diff --git a/.circleci/config.yml b/.circleci/config.yml index 2416772342..ace66e7602 100644 --- a/.circleci/config.yml +++ b/.circleci/config.yml @@ -156,6 +156,39 @@ jobs: name: Check built image availability command: docker images "richie:${CIRCLE_SHA1}*" + # ---- Security jobs ---- + # CVEs (report only, never fails) + scan-cve: + docker: + - image: cimg/base:current + auth: + username: $DOCKER_USER + password: $DOCKER_PASS + working_directory: ~/fun + steps: + - checkout + - setup_remote_docker: + version: default + - run: + name: Build production image + command: docker build -t richie:${CIRCLE_SHA1} --target production . + - run: + name: Install trivy + command: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sudo sh -s -- -b /usr/local/bin + - run: + name: Scan runtime environment (OS packages) for known CVEs + command: | + mkdir -p reports/trivy + trivy image --vuln-type os --exit-code 0 --format template --template "@.circleci/templates/trivy-cve-report.tpl" -o reports/trivy/env-report.html richie:${CIRCLE_SHA1} + - run: + name: Scan back-end application dependencies for known CVEs + command: trivy image --vuln-type library --exit-code 0 --format template --template "@.circleci/templates/trivy-cve-report.tpl" -o reports/trivy/back-report.html richie:${CIRCLE_SHA1} + - run: + name: Scan front-end application dependencies for known CVEs + command: trivy fs --vuln-type library --exit-code 0 --format template --template "@.circleci/templates/trivy-cve-report.tpl" -o reports/trivy/front-report.html src/frontend + - store_artifacts: + path: reports/trivy + # ---- Backend jobs ---- # Build backend development environment build-back: @@ -998,6 +1031,15 @@ workflows: tags: only: /.*/ + # Security jobs + # + # Scan the production docker image for known CVEs (report only, never + # blocks the pipeline) + - scan-cve: + filters: + tags: + only: /.*/ + # Backend jobs # # Build, lint and test production and development Docker images diff --git a/.circleci/templates/trivy-cve-report.tpl b/.circleci/templates/trivy-cve-report.tpl new file mode 100644 index 0000000000..5f11a63692 --- /dev/null +++ b/.circleci/templates/trivy-cve-report.tpl @@ -0,0 +1,68 @@ + + + + + Trivy CVE Report - {{ now }} + + + + +

Trivy CVE Report - {{ now }}

+ + + + + + + + + + + + + + {{- range . }} + {{- $target := .Target }} + {{- range .Vulnerabilities }} + {{- $sev := .Vulnerability.Severity }} + {{- $rank := 0 }} + {{- if eq $sev "CRITICAL" }}{{ $rank = 4 }} + {{- else if eq $sev "HIGH" }}{{ $rank = 3 }} + {{- else if eq $sev "MEDIUM" }}{{ $rank = 2 }} + {{- else if eq $sev "LOW" }}{{ $rank = 1 }} + {{- end }} + + + + + + + + + + {{- end }} + {{- end }} + +
TargetPackageVulnerability IDSeverityInstalled VersionFixed VersionTitle
{{ escapeXML $target }}{{ escapeXML .PkgName }}{{ escapeXML .VulnerabilityID }}{{ escapeXML $sev }}{{ escapeXML .InstalledVersion }}{{ escapeXML .FixedVersion }}{{ escapeXML .Title }}
+ + + + + diff --git a/CHANGELOG.md b/CHANGELOG.md index c34bb74c4b..0b1c7d41db 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,6 +10,7 @@ Versioning](https://semver.org/spec/v2.0.0.html). ### Added +- Add Trivy CVE scan job in CI (report only, non-blocking) - Handle aliases in mail regex for b2b sale tunnel - Add next_url configuration for OpenEdX Hawthorn login/register redirects