Skip to content

Fix Grype false positives, patch Jammy, sort results, post digest to Slack - #173

Merged
jsokol merged 4 commits into
testingfrom
FIX-grype-false-positives
Sep 29, 2026
Merged

jsokol merged 4 commits into
testingfrom
FIX-grype-false-positives

Conversation

@jsokol

@jsokol jsokol commented Sep 29, 2026

Copy link
Copy Markdown
Member

Description

Cleans up the Grype scan results for the Docker images and makes them easier to track.

  • False positives (.grype.yaml): Grype's binary classifier reads PHP's own version (e.g. 8.5.11) out of curl.so and reports it as curl, so every curl CVE fixed after that number was flagged (43 findings on simplerisk-minimal). The real Debian curl is 8.14.1 and is scanned separately. Replaced the per-CVE ignores with one rule scoped to curl binaries under /usr/local/lib/php/extensions/**. Also ignored swagger-ui-dist, which is a release-script template (swagger-ui-dist-package/package.json, version literally $$VERSION) shipped inside the swagger-api/swagger-ui Composer package; the UI actually served is 5.x.
  • Jammy patching: the full-stack image ran apt-get install but never apt-get upgrade, so ubuntu:22.04 kept libc-bin 2.35-0ubuntu3.14 (5 CVEs fixed in 3.15). Added apt-get upgrade to the generator and the committed Dockerfile, matching the minimal image.
  • Sorted output: the scan now prints package, then severity (worst first), then vulnerability ID. --fail-on critical still gates the job (verified exit code 2 without the ignore rules).
  • Slack digest: each scan job uploads its grype.json (1-day retention); a final job posts one de-duplicated digest per run to SLACK_WEBHOOK_URL. It skips with a notice when the secret is absent (fork PRs).

Release Notes

N/A (CI and image-hardening only).

Testing

  • Scanned simplerisk-minimal:testing locally with the new .grype.yaml: no vulnerabilities. Rebuilt Jammy with the upgrade step: no vulnerabilities, libc-bin 3.15.
  • Ran the new scan step through a Docker grype shim: sorted table, exit 2 without ignores, exit 0 with them.
  • test_generate_dockerfile.sh passes; ShellCheck and actionlint clean on the new files.
  • Built the Slack payload from sample reports and posted it to the real webhook (two [TEST] messages, rendered correctly).
  • Not tested locally: the full CI run, the artifact upload/download, and the truncation path for very long digests. This PR's own run is the first real check. Noble was not rebuilt locally; CI showed only the two swagger findings there.

Notes for reviewers

The Slack post happens on every PR run with findings, from a final job that runs even when a scan job fails.

jsokol and others added 4 commits September 29, 2026 14:42
…ion, swagger-ui-dist template)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ches

ubuntu:22.04 ships libc-bin 2.35-0ubuntu3.14; 3.15 (fixing 5 CVEs) is in
jammy-updates. The minimal image already upgrades; the full-stack did not.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Each scan job uploads its grype.json (1-day retention); a final job builds one
de-duplicated digest (package, then severity) and posts it to the
SLACK_WEBHOOK_URL webhook, skipping cleanly when the secret is absent (fork PRs).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@jsokol
jsokol marked this pull request as ready for review September 29, 2026 21:10
@jsokol
jsokol merged commit 1a2b989 into testing Sep 29, 2026
8 checks passed
@jsokol
jsokol deleted the FIX-grype-false-positives branch September 29, 2026 21:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant