Skip to content

ci: add DockSec container scan with SARIF upload - #34

Merged
CyberSunil merged 1 commit into
CyberSunil:mainfrom
advaitpatel:ci/docksec-sarif-scan
Sep 22, 2026
Merged

CyberSunil merged 1 commit into
CyberSunil:mainfrom
advaitpatel:ci/docksec-sarif-scan

Conversation

@advaitpatel

@advaitpatel advaitpatel commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

What this adds

A GitHub Actions workflow that scans the Dockerfile with OWASP DockSec
and uploads the results to the Security tab as SARIF, so container findings are
annotated inline on pull requests.

DockSec is an OWASP Lab Project (MIT). It wraps Hadolint and Trivy and reports
Dockerfile misconfigurations and image CVEs through a single SARIF upload.

Why

The Dockerfile itself is clean: DockSec scores it 82.5/100 with zero lint
findings. The base image is where the real number is - python:3.12-slim
(line 3) currently carries 44 HIGH CVEs.

Given what this repository is (a deliberately vulnerable OWASP LLM Top 10
training range, meant to be self-hosted), the container it ships in seems worth
keeping an eye on for reasons separate from the intentional lab vulnerabilities:
an unrelated HIGH CVE in the base image is not part of the training exercise,
it is just exposure a self-hoster picks up incidentally by running the range.

What it does not do

  • No API key and no AI calls: the workflow runs with scan_only: true, which is
    fully local to the runner.
  • It does not gate merges. There is no fail_on, so the job reports and never
    fails the build. Adding a gate later is a one-line change.
  • Scans the Dockerfile only, so the CVE count above is not what it reports on
    day one. Adding image: to the same step turns on the image scan once you
    decide where the built image comes from.

Details

  • Runs on pull requests and pushes that touch the Dockerfile, plus a weekly
    scheduled scan so newly disclosed CVEs in the base image surface without a
    code change.
  • All three actions are pinned to a commit SHA. persist-credentials: false on
    checkout, since nothing after it needs the token in git config.
  • security-events: write is scoped to the single job that needs it, and the
    SARIF upload is skipped on fork pull requests, where that permission does not
    apply and the upload would otherwise fail as a red required check.
  • Passes actionlint with no warnings.

Disclosure of interest: I am the project lead for DockSec, the tool this
workflow adds. Happy to close this if it is not a fit - no hard feelings either
way.

Scans the Dockerfile with DockSec and uploads the results to code scanning
as SARIF, so container findings are annotated on pull requests.

Runs scan-only, so no API key is required and no gate is added to the build.
All actions are pinned to a commit SHA.

Signed-off-by: Advait Patel <advaitpa93@gmail.com>
@advaitpatel

Copy link
Copy Markdown
Contributor Author

Hello @CyberSunil - integrating OWASP DockSec for container security analyzer as per our discussion in the OWASP Slack. Let me know your thoughts.

@CyberSunil
CyberSunil merged commit 24e77f3 into CyberSunil:main Sep 22, 2026
4 checks passed
@CyberSunil

Copy link
Copy Markdown
Owner

Thanks Advait, merged. Appreciate the contribution 🙏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants