feat(build): 扫描门按可配严重度拦截并可接受已知风险,留存 Trivy 报告与 CycloneDX SBOM,面板构建页展示扫描结果
This commit is contained in:
37 files changed
+3577
-91
No files matched your search
@@ -1390,6 +1390,9 @@ trivy_java_db_repository = "registry.felis.svc:5000/mirror/trivy-java-db:1"
|
||||
build_disk_limit = "20Gi"
|
||||
build_user_namespaces = "off"
|
||||
build_runtime_class = "gvisor"
|
||||
scan_fail_on = ["CRITICAL"]
|
||||
scan_fail_unfixed = true
|
||||
scan_accept = ["CVE-2021-35515", "CVE-2025-67030"]
|
||||
|
||||
[registry.s3]
|
||||
endpoint = "https://s3.example"
|
||||
@@ -1430,6 +1433,9 @@ expect "a re-run carries the trivy java-DB mirror" \
|
||||
expect "a re-run carries the build disk cap" 'build_disk_limit = "20Gi"' "$out"
|
||||
expect "a re-run carries the build user-namespace mode" 'build_user_namespaces = "off"' "$out"
|
||||
expect "a re-run carries the build runtime class" 'build_runtime_class = "gvisor"' "$out"
|
||||
expect "a re-run carries the scan gate's blocking severities" 'scan_fail_on = ["CRITICAL"]' "$out"
|
||||
expect "a re-run carries the scan gate's unfixed-vulnerability rule" 'scan_fail_unfixed = true' "$out"
|
||||
expect "a re-run carries the scan gate's accepted finding ids" 'scan_accept = ["CVE-2021-35515", "CVE-2025-67030"]' "$out"
|
||||
expect "a re-run carries the [registry.s3] uploads subtable" "[registry.s3]" "$out"
|
||||
expect "the carried subtable keeps its keys" 'endpoint = "https://s3.example"' "$out"
|
||||
expect "url stays installer-owned" 'url = "registry.felis.svc:5000"' "$out"
|
||||
|
||||
Reference in new issue
Block a user