Skip to content

security: pin base images in FROM, sign release checksums, add fuzz test and OSV config - #3

Merged
krax1337 merged 1 commit into
mainfrom
security/scorecard-fixes
Sep 24, 2026
Merged

krax1337 merged 1 commit into
mainfrom
security/scorecard-fixes

Conversation

@krax1337

Copy link
Copy Markdown
Owner

Fixes the fixable OpenSSF Scorecard findings in the Security tab.

  • Pinned-Dependencies (Dockerfile:6, :40): both base images are now pinned by multi-arch index digest directly in FROM. Scorecard can't resolve ARGs, and neither can Dependabot, so the base images were never being bumped.
  • Signed-Releases: the release job now attaches checksums.txt.sigstore.json (keyless cosign) and notation-aws-verifier_<version>.intoto.jsonl (SLSA provenance bundle). v1.0.0 was backfilled with its existing provenance bundle, verified offline with gh attestation verify --bundle.
  • Fuzzing: FuzzProcessRequestData runs the /checkimages body decode + validation path. Local run: 680k execs in 45s, no failures. Seeds run in normal go test.
  • Vulnerabilities: osv-scanner.toml ignores the 6 OSV findings with reasons (same decisions as .govulncheck-ignore / .trivyignore.yaml; grpc entry expires 2026-12-31). osv-scanner scan source locally: all 6 filtered, no issues.

Not fixable by code: Code-Review and Branch-Protection (need a second maintainer), Maintained (needs 90 days), CII-Best-Practices (needs the bestpractices.dev form).

…est and OSV config

Addresses OpenSSF Scorecard findings: Pinned-Dependencies (Dockerfile FROM lines resolved through ARGs), Signed-Releases (signature and provenance now attached to the GitHub release), Fuzzing (native Go fuzz test for request parsing) and Vulnerabilities (osv-scanner.toml with reasons, mirroring .govulncheck-ignore).
@krax1337
krax1337 merged commit 5add5e6 into main Sep 24, 2026
8 checks passed
@krax1337
krax1337 deleted the security/scorecard-fixes branch September 24, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant