ci: add DockSec container scan with SARIF upload - #34
Merged
Merged
Conversation
Scans the Dockerfile with DockSec and uploads the results to code scanning as SARIF, so container findings are annotated on pull requests. Runs scan-only, so no API key is required and no gate is added to the build. All actions are pinned to a commit SHA. Signed-off-by: Advait Patel <advaitpa93@gmail.com>
Contributor
Author
|
Hello @CyberSunil - integrating OWASP DockSec for container security analyzer as per our discussion in the OWASP Slack. Let me know your thoughts. |
Owner
|
Thanks Advait, merged. Appreciate the contribution 🙏 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this adds
A GitHub Actions workflow that scans the
Dockerfilewith OWASP DockSecand uploads the results to the Security tab as SARIF, so container findings are
annotated inline on pull requests.
DockSec is an OWASP Lab Project (MIT). It wraps Hadolint and Trivy and reports
Dockerfile misconfigurations and image CVEs through a single SARIF upload.
Why
The Dockerfile itself is clean: DockSec scores it 82.5/100 with zero lint
findings. The base image is where the real number is -
python:3.12-slim(line 3) currently carries 44 HIGH CVEs.
Given what this repository is (a deliberately vulnerable OWASP LLM Top 10
training range, meant to be self-hosted), the container it ships in seems worth
keeping an eye on for reasons separate from the intentional lab vulnerabilities:
an unrelated HIGH CVE in the base image is not part of the training exercise,
it is just exposure a self-hoster picks up incidentally by running the range.
What it does not do
scan_only: true, which isfully local to the runner.
fail_on, so the job reports and neverfails the build. Adding a gate later is a one-line change.
day one. Adding
image:to the same step turns on the image scan once youdecide where the built image comes from.
Details
scheduled scan so newly disclosed CVEs in the base image surface without a
code change.
persist-credentials: falseoncheckout, since nothing after it needs the token in git config.
security-events: writeis scoped to the single job that needs it, and theSARIF upload is skipped on fork pull requests, where that permission does not
apply and the upload would otherwise fail as a red required check.
actionlintwith no warnings.Disclosure of interest: I am the project lead for DockSec, the tool this
workflow adds. Happy to close this if it is not a fit - no hard feelings either
way.