Skip to content

feat: add weekly security scan workflow - #320

Merged
openshift-merge-bot[bot] merged 3 commits into
mainfrom
feat/add-weekly-security-scan-ARO-26962
May 14, 2026
Merged

openshift-merge-bot[bot] merged 3 commits into
mainfrom
feat/add-weekly-security-scan-ARO-26962

Conversation

@RadekCap

@RadekCap RadekCap commented May 14, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • ASO has no weekly security scanning — vulnerabilities on any branch go undetected
  • Add a weekly Trivy security scan workflow that covers all active branches (main, backplane-2.11, backplane-2.17, backplane-5.0, backplane-5.1)
  • The workflow runs every Monday at 12:00 UTC, uploads SARIF results to the Security tab, and auto-creates GitHub issues when vulnerabilities are found
  • Adapted from the existing CAPZ weekly security scan with ASO-specific action pinning

Jira: ARO-26962

Summary by CodeRabbit

  • New Features
    • Weekly automated security scans (also manually triggerable) run across supported branches on a scheduled cadence.
    • Produces SARIF uploads to the Security tab and downloadable text artifacts retained for 30 days.
    • Summarizes vulnerability counts (critical/high/medium/low/total) and embeds human-readable results in run summaries.
    • Automatically files or updates tracking issues/comments when vulnerabilities are found and fails the run to surface detections.

Add a weekly Trivy security scan that runs every Monday at 12:00 UTC
across all active branches (main, backplane-2.11, backplane-2.17,
backplane-5.0, backplane-5.1).

The workflow scans for vulnerabilities, uploads SARIF results to the
Security tab, and auto-creates GitHub issues when vulnerabilities are
found. This aligns ASO with the security scanning already in place
for CAPZ.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented May 14, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: a125ec33-7301-4077-8691-d3ec91bc7e5d

📥 Commits

Reviewing files that changed from the base of the PR and between 8ca4aa9 and f0568f3.

📒 Files selected for processing (1)
  • .github/workflows/weekly-security-scan.yaml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/weekly-security-scan.yaml

📝 Walkthrough

Walkthrough

Adds a new GitHub Actions workflow that runs Trivy weekly and on-demand across a branch matrix, validates and counts SARIF findings, uploads SARIF/artifacts to the Security tab, and creates or updates GitHub issues when vulnerabilities are detected.

Changes

Automated Weekly Security Scanning

Layer / File(s) Summary
Workflow trigger, matrix, and job scaffolding
.github/workflows/weekly-security-scan.yaml
Introduces the workflow name, weekly schedule (Mondays 12:00 UTC), manual dispatch, concurrency, repository permissions, branch matrix (main, backplane-2.11, backplane-2.17, backplane-5.0, backplane-5.1), runner, and job timeout.
Checkout and Trivy execution
.github/workflows/weekly-security-scan.yaml (scan steps)
Checks out each matrix branch and records the commit SHA; runs Trivy filesystem scans twice producing trivy-results.sarif (SARIF, severity-filtered, exit-code 1) and trivy-results.txt (human-readable); scan failures are tolerated to allow post-processing.
SARIF validation and severity counting
.github/workflows/weekly-security-scan.yaml (validation/counting steps)
Verifies SARIF file presence and JSON validity; uses jq to count findings by severity (CRITICAL/HIGH/MEDIUM/LOW), normalizes invalid/missing values to 0, computes total, and exposes counts as step outputs.
Summary, uploads, and artifacts
.github/workflows/weekly-security-scan.yaml (summary/upload steps)
Writes a step summary to $GITHUB_STEP_SUMMARY with counts and embedded trivy-results.txt when present; uploads SARIF to the Security tab via github/codeql-action/upload-sarif (pinned) and uploads SARIF + text as a per-branch artifact with 30-day retention.
Issue creation/update and final gating
.github/workflows/weekly-security-scan.yaml (issue/comment steps, final step)
On non-PR runs when Trivy indicates vulnerabilities, uses gh to find an open issue labeled security,trivy, and the branch name to comment or creates a new issue containing severity counts, run link, truncated Trivy output, and a Security-tab link. Final step fails the job (exit 1) when vulnerabilities were found.

