ci(P2-7): 增加Trivy镜像安全扫描(高危漏洞检测,仅告警不阻断)
This commit is contained in:
@@ -765,6 +765,24 @@ jobs:
|
||||
chmod +x scripts/build_release_images.sh
|
||||
REGISTRY_TOKEN="${REGISTRY_TOKEN}" scripts/build_release_images.sh "${GITHUB_REF_NAME}"
|
||||
|
||||
- name: Trivy image security scan
|
||||
continue-on-error: true
|
||||
shell: sh
|
||||
run: |
|
||||
set +e
|
||||
echo "=== Running Trivy security scan on production images ==="
|
||||
IMAGE_TAG="${GITHUB_REF_NAME}"
|
||||
REGISTRY="git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas"
|
||||
|
||||
# 扫描 API 镜像(只报告 CRITICAL 和 HIGH 级别漏洞)
|
||||
for svc in api worker web; do
|
||||
echo ""
|
||||
echo "--- Scanning xiaoxia-saas-${svc}:${IMAGE_TAG} ---"
|
||||
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock -v trivy-cache:/root/.cache/ aquasec/trivy:latest image --severity CRITICAL,HIGH --ignore-unfixed --format table "xiaoxia-saas-${svc}:${IMAGE_TAG}" 2>&1 | tail -30
|
||||
done
|
||||
echo ""
|
||||
echo "=== Trivy scan complete (advisory only, does not block deploy) ==="
|
||||
|
||||
- name: Cleanup old Docker images
|
||||
if: always()
|
||||
shell: sh
|
||||
|
||||
Reference in New Issue
Block a user