Two unrelated causes, plus one that hid the others. govulncheck: setup-go used go-version-file, so it installed exactly what each go.mod pins -- `go 1.25.0` -- and then reported 28 CVEs in that release's standard library (crypto/x509 quadratic name-constraint parsing, GO-2025-4007, and friends), all fixed in 1.25.3. None of it described anything we ship: every Dockerfile builds FROM golang:1.25-alpine, a floating tag that resolves to the newest 1.25.x, so the binaries already had the fixes. The go directive is a minimum language version, not a statement about which toolchain to audit with. Track the floating 1.25 line instead, and the scan matches production. Confirmed by running govulncheck against a patched toolchain locally: deploy/operator reports 0 vulnerabilities and exits 0. cargo-deny: RUSTSEC-2024-0384, `instant` is unmaintained. A maintenance advisory rather than a vulnerability -- no CVE, nothing to patch -- and it arrives transitively via tantivy 0.22.1 -> measure_time 0.8.3, so it cannot be dropped without moving off the pinned Tantivy. The advisory's substance does not apply here anyway: instant papers over std::time::Instant being missing on wasm, and search builds native musl. Ignored in search/deny.toml with that reasoning recorded and a note to delete the entry at the next Tantivy upgrade rather than let it ossify. Both matrices now set fail-fast: false. Only two of the twelve jobs actually failed; the other nine were cancelled, which made a two-cause failure look like a total collapse and hid every finding but the first.
97 lines
3.7 KiB
YAML
97 lines
3.7 KiB
YAML
name: Security scan
|
|
|
|
# Closes a real gap the security audit found: license-compliance.yml
|
|
# (this repo's only other workflow) checks license text, never
|
|
# vulnerabilities -- and agent/deny.toml and search/deny.toml already
|
|
# ship an [advisories] policy that nothing in CI ever invoked. Same
|
|
# matrix-per-language shape as license-compliance.yml, extended to the
|
|
# equivalent vulnerability-scanning tool per ecosystem: cargo-deny's
|
|
# other command for Rust, govulncheck for Go, npm audit for the one
|
|
# npm package. A new dependency with a known vulnerability now fails
|
|
# the build here, not months later when someone happens to re-run this
|
|
# by hand.
|
|
|
|
on:
|
|
push:
|
|
branches: [master, main]
|
|
pull_request:
|
|
|
|
jobs:
|
|
rust-advisories:
|
|
name: Rust vulnerability check (cargo-deny)
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
crate_dir: [agent, search]
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: EmbarkStudios/cargo-deny-action@v2
|
|
with:
|
|
manifest-path: ${{ matrix.crate_dir }}/Cargo.toml
|
|
command: check advisories
|
|
|
|
go-vulncheck:
|
|
name: Go vulnerability check (govulncheck)
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
# One module's findings must not cancel the other eight -- with
|
|
# fail-fast a single failure hid the whole matrix behind one log.
|
|
fail-fast: false
|
|
matrix:
|
|
# Same module list as license-compliance.yml's go-licenses job --
|
|
# see that job's own comment for why cli/hack-webhook-sink/
|
|
# hack-alert-load-test are excluded (no third-party dependencies
|
|
# at audit time).
|
|
module_dir:
|
|
- api
|
|
- ingest
|
|
- alerting
|
|
- enterprise
|
|
- deploy/operator
|
|
- terraform
|
|
- proto
|
|
- hack/benchmark-fixture
|
|
- hack/windows-fixture
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-go@v5
|
|
with:
|
|
# Deliberately NOT go-version-file. Each go.mod pins an exact
|
|
# patch (`go 1.25.0`), so go-version-file made CI scan against
|
|
# the *unpatched* 1.25.0 standard library and fail on 28
|
|
# stdlib CVEs -- crypto/x509 quadratic name-constraint parsing
|
|
# (GO-2025-4007) and friends, all fixed in 1.25.3. None of it
|
|
# was real: every Dockerfile builds `FROM golang:1.25-alpine`,
|
|
# a floating tag that resolves to the newest 1.25.x, so the
|
|
# shipped binaries already had the fixes. The go directive
|
|
# states the minimum language version, not the toolchain to
|
|
# audit with. Track the floating 1.25 line so this scans what
|
|
# production actually builds.
|
|
go-version: '1.25'
|
|
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
|
|
- name: Check for known vulnerabilities
|
|
working-directory: ${{ matrix.module_dir }}
|
|
run: govulncheck ./...
|
|
|
|
npm-audit:
|
|
name: npm vulnerability check (npm audit)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 22
|
|
- working-directory: web
|
|
run: npm ci
|
|
- name: Audit production dependencies
|
|
working-directory: web
|
|
# --omit=dev, not the deprecated --production: this deliberately
|
|
# only gates the runtime bundle a real deployment actually
|
|
# ships. The one known finding in web's full dependency tree
|
|
# today (a `cookie` advisory) lives entirely in the SvelteKit
|
|
# build toolchain, not the production bundle -- fixing it needs
|
|
# a deliberate, tested major-version bump, not an automated
|
|
# `audit fix --force`, so it's out of scope for this gate.
|
|
run: npm audit --omit=dev
|