fix(ci): 修复三个安全扫描的问题
CI/CD Pipeline / Production Browser E2E (pull_request) Failing after 1535h56m3s
CI/CD Pipeline / Deploy Production (pull_request) Failing after 1535h56m4s
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (pull_request) Failing after 1535h56m4s
CI/CD Pipeline / Staging API Integration Tests (pull_request) Failing after 1535h56m4s
CI/CD Pipeline / Build Production API Image (pull_request) Failing after 1535h56m6s
CI/CD Pipeline / Build Staging Web Image (pull_request) Failing after 1535h56m6s
CI/CD Pipeline / Build Production Web Image (pull_request) Failing after 1535h56m5s
CI/CD Pipeline / Build Staging Worker Image (pull_request) Failing after 1535h56m6s
CI/CD Pipeline / Build Staging API Image (pull_request) Failing after 1535h56m7s
CI/CD Pipeline / Validate Code Quality And Tests (pull_request) Has been skipped
CI/CD Pipeline / Unit Tests (pull_request) Has been skipped
CI/CD Pipeline / Integration Tests (pull_request) Has been skipped
CI/CD Pipeline / Frontend Lint (pull_request) Has been skipped
CI/CD Pipeline / Build Production Worker Image (pull_request) Failing after 1536h27m44s
CI/CD Pipeline / Staging E2E Tests (pull_request) Failing after 1536h27m42s

- gitleaks: 增加ghproxy镜像源,解决下载失败问题
- pip-audit: 去掉--format text(不支持),用默认columns格式
- vulture: 改用命令行参数,移除有问题的toml配置文件和白名单文件
This commit is contained in:
CI Bot
2026-07-14 15:30:57 +08:00
parent d642f65028
commit bcb9f868ee
2 changed files with 44 additions and 37 deletions
+22 -10
View File
@@ -107,20 +107,30 @@ jobs:
set -eu
echo "=== Installing gitleaks ==="
GITLEAKS_VERSION="8.18.4"
GITLEAKS_FILE="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"
install_gitleaks() {
local url="$1"
curl -sSL -f -o /tmp/gitleaks.tar.gz "$url" || return 1
echo "Trying: $url"
curl -sSL -f --connect-timeout 10 --max-time 60 -o /tmp/gitleaks.tar.gz "$url" || return 1
tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks || return 1
chmod +x /tmp/gitleaks || return 1
/tmp/gitleaks version || return 1
return 0
}
if ! install_gitleaks "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"; then
echo "GitHub release failed, trying mirror..."
if ! install_gitleaks "https://gitee.com/mirrors/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"; then
echo "WARN: Failed to install gitleaks from all sources, skipping secret scan"
exit 0
GITLEAKS_INSTALLED=false
for mirror_url in \
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}" \
"https://ghproxy.com/https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}" \
"https://mirror.ghproxy.com/https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}" \
"https://gitee.com/mirrors/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}"; do
if install_gitleaks "$mirror_url"; then
GITLEAKS_INSTALLED=true
break
fi
done
if [ "$GITLEAKS_INSTALLED" = "false" ]; then
echo "WARN: Failed to install gitleaks from all sources, skipping secret scan"
exit 0
fi
echo ""
echo "=== Running gitleaks scan ==="
@@ -173,7 +183,7 @@ jobs:
for req_file in requirements.txt requirements-base.txt requirements-dev.txt; do
if [ -f "$req_file" ]; then
echo "--- Scanning $req_file ---"
pip-audit -r "$req_file" --desc on --format text 2>&1 | head -30 || EXIT_CODE=$?
pip-audit -r "$req_file" --desc on 2>&1 | head -40 || EXIT_CODE=$?
echo ""
fi
done
@@ -193,12 +203,14 @@ jobs:
echo ""
echo "=== Running vulture dead code scan ==="
EXIT_CODE=0
vulture --config vulture.conf vulture_whitelist.py || EXIT_CODE=$?
vulture apps packages scripts \
--exclude "tests,test,migrations,.gitea,docs,node_modules,site-packages,*/test_*.py,*/conftest.py" \
--min-confidence 80 \
2>&1 | head -60 || EXIT_CODE=$?
echo ""
echo "vulture scan completed (advisory mode - P2, for reference only)"
if [ "$EXIT_CODE" != "0" ]; then
echo "NOTE: Potential dead code found. Review results above."
echo "False positives can be added to vulture_whitelist.py"
echo "NOTE: Potential dead code found (may include false positives from framework code)."
fi
exit 0
+22 -27
View File
@@ -1,35 +1,30 @@
# vulture.conf - 死代码检测配置
# 仓库: xiaoxia/xiaoxia-saas
# 用途: 检测未使用的函数、变量、导入、类、方法、属性
# 扫描目录(空格分隔)
path = alembic apps packages scripts
# 扫描目录
paths = ["alembic", "apps", "packages", "scripts"]
# 排除路径(每个路径一行,相对于仓库根目录)
exclude =
tests
test
*/tests
*/test
site-packages
node_modules
migrations
.gitea
docs
scripts/check_*.py
scripts/init_*.py
# 排除路径
exclude = [
"tests",
"test",
"*/tests",
"*/test",
"site-packages",
"node_modules",
"migrations",
".gitea",
"docs",
]
# 最低置信度 (%)
# 0 = 报告所有可能的未使用代码
# 100 = 只报告确定未使用的代码
# 推荐从 80% 开始,逐步调高
min-confidence = 80
# 最低置信度 (0-100)
min_confidence = 80
# 输出格式: string, json, yaml
format = text
# 输出格式
# output_format = "text"
# 按置信度排序
sort-by-size = False
# 按大小排序
# sort_by_size = false
# 显示置信度
show-uncertain = True
# 显示不确定的
show_uncertain = true