fix(ci): 修复三个安全扫描的问题
CI/CD Pipeline / Production Browser E2E (pull_request) Failing after 1535h56m3s
CI/CD Pipeline / Deploy Production (pull_request) Failing after 1535h56m4s
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (pull_request) Failing after 1535h56m4s
CI/CD Pipeline / Staging API Integration Tests (pull_request) Failing after 1535h56m4s
CI/CD Pipeline / Build Production API Image (pull_request) Failing after 1535h56m6s
CI/CD Pipeline / Build Staging Web Image (pull_request) Failing after 1535h56m6s
CI/CD Pipeline / Build Production Web Image (pull_request) Failing after 1535h56m5s
CI/CD Pipeline / Build Staging Worker Image (pull_request) Failing after 1535h56m6s
CI/CD Pipeline / Build Staging API Image (pull_request) Failing after 1535h56m7s
CI/CD Pipeline / Validate Code Quality And Tests (pull_request) Has been skipped
CI/CD Pipeline / Unit Tests (pull_request) Has been skipped
CI/CD Pipeline / Integration Tests (pull_request) Has been skipped
CI/CD Pipeline / Frontend Lint (pull_request) Has been skipped
CI/CD Pipeline / Build Production Worker Image (pull_request) Failing after 1536h27m44s
CI/CD Pipeline / Staging E2E Tests (pull_request) Failing after 1536h27m42s
CI/CD Pipeline / Production Browser E2E (pull_request) Failing after 1535h56m3s
CI/CD Pipeline / Deploy Production (pull_request) Failing after 1535h56m4s
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (pull_request) Failing after 1535h56m4s
CI/CD Pipeline / Staging API Integration Tests (pull_request) Failing after 1535h56m4s
CI/CD Pipeline / Build Production API Image (pull_request) Failing after 1535h56m6s
CI/CD Pipeline / Build Staging Web Image (pull_request) Failing after 1535h56m6s
CI/CD Pipeline / Build Production Web Image (pull_request) Failing after 1535h56m5s
CI/CD Pipeline / Build Staging Worker Image (pull_request) Failing after 1535h56m6s
CI/CD Pipeline / Build Staging API Image (pull_request) Failing after 1535h56m7s
CI/CD Pipeline / Validate Code Quality And Tests (pull_request) Has been skipped
CI/CD Pipeline / Unit Tests (pull_request) Has been skipped
CI/CD Pipeline / Integration Tests (pull_request) Has been skipped
CI/CD Pipeline / Frontend Lint (pull_request) Has been skipped
CI/CD Pipeline / Build Production Worker Image (pull_request) Failing after 1536h27m44s
CI/CD Pipeline / Staging E2E Tests (pull_request) Failing after 1536h27m42s
- gitleaks: 增加ghproxy镜像源,解决下载失败问题 - pip-audit: 去掉--format text(不支持),用默认columns格式 - vulture: 改用命令行参数,移除有问题的toml配置文件和白名单文件
This commit is contained in:
+22
-10
@@ -107,20 +107,30 @@ jobs:
|
||||
set -eu
|
||||
echo "=== Installing gitleaks ==="
|
||||
GITLEAKS_VERSION="8.18.4"
|
||||
GITLEAKS_FILE="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"
|
||||
install_gitleaks() {
|
||||
local url="$1"
|
||||
curl -sSL -f -o /tmp/gitleaks.tar.gz "$url" || return 1
|
||||
echo "Trying: $url"
|
||||
curl -sSL -f --connect-timeout 10 --max-time 60 -o /tmp/gitleaks.tar.gz "$url" || return 1
|
||||
tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks || return 1
|
||||
chmod +x /tmp/gitleaks || return 1
|
||||
/tmp/gitleaks version || return 1
|
||||
return 0
|
||||
}
|
||||
if ! install_gitleaks "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"; then
|
||||
echo "GitHub release failed, trying mirror..."
|
||||
if ! install_gitleaks "https://gitee.com/mirrors/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"; then
|
||||
echo "WARN: Failed to install gitleaks from all sources, skipping secret scan"
|
||||
exit 0
|
||||
GITLEAKS_INSTALLED=false
|
||||
for mirror_url in \
|
||||
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}" \
|
||||
"https://ghproxy.com/https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}" \
|
||||
"https://mirror.ghproxy.com/https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}" \
|
||||
"https://gitee.com/mirrors/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}"; do
|
||||
if install_gitleaks "$mirror_url"; then
|
||||
GITLEAKS_INSTALLED=true
|
||||
break
|
||||
fi
|
||||
done
|
||||
if [ "$GITLEAKS_INSTALLED" = "false" ]; then
|
||||
echo "WARN: Failed to install gitleaks from all sources, skipping secret scan"
|
||||
exit 0
|
||||
fi
|
||||
echo ""
|
||||
echo "=== Running gitleaks scan ==="
|
||||
@@ -173,7 +183,7 @@ jobs:
|
||||
for req_file in requirements.txt requirements-base.txt requirements-dev.txt; do
|
||||
if [ -f "$req_file" ]; then
|
||||
echo "--- Scanning $req_file ---"
|
||||
pip-audit -r "$req_file" --desc on --format text 2>&1 | head -30 || EXIT_CODE=$?
|
||||
pip-audit -r "$req_file" --desc on 2>&1 | head -40 || EXIT_CODE=$?
|
||||
echo ""
|
||||
fi
|
||||
done
|
||||
@@ -193,12 +203,14 @@ jobs:
|
||||
echo ""
|
||||
echo "=== Running vulture dead code scan ==="
|
||||
EXIT_CODE=0
|
||||
vulture --config vulture.conf vulture_whitelist.py || EXIT_CODE=$?
|
||||
vulture apps packages scripts \
|
||||
--exclude "tests,test,migrations,.gitea,docs,node_modules,site-packages,*/test_*.py,*/conftest.py" \
|
||||
--min-confidence 80 \
|
||||
2>&1 | head -60 || EXIT_CODE=$?
|
||||
echo ""
|
||||
echo "vulture scan completed (advisory mode - P2, for reference only)"
|
||||
if [ "$EXIT_CODE" != "0" ]; then
|
||||
echo "NOTE: Potential dead code found. Review results above."
|
||||
echo "False positives can be added to vulture_whitelist.py"
|
||||
echo "NOTE: Potential dead code found (may include false positives from framework code)."
|
||||
fi
|
||||
exit 0
|
||||
|
||||
|
||||
+22
-27
@@ -1,35 +1,30 @@
|
||||
# vulture.conf - 死代码检测配置
|
||||
# 仓库: xiaoxia/xiaoxia-saas
|
||||
# 用途: 检测未使用的函数、变量、导入、类、方法、属性
|
||||
|
||||
# 扫描目录(空格分隔)
|
||||
path = alembic apps packages scripts
|
||||
# 扫描目录
|
||||
paths = ["alembic", "apps", "packages", "scripts"]
|
||||
|
||||
# 排除路径(每个路径一行,相对于仓库根目录)
|
||||
exclude =
|
||||
tests
|
||||
test
|
||||
*/tests
|
||||
*/test
|
||||
site-packages
|
||||
node_modules
|
||||
migrations
|
||||
.gitea
|
||||
docs
|
||||
scripts/check_*.py
|
||||
scripts/init_*.py
|
||||
# 排除路径
|
||||
exclude = [
|
||||
"tests",
|
||||
"test",
|
||||
"*/tests",
|
||||
"*/test",
|
||||
"site-packages",
|
||||
"node_modules",
|
||||
"migrations",
|
||||
".gitea",
|
||||
"docs",
|
||||
]
|
||||
|
||||
# 最低置信度 (%)
|
||||
# 0 = 报告所有可能的未使用代码
|
||||
# 100 = 只报告确定未使用的代码
|
||||
# 推荐从 80% 开始,逐步调高
|
||||
min-confidence = 80
|
||||
# 最低置信度 (0-100)
|
||||
min_confidence = 80
|
||||
|
||||
# 输出格式: string, json, yaml
|
||||
format = text
|
||||
# 输出格式
|
||||
# output_format = "text"
|
||||
|
||||
# 按置信度排序
|
||||
sort-by-size = False
|
||||
# 按大小排序
|
||||
# sort_by_size = false
|
||||
|
||||
# 显示置信度
|
||||
show-uncertain = True
|
||||
# 显示不确定的
|
||||
show_uncertain = true
|
||||
|
||||
Reference in New Issue
Block a user