diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 8a763faaa2..6be720a8d3 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -76,6 +76,10 @@ jobs: build-docker: needs: build-maven runs-on: 'ubuntu-latest' + permissions: + contents: read + # upload the Trivy scan of the built image to code scanning + security-events: write services: registry: image: registry:2 @@ -490,3 +494,26 @@ jobs: http://openam3.example.org:8080/openam/json/authenticate | grep tokenId' docker inspect --format="{{json .State.Health.Status}}" test-openam3 | grep -q \"healthy\" + + - name: Scan image for vulnerabilities (Trivy) + # trivy resolves the image from the local Docker daemon, so only the runner's + # linux/amd64 manifest is scanned; cache: false keeps the ~1GB trivy DBs from + # evicting the m2-repository caches out of the repo's 10GB actions-cache quota + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 + with: + image-ref: ${{ env.OPENAM_IMAGE }} + format: sarif + output: trivy-results.sarif + severity: CRITICAL,HIGH + limit-severities-for-sarif: true + ignore-unfixed: true + scanners: vuln + cache: false + - name: Upload Trivy report to GitHub Security + uses: github/codeql-action/upload-sarif@v4 + # upload even if a preceding step failed, but not without a report to upload + if: ${{ always() && hashFiles('trivy-results.sarif') != '' }} + with: + sarif_file: trivy-results.sarif + # distinct from the docker-scan.yml category, which tracks the published image + category: trivy-build diff --git a/.github/workflows/docker-scan.yml b/.github/workflows/docker-scan.yml new file mode 100644 index 0000000000..4e4d175770 --- /dev/null +++ b/.github/workflows/docker-scan.yml @@ -0,0 +1,55 @@ +# The contents of this file are subject to the terms of the Common Development and +# Distribution License (the License). You may not use this file except in compliance with the +# License. +# +# You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the +# specific language governing permission and limitations under the License. +# +# When distributing Covered Software, include this CDDL Header Notice in each file and include +# the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL +# Header, with the fields enclosed by brackets [] replaced by your own identifying +# information: "Portions copyright [year] [name of copyright owner]". +# +# Copyright 2026 3A Systems, LLC. + +# Scans the published Docker image for known vulnerabilities: new CVEs surface in +# already-released images (mostly via the base image), without any change in this repository. +name: Docker Scan + +on: + schedule: + - cron: '30 5 * * 1' + workflow_dispatch: + +permissions: + contents: read + +jobs: + scan: + # Do not run the scheduled scan in forks; manual runs are always allowed. + if: github.event_name == 'workflow_dispatch' || github.repository == 'OpenIdentityPlatform/OpenAM' + runs-on: ubuntu-latest + permissions: + contents: read + security-events: write + steps: + - uses: actions/checkout@v7 + - name: Scan openidentityplatform/openam:latest (Trivy) + # unlike the build.yml gate, unfixed CVEs are reported too: surfacing them in + # the already-released image is the point of this workflow + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 + with: + image-ref: openidentityplatform/openam:latest + format: sarif + output: trivy-latest.sarif + severity: CRITICAL,HIGH + limit-severities-for-sarif: true + scanners: vuln + cache: false + - name: Upload report to GitHub Security + uses: github/codeql-action/upload-sarif@v4 + # upload even if a preceding step failed, but not without a report to upload + if: ${{ always() && hashFiles('trivy-latest.sarif') != '' }} + with: + sarif_file: trivy-latest.sarif + category: trivy-image-latest