Skip to content

Scan published testing images, weekly :testing scan, per-image scan summary - #174

Merged
jsokol merged 2 commits into
testingfrom
FIX-grype-scan-completion-summary
Sep 29, 2026
Merged

jsokol merged 2 commits into
testingfrom
FIX-grype-scan-completion-summary

Conversation

@jsokol

@jsokol jsokol commented Sep 29, 2026

Copy link
Copy Markdown
Member

Description

Follow-up to #173. The PR validation scans an image built from the PR; the image that actually ships is rebuilt later from the testing bundle and promoted straight to tier=testing customers. This adds scans where they were missing and makes every run show that its scans finished.

  • Per-image summary: the run's log and summary page now list every scanned image with ✅ No findings, ⚠️ N findings (by severity), or ❌ scan did not complete. A scan that never produced a report is never shown as clean.
  • Scan before promote (publish-testing.yml): the minimal (php83/84/85) and full-stack (jammy/noble) images are scanned as published. The minimal scans run before the SSM promote step, so a critical finding fails the job and the promote does not happen (the tags are already pushed; the customer rollout is what is held back). Each scan is continue-on-error so every report is produced, then a gate step fails the job.
  • Weekly scan (scheduled-grype-scan.yml): Mondays 13:00 UTC and on manual dispatch, scans simplerisk/simplerisk-minimal:testing and simplerisk/simplerisk:testing, so a CVE disclosed after publish is still reported.
  • Refactor: the scan and the report are now composite actions (.github/actions/grype-scan, .github/actions/grype-report) used by PR validation, publish and the weekly scan, so there is one copy of the logic. Reports go to the same Slack digest (findings only) and artifacts keep 1-day retention.

Release Notes

N/A (CI only).

Testing

  • Ran the scan action's shell against the real simplerisk-minimal:testing image: clean case exits 0 and writes the report; the no-ignore case prints the sorted table and keeps the report. Summary and digest built from those reports render correctly.
  • YAML parses; actionlint reports nothing new (one existing SC2086 note in create_new_tag.yml); ShellCheck clean.
  • Not tested until it runs on GitHub: the composite actions themselves (this PR's validation run exercises them), the publish-workflow scan and the promote block (first runs on the next push to testing), and the weekly schedule (runs first on a Monday, or via manual dispatch).
  • The publish scans pull the pushed multi-arch tags and scan the runner's amd64 variant, so arm64-only findings would not show.

Notes for reviewers

The promote block only stops the SSM write; images and tags are already pushed by then. The scans are report-only for the full-stack image, which has no SSM tier.

jsokol and others added 2 commits September 29, 2026 16:14
…cl. all-clear)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…of :testing

Factor the Grype scan and the report (summary + Slack digest) into composite
actions shared by PR validation, publish-testing, and a new weekly workflow.
publish-testing scans the pushed images before the SSM promote and blocks it on
a critical finding.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@jsokol
jsokol marked this pull request as ready for review September 29, 2026 21:50
@jsokol
jsokol merged commit d14938f into testing Sep 29, 2026
8 checks passed
@jsokol
jsokol deleted the FIX-grype-scan-completion-summary branch September 29, 2026 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant