chore: refresh the hardened example's pins, scan workflows with CodeQL - #188
Merged
Merged
Conversation
Both follow-ups from the #187 review. The hardened compose example had been pinned to nginx:1.25.3-alpine and postgres:15.5-alpine since June, carrying 35 CRITICAL/HIGH CVEs. Nothing surfaced that because the example's images were silently failing to scan, so the assertion over them was running against an empty result. nginx:1.31.6-alpine is clean. The 22 findings that remain are all in the Go stdlib compiled into the official postgres image and have no fix at any tag - 18.6-alpine reports exactly the same 22 - so the 15 line stays, which keeps the example about configuration rather than turning it into a major version upgrade. Verified by scanning all three candidates. CodeQL gains `language: actions`, so the workflow files are analyzed. It was already expecting a /language:actions configuration and warned on every pull request that it could not find one. Autobuild is skipped for that language, which analyses YAML in place and has nothing to build.
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Both follow-ups identified during the #187 review.
Hardened example base images
examples/compose/docker-compose-secure.ymlhad been pinned since June and carried 35 CRITICAL/HIGH CVEs. Nothing surfaced that, because the example's images were silently failing to scan — so the CI assertion over them was running against an empty result until #187 made compose actually pull images.nginx:1.25.3-alpine->1.31.6-alpine— now scans clean (0 findings)postgres:15.5-alpine->15.19-alpine— 22 findings remainThe 22 are all in the Go
stdlibcompiled into the official postgres image, and have no fix available upstream at any tag.postgres:18.6-alpinereports exactly the same 22, so a major version jump buys nothing — the CVEs live in shared base layers, not the Postgres version. Staying on the actively-maintained 15 line (15.19 was published two days ago) keeps the example about configuration hardening rather than turning it into a version-upgrade guide.Verified by scanning all three candidates before choosing.
CodeQL workflow scanning
Adds
language: actionsto the analysis matrix. CodeQL was already expecting that configuration and printed a warning on every pull request that it could not find one, which meant workflow files were never analyzed — including the two workflows edited in #187.Autobuildis skipped for that language, which analyses YAML in place and has nothing to build.Verification
ruff check .clean