Repository navigation
security: pin base images in FROM, sign release checksums, add fuzz test and OSV config - #3
Merged
Merged
Conversation
…est and OSV config Addresses OpenSSF Scorecard findings: Pinned-Dependencies (Dockerfile FROM lines resolved through ARGs), Signed-Releases (signature and provenance now attached to the GitHub release), Fuzzing (native Go fuzz test for request parsing) and Vulnerabilities (osv-scanner.toml with reasons, mirroring .govulncheck-ignore).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the fixable OpenSSF Scorecard findings in the Security tab.
FROM. Scorecard can't resolveARGs, and neither can Dependabot, so the base images were never being bumped.checksums.txt.sigstore.json(keyless cosign) andnotation-aws-verifier_<version>.intoto.jsonl(SLSA provenance bundle). v1.0.0 was backfilled with its existing provenance bundle, verified offline withgh attestation verify --bundle.FuzzProcessRequestDataruns the/checkimagesbody decode + validation path. Local run: 680k execs in 45s, no failures. Seeds run in normalgo test.osv-scanner.tomlignores the 6 OSV findings with reasons (same decisions as.govulncheck-ignore/.trivyignore.yaml; grpc entry expires 2026-12-31).osv-scanner scan sourcelocally: all 6 filtered, no issues.Not fixable by code: Code-Review and Branch-Protection (need a second maintainer), Maintained (needs 90 days), CII-Best-Practices (needs the bestpractices.dev form).