Skip to content

chore: refresh the hardened example's pins, scan workflows with CodeQL - #188

Merged
advaitpatel merged 1 commit into
mainfrom
chore/codeql-actions-and-example-pins
Sep 20, 2026
Merged

advaitpatel merged 1 commit into
mainfrom
chore/codeql-actions-and-example-pins

Conversation

@advaitpatel

Copy link
Copy Markdown
Collaborator

Both follow-ups identified during the #187 review.

Hardened example base images

examples/compose/docker-compose-secure.yml had been pinned since June and carried 35 CRITICAL/HIGH CVEs. Nothing surfaced that, because the example's images were silently failing to scan — so the CI assertion over them was running against an empty result until #187 made compose actually pull images.

  • nginx:1.25.3-alpine -> 1.31.6-alpine — now scans clean (0 findings)
  • postgres:15.5-alpine -> 15.19-alpine — 22 findings remain

The 22 are all in the Go stdlib compiled into the official postgres image, and have no fix available upstream at any tag. postgres:18.6-alpine reports exactly the same 22, so a major version jump buys nothing — the CVEs live in shared base layers, not the Postgres version. Staying on the actively-maintained 15 line (15.19 was published two days ago) keeps the example about configuration hardening rather than turning it into a version-upgrade guide.

Verified by scanning all three candidates before choosing.

CodeQL workflow scanning

Adds language: actions to the analysis matrix. CodeQL was already expecting that configuration and printed a warning on every pull request that it could not find one, which meant workflow files were never analyzed — including the two workflows edited in #187.

Autobuild is skipped for that language, which analyses YAML in place and has nothing to build.

Verification

  • 510 tests pass, ruff check . clean
  • The hardened-example CI assertion run verbatim: 0 config findings, 22 base-image CVEs (was 35)
  • No stale references to the old tags anywhere in the repo

Both follow-ups from the #187 review.

The hardened compose example had been pinned to nginx:1.25.3-alpine and
postgres:15.5-alpine since June, carrying 35 CRITICAL/HIGH CVEs. Nothing
surfaced that because the example's images were silently failing to scan,
so the assertion over them was running against an empty result.

nginx:1.31.6-alpine is clean. The 22 findings that remain are all in the
Go stdlib compiled into the official postgres image and have no fix at
any tag - 18.6-alpine reports exactly the same 22 - so the 15 line stays,
which keeps the example about configuration rather than turning it into a
major version upgrade. Verified by scanning all three candidates.

CodeQL gains `language: actions`, so the workflow files are analyzed. It
was already expecting a /language:actions configuration and warned on
every pull request that it could not find one. Autobuild is skipped for
that language, which analyses YAML in place and has nothing to build.
@github-actions github-actions Bot added documentation Improvements or additions to documentation ci Changes to CI/CD workflows docker Changes to Docker/container assets labels Sep 20, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@advaitpatel
advaitpatel merged commit c7c4b5e into main Sep 20, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Changes to CI/CD workflows docker Changes to Docker/container assets documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant