan job that uses the branch matrix value (group:
weekly-security-scan-${{ matrix.branch }}) and set cancel-in-progress: false so
only one job per branch runs the gh issue list → gh issue create sequence at a
time; update the scan job definition to include this concurrency stanza
referencing matrix.branch to serialize issue creation per branch.
- Around line 69-96: The jq commands that set CRITICAL/HIGH/MEDIUM/LOW currently
count rule definitions via .runs[].tool.driver.rules[]; change them to count
findings in .runs[].results[] and map SARIF result severity (e.g., .level ==
"error" → CRITICAL, .level == "warning" → HIGH, or adjust per Trivy's output) so
each vulnerability occurrence is counted; update the CRITICAL, HIGH, MEDIUM, LOW
assignments in the vuln-counts step (the variables CRITICAL, HIGH, MEDIUM, LOW
and the TOTAL calculation/outputs) to use the new .runs[].results[] selectors
and correct level-to-severity mapping.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Enterprise
Run ID: 0799a222-ece0-4fcd-9c7b-19e09d32cb65
📒 Files selected for processing (1)
.github/workflows/weekly-security-scan.yaml
- Pin trivy-action comment to v0.35.0 instead of 'master'
- Fix cat|head||echo fallback that silently produces empty output
- Quote $GITHUB_STEP_SUMMARY for shell safety consistency
- Replace eval with ${!var}/declare for safer variable indirection
- Handle null SARIF rules array with jq // [] fallback
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add job-level concurrency keyed by branch to serialize the gh issue list → gh issue create sequence per branch, preventing duplicate issues from overlapping scheduled or manual runs. CodeRabbit finding #1 for PR #320: - File: .github/workflows/weekly-security-scan.yaml:15-22 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
RadekCap
left a comment
There was a problem hiding this comment.
Implemented Finding #1 (concurrency control): Added job-level concurrency with group: weekly-security-scan-${{ matrix.branch }} and cancel-in-progress: false to serialize issue creation per branch. Commit: f0568f377
Implemented Finding #2 (SARIF counting): Changed vulnerability counting from tool.driver.rules[] (rule metadata) to runs[].results[] cross-referenced with rules[.ruleIndex] to count actual finding occurrences by severity. Same CVE in multiple packages now correctly counts as multiple findings. Commit: f0568f377
AI Review Pipeline Summary
Accepted Findings
All CodeRabbit threads resolved: Yes. PR description updated: Pending. 🤖 Generated by |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: marek-veber, RadekCap The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Summary
main,backplane-2.11,backplane-2.17,backplane-5.0,backplane-5.1)Jira: ARO-26962
Summary by CodeRabbit