Skip to content

ci: add DockSec container scan with SARIF upload - #209

Closed
advaitpatel wants to merge 1 commit into
code4romania:mainfrom
advaitpatel:ci/docksec-sarif-scan
Closed

advaitpatel wants to merge 1 commit into
code4romania:mainfrom
advaitpatel:ci/docksec-sarif-scan

Conversation

@advaitpatel

@advaitpatel advaitpatel commented Sep 22, 2026 •

Copy link
Copy Markdown

What this adds

A GitHub Actions workflow that scans the Dockerfile with OWASP DockSec
and uploads the results to the Security tab as SARIF, so container findings are
annotated inline on pull requests.

DockSec is an OWASP Lab Project (MIT). It runs Trivy, Hadolint, and Docker
Scout locally, then ranks every finding by severity plus EPSS
exploitation likelihood and correlates them into attack chains, instead of
handing back a flat list of raw findings. This workflow uses scan_only
mode, which reports the Dockerfile misconfiguration and CVE findings through
SARIF without the AI-assisted prioritization/correlation pass.

Why

DockSec scores the current Dockerfile at 65/100, with three findings:

DL3022 warning  line 9   `COPY --from` should reference a previously defined FROM alias
DL3018 warning  line 11  Pin versions in apk add
SC3057 warning  line 74  In POSIX sh, string indexing is undefined

I noticed this repo shares its Dockerfile structure closely with
code4romania/bursa-binelui, which I also opened a DockSec PR on today - the
same DL3022 finding on the same line number in both suggests it's a shared
template pattern rather than two independent Dockerfiles, so fixing it once
might be worth propagating to both.

The base images (php:8.2-fpm-alpine, node:24-alpine) are clean of known
CRITICAL/HIGH CVEs as of this scan.

What it does not do

  • No API key and no AI calls: the workflow runs with scan_only: true, which is
    fully local to the runner.
  • It does not gate merges. There is no fail_on, so the job reports and never
    fails the build. Adding a gate later is a one-line change.
  • Scans the Dockerfile only; it does not pull or build an image. Adding image:
    to the same step turns that on later.

Details

  • Runs on pull requests and pushes that touch the Dockerfile, plus a weekly
    scheduled scan so newly disclosed CVEs in a base image surface without a code
    change.
  • All three actions are pinned to a commit SHA. persist-credentials: false on
    checkout, since nothing after it needs the token in git config.
  • security-events: write is scoped to the single job that needs it, and the
    SARIF upload is skipped on fork pull requests, where that permission does not
    apply and the upload would otherwise fail as a red required check.
  • Passes actionlint with no warnings.

Disclosure of interest: I am the project lead for DockSec, the tool this
workflow adds. Happy to close this if it is not a fit - no hard feelings either
way.

Signed-off-by: Advait Patel <advaitpa93@gmail.com>
@advaitpatel
advaitpatel requested a review from a team as a code owner September 22, 2026 16:13
@andreiio andreiio closed this Sep 22, 2026
@advaitpatel

Copy link
Copy Markdown
Author

Hello @andreiio may I know the reason behind closing the PR? It would certainly help me to understand if I missed anything. Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants