From bf2649e445042e374ffeb2436e870b492d1ac38a Mon Sep 17 00:00:00 2001 From: xiaoxia Date: Thu, 9 Jul 2026 13:58:58 +0800 Subject: [PATCH] =?UTF-8?q?ci(P2-7):=20=E5=A2=9E=E5=8A=A0Trivy=E9=95=9C?= =?UTF-8?q?=E5=83=8F=E5=AE=89=E5=85=A8=E6=89=AB=E6=8F=8F=EF=BC=88=E9=AB=98?= =?UTF-8?q?=E5=8D=B1=E6=BC=8F=E6=B4=9E=E6=A3=80=E6=B5=8B=EF=BC=8C=E4=BB=85?= =?UTF-8?q?=E5=91=8A=E8=AD=A6=E4=B8=8D=E9=98=BB=E6=96=AD=EF=BC=89?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .gitea/workflows/ci-cd.yml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/.gitea/workflows/ci-cd.yml b/.gitea/workflows/ci-cd.yml index ca6251575..97ae9a987 100755 --- a/.gitea/workflows/ci-cd.yml +++ b/.gitea/workflows/ci-cd.yml @@ -765,6 +765,24 @@ jobs: chmod +x scripts/build_release_images.sh REGISTRY_TOKEN="${REGISTRY_TOKEN}" scripts/build_release_images.sh "${GITHUB_REF_NAME}" + - name: Trivy image security scan + continue-on-error: true + shell: sh + run: | + set +e + echo "=== Running Trivy security scan on production images ===" + IMAGE_TAG="${GITHUB_REF_NAME}" + REGISTRY="git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas" + + # 扫描 API 镜像(只报告 CRITICAL 和 HIGH 级别漏洞) + for svc in api worker web; do + echo "" + echo "--- Scanning xiaoxia-saas-${svc}:${IMAGE_TAG} ---" + docker run --rm -v /var/run/docker.sock:/var/run/docker.sock -v trivy-cache:/root/.cache/ aquasec/trivy:latest image --severity CRITICAL,HIGH --ignore-unfixed --format table "xiaoxia-saas-${svc}:${IMAGE_TAG}" 2>&1 | tail -30 + done + echo "" + echo "=== Trivy scan complete (advisory only, does not block deploy) ===" + - name: Cleanup old Docker images if: always() shell: sh