Sequence Diagram

sequenceDiagram
    autonumber
    participant S as Scheduler
    participant R as Runner
    participant T as Trivy
    participant A as SARIF API
    participant G as GH CLI
    S->>R: scheduled or manual job (branch matrix)
    R->>T: checkout branch and run scans
    R->>R: validate SARIF and count severities
    R->>A: upload SARIF to Security tab
    alt vulnerabilities found and not a PR
        R->>G: find open issue by labels
        G-->>R: issue found or not
        R->>G: post comment or create issue with counts and output
    end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Suggested labels

lgtm

Suggested reviewers

  • marek-veber
  • mzazrivec

Poem

🐰 I hop each Monday with a careful sniff,
Through branches wide where secrets drift.
Trivy hums and writes its scores,
I leave a note and close old doors.
Safe code hops onward, brisk and swift.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Description check ❓ Inconclusive The description provides context and rationale but does not follow the repository's required template structure with sections like checklist. Consider completing the template checklist sections to indicate whether documentation/tests/samples are included, though the core content adequately explains the PR's purpose.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely summarizes the main change: adding a weekly security scan workflow to the repository.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/add-weekly-security-scan-ARO-26962

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/weekly-security-scan.yaml:
- Around line 15-22: The Trivy scan job ("scan") can run concurrently across
matrix entries and create duplicate GH issues; add a job-level concurrency block
under the scan job that uses the branch matrix value (group:
weekly-security-scan-${{ matrix.branch }}) and set cancel-in-progress: false so
only one job per branch runs the gh issue list → gh issue create sequence at a
time; update the scan job definition to include this concurrency stanza
referencing matrix.branch to serialize issue creation per branch.
- Around line 69-96: The jq commands that set CRITICAL/HIGH/MEDIUM/LOW currently
count rule definitions via .runs[].tool.driver.rules[]; change them to count
findings in .runs[].results[] and map SARIF result severity (e.g., .level ==
"error" → CRITICAL, .level == "warning" → HIGH, or adjust per Trivy's output) so
each vulnerability occurrence is counted; update the CRITICAL, HIGH, MEDIUM, LOW
assignments in the vuln-counts step (the variables CRITICAL, HIGH, MEDIUM, LOW
and the TOTAL calculation/outputs) to use the new .runs[].results[] selectors
and correct level-to-severity mapping.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 0799a222-ece0-4fcd-9c7b-19e09d32cb65

📥 Commits

Reviewing files that changed from the base of the PR and between b3572ee and fdf8c12.

📒 Files selected for processing (1)
  • .github/workflows/weekly-security-scan.yaml

Comment thread .github/workflows/weekly-security-scan.yaml
Comment thread .github/workflows/weekly-security-scan.yaml
RadekCap and others added 2 commits May 14, 2026 16:10
- Pin trivy-action comment to v0.35.0 instead of 'master'
- Fix cat|head||echo fallback that silently produces empty output
- Quote $GITHUB_STEP_SUMMARY for shell safety consistency
- Replace eval with ${!var}/declare for safer variable indirection
- Handle null SARIF rules array with jq // [] fallback

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add job-level concurrency keyed by branch to serialize the
gh issue list → gh issue create sequence per branch, preventing
duplicate issues from overlapping scheduled or manual runs.

CodeRabbit finding #1 for PR #320:
- File: .github/workflows/weekly-security-scan.yaml:15-22

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@RadekCap RadekCap left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Implemented Finding #1 (concurrency control): Added job-level concurrency with group: weekly-security-scan-${{ matrix.branch }} and cancel-in-progress: false to serialize issue creation per branch. Commit: f0568f377

Implemented Finding #2 (SARIF counting): Changed vulnerability counting from tool.driver.rules[] (rule metadata) to runs[].results[] cross-referenced with rules[.ruleIndex] to count actual finding occurrences by severity. Same CVE in multiple packages now correctly counts as multiple findings. Commit: f0568f377

@RadekCap

Copy link
Copy Markdown
Collaborator Author

AI Review Pipeline Summary

Category Details
Self-Review 5 findings found, 1 commit (8ca4aa91f)
Security Review 0 findings
CodeRabbit 2 rounds, 2 accepted, 0 denied
Pre-merge Checks 0 failures
Qodo 0 findings (not configured for this PR)

Accepted Findings

# Source Description File Commit
1 Self-review Pin trivy-action to v0.35.0, fix cat|head fallback, quote GITHUB_STEP_SUMMARY, replace eval with declare, handle null SARIF rules weekly-security-scan.yaml 8ca4aa91f
2 CodeRabbit R1 Add concurrency control per branch to prevent duplicate issue creation weekly-security-scan.yaml:15 f0568f377
3 CodeRabbit R1 Count SARIF results instead of rule definitions for accurate vulnerability counts weekly-security-scan.yaml:73-76 f0568f377

All CodeRabbit threads resolved: Yes. PR description updated: Pending.

🤖 Generated by /ai-review pipeline

@marek-veber marek-veber left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci

openshift-ci Bot commented May 14, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: marek-veber, RadekCap

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [RadekCap,marek-veber]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit 0eb36d0 into main May 14, 2026
8 checks passed
@openshift-merge-bot
openshift-merge-bot Bot deleted the feat/add-weekly-security-scan-ARO-26962 branch May 14, 2026 14:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants