docs(ci): update security scan briefing with gitleaks fix details + PR264 review
CI/CD Pipeline / Unit Tests (pull_request) Failing after 9s
CI/CD Pipeline / Validate Code Quality And Tests (pull_request) Failing after 10s
CI/CD Pipeline / Integration Tests (pull_request) Failing after 26s
CI/CD Pipeline / Production Browser E2E (pull_request) Failing after 1558h36m40s
CI/CD Pipeline / Staging E2E Tests (pull_request) Failing after 1558h36m41s
CI/CD Pipeline / Build Production Runtime Images (pull_request) Failing after 1558h36m41s
CI/CD Pipeline / Deploy Production (pull_request) Failing after 1558h36m41s
CI/CD Pipeline / Build & Push Staging (Watchtower auto-deploy) (pull_request) Failing after 1558h36m41s
CI/CD Pipeline / Frontend Lint (pull_request) Has been skipped
CI/CD Pipeline / Staging API Integration Tests (pull_request) Failing after 1559h8m16s

This commit is contained in:
代码审计
2026-07-13 16:51:46 +08:00
parent 10cb082560
commit 90f3c0694c
+54 -20
View File
@@ -3,15 +3,15 @@
> 仓库: xiaoxia/xiaoxia-saas
> 扫描时间: 2026-07-13
> 负责人: 代码审计 Agent
> 状态: CI Runner 环境问题导致扫描结果暂不可用,代码已提交待验证
> 状态: CI 排队中(Runner 环境修复中),gitleaks 下载链路二次优化已提交,待 CI 跑通后获取真实扫描数据
## 一、概览
| 工具 | 优先级 | PR | 接入状态 | CI 验证 | 扫描结果 |
|---|---|---|---|---|---|
| gitleaks(密钥检测) | P0 | [#256](https://git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas/pulls/256) | ✅ 代码已提交 | ⚠️ Runner 卡住 | 待验证 |
| pip-audit(Python 依赖漏洞) | P1 | [#256](https://git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas/pulls/256) | ✅ 代码已提交 | ⚠️ Runner 卡住 | 待验证 |
| vulture(死代码检测) | P2 | [#259](https://git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas/pulls/259) | ✅ 代码已提交 | ❌ black 格式失败 | 待验证 |
| gitleaks(密钥检测) | P0 | [#256](https://git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas/pulls/256) | ✅ 二次优化提交 | 🕐 CI 排队中 | 待验证 |
| pip-audit(Python 依赖漏洞) | P1 | [#256](https://git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas/pulls/256) | ✅ 代码已提交 | 🕐 CI 排队中 | 待验证 |
| vulture(死代码检测) | P2 | [#259](https://git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas/pulls/259) | ✅ 代码已提交 | 🕐 等待 black 修复 + CI 排队 | 待验证 |
## 二、各工具详情
@@ -28,16 +28,26 @@
- 锁定文件(poetry.lock 等)
- 占位符字符串(`your-password`、`changeme`、`placeholder` 等)
**下载问题(已修复)**
- 问题:国内服务器直接访问 GitHub 超时(130s)
- 修复:增加国内镜像下载源(ghproxy mirror 优先),多源 fallback
- 修复 commit:`fix(ci): add Chinese mirror for gitleaks download`
**下载问题(第二轮修复已提交)**
- 第一轮修复(ghproxy + 99988866 + GitHub 直连):全部失败
- `mirror.ghproxy.com`: 连接超时(7.7s)
- `gh.api.99988866.xyz`: SSL 握手失败
- GitHub 直连: 120s 超时,仅下载 1.6MB/2.9MB
- 第二轮修复(6 个镜像 + go install 降级):
- 新增 4 个国内镜像:`gh-proxy.com`、`ghproxy.net`、`hub.gitmirror.com`、`ghps.cc`
- 每个镜像重试 2 次,connect-timeout 8s,max-time 90s
- 增加 `go install` 源码编译降级方案
- 全部失败时告警跳过(不阻断 CI),避免阻塞开发流程
- 修复 commit:`fix(ci): add more Chinese mirrors for gitleaks download + graceful degradation`
**长期建议**:在 Runner 镜像中预装 gitleaks 二进制,彻底避免下载问题
**CI 状态**
- Workflow Run #4075,分配到 Runner: `xiaoxia-ci-runner-new-2`
- 异常:Job 状态 `in_progress` 但所有步骤 `queued`,持续超过 5 分钟
- 判断:新 CI 服务器 Runner 执行环境问题,非代码配置问题
- 佐证:同批次 Frontend Lint Job 在 `xiaoxia-ci-runner-3` 上正常执行完成
- 当前状态:大量 CI 任务排队中(9 个 Runner 在线但任务堆积)
- 历史失败 Run #4071(旧 Runner):gitleaks 下载失败(见上)
- 历史失败 Run #4075(新 Runner):Job in_progress 但步骤全 queued(新 Runner 执行环境问题)
- 最新 Run #4096:queued 状态,等待执行
- 构建运维 Agent 正在修复:Runner 标签匹配 + 新 Runner 执行环境 + 并发优化
### 2. pip-audit Python 依赖漏洞扫描(P1)
@@ -76,7 +86,29 @@
- 说明:非 vulture 引入的问题(vulture 步骤还没执行到),是其他 Agent 修改了迁移安全检查脚本但没跑 black 格式化
- 建议:后端开发 Agent 在迁移安全 PR 中同步修复 black 格式问题
## 三、发现的其他 CI 问题
## 三、PR #264(前端清理)安全审查
**审查结论:✅ 无安全风险,可合并**
**审查范围**:PR #264 `cleanup/phase3-frontend` → `develop`,6 个文件变更(+261/-1359 行)
**检查项**:
| 检查项 | 结果 | 说明 |
|---|---|---|
| 危险 DOM 操作(innerHTML/eval 等) | ✅ 通过 | 未发现 dangerouslySetInnerHTML、eval、document.write 等 |
| 硬编码密钥/Token | ✅ 通过 | 未发现 API Key、Secret、Password 等硬编码 |
| 本地存储操作(localStorage 等) | ✅ 通过 | 未新增本地存储操作 |
| 开放重定向漏洞 | ✅ 通过 | 未新增 window.location / redirect 操作 |
| 新增第三方依赖 | ✅ 通过 | 仅新增 `@ant-design/icons` 的 DatabaseOutlined 图标 |
| 删除文件安全性 | ✅ 通过 | 删除 `apps/web/src/api/accounts.ts`(Mock API 文件),无安全影响 |
**核心变更性质**:
- 删除 Mock 数据(accounts.ts),替换为真实 API 调用或占位
- 清理 Admin.css 冗余样式(-460 行)
- Dashboard / GeneratePage / TitleLibrary 页面 Mock 替换为真实数据调用
- 整体净删除 1098 行,代码量减少,攻击面缩小
## 四、发现的其他 CI 问题
### Runner 环境问题
1. **新服务器 Runner 卡住**:`xiaoxia-ci-runner-new-2` 上的 Job 一直停留在 queued 状态,无法执行步骤
@@ -86,15 +118,17 @@
### 代码质量预存问题
1. `scripts/check_migration_safety.py` 不符合 black 格式(可能是后端开发刚改动过)
## 四、下一步计划
## 五、下一步计划
1. **等待 Runner 环境修复**:新服务器 Runner 执行环境问题修复后,重新触发 PR #256 CI
2. **修复 black 格式问题**:确认 vulture PR #259 中的 black 格式问题由后端开发在迁移安全 PR 中修复
3. **收集首次扫描数据**:CI 跑通后,整理 gitleaks / pip-audit / vulture 的首次扫描结果
4. **根据结果调优白名单**:如有误报,及时更新 `.gitleaks.toml` 和 `vulture_whitelist.py`
5. **推进 npm audit**:前端开发完成 PR #255 后接入 npm audit
1. **等待 CI 环境修复**:构建运维修复 Runner 标签匹配 + 执行环境 + 并发配置后,CI 才能正常运行
2. **收集首次扫描数据**:CI 跑通后,第一时间整理 gitleaks / pip-audit / vulture 的首次真实扫描结果
3. **根据结果调优白名单**:如有误报,及时更新 `.gitleaks.toml` 和 `vulture_whitelist.py`
4. **跟进 PR #259 black 格式问题**:等待后端开发修复 `check_migration_safety.py` 后 rebase 验证 vulture
5. **推动 gitleaks 预装**:建议在 Runner 镜像中预装 gitleaks,彻底规避下载链路问题
6. **推进 npm audit**:前端开发 PR #260 已提交 npm audit,等待 CI 验证
7. **PR #264 合并**:安全审查通过,CI 跑通后可合并
## 五、相关文档
## 六、相关文档
- [安全工具接入方案](docs/ci/代码安全扫描CI集成方案_report.md)
- [安全工具路线图](docs/ci/security-scanning-roadmap.md)