Repository navigation
ci: add DockSec container scan with SARIF upload - #209
Closed
advaitpatel wants to merge 1 commit into
Closed
advaitpatel wants to merge 1 commit into
advaitpatel wants to merge 1 commit into
Conversation
Signed-off-by: Advait Patel <advaitpa93@gmail.com>
Author
|
Hello @andreiio may I know the reason behind closing the PR? It would certainly help me to understand if I missed anything. Thank you! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this adds
A GitHub Actions workflow that scans the
Dockerfilewith OWASP DockSecand uploads the results to the Security tab as SARIF, so container findings are
annotated inline on pull requests.
DockSec is an OWASP Lab Project (MIT). It runs Trivy, Hadolint, and Docker
Scout locally, then ranks every finding by severity plus EPSS
exploitation likelihood and correlates them into attack chains, instead of
handing back a flat list of raw findings. This workflow uses
scan_onlymode, which reports the Dockerfile misconfiguration and CVE findings through
SARIF without the AI-assisted prioritization/correlation pass.
Why
DockSec scores the current
Dockerfileat 65/100, with three findings:I noticed this repo shares its Dockerfile structure closely with
code4romania/bursa-binelui, which I also opened a DockSec PR on today - thesame
DL3022finding on the same line number in both suggests it's a sharedtemplate pattern rather than two independent Dockerfiles, so fixing it once
might be worth propagating to both.
The base images (
php:8.2-fpm-alpine,node:24-alpine) are clean of knownCRITICAL/HIGH CVEs as of this scan.
What it does not do
scan_only: true, which isfully local to the runner.
fail_on, so the job reports and neverfails the build. Adding a gate later is a one-line change.
image:to the same step turns that on later.
Details
scheduled scan so newly disclosed CVEs in a base image surface without a code
change.
persist-credentials: falseoncheckout, since nothing after it needs the token in git config.
security-events: writeis scoped to the single job that needs it, and theSARIF upload is skipped on fork pull requests, where that permission does not
apply and the upload would otherwise fail as a red required check.
actionlintwith no warnings.Disclosure of interest: I am the project lead for DockSec, the tool this
workflow adds. Happy to close this if it is not a fit - no hard feelings either
way.