From cd66aace5b35e8f7754007640bed33c84ae45147 Mon Sep 17 00:00:00 2001 From: xiaoxia Date: Mon, 13 Jul 2026 16:39:44 +0800 Subject: [PATCH] docs(ci): add first security scan briefing report - Overview of gitleaks, pip-audit, vulture status - Known issues: new runner stuck, black format failure - Next steps and action items --- docs/ci/first-security-scan-briefing.md | 103 ++++++++++++++++++++++++ 1 file changed, 103 insertions(+) create mode 100644 docs/ci/first-security-scan-briefing.md diff --git a/docs/ci/first-security-scan-briefing.md b/docs/ci/first-security-scan-briefing.md new file mode 100644 index 000000000..9d39dce4f --- /dev/null +++ b/docs/ci/first-security-scan-briefing.md @@ -0,0 +1,103 @@ +# 首次安全扫描简报 + +> 仓库: xiaoxia/xiaoxia-saas +> 扫描时间: 2026-07-13 +> 负责人: 代码审计 Agent +> 状态: CI Runner 环境问题导致扫描结果暂不可用,代码已提交待验证 + +## 一、概览 + +| 工具 | 优先级 | PR | 接入状态 | CI 验证 | 扫描结果 | +|---|---|---|---|---|---| +| gitleaks(密钥检测) | P0 | [#256](https://git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas/pulls/256) | ✅ 代码已提交 | ⚠️ Runner 卡住 | 待验证 | +| pip-audit(Python 依赖漏洞) | P1 | [#256](https://git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas/pulls/256) | ✅ 代码已提交 | ⚠️ Runner 卡住 | 待验证 | +| vulture(死代码检测) | P2 | [#259](https://git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas/pulls/259) | ✅ 代码已提交 | ❌ black 格式失败 | 待验证 | + +## 二、各工具详情 + +### 1. gitleaks 密钥检测(P0) + +**接入配置** +- 位置:validate Job 第 3 步(Verify CI environment 之后) +- PR 模式:增量扫描(`--log-opts="origin/base..HEAD"`),只扫描改动文件 +- Push 模式:全量扫描 +- 阻断策略:发现密钥直接阻断合并(exit code 1) +- 白名单:`.gitleaks.toml`,排除以下路径/内容: + - `.env.example`、示例配置文件 + - `tests/`、`docs/`、`node_modules/`、`site-packages/` + - 锁定文件(poetry.lock 等) + - 占位符字符串(`your-password`、`changeme`、`placeholder` 等) + +**下载问题(已修复)** +- 问题:国内服务器直接访问 GitHub 超时(130s) +- 修复:增加国内镜像下载源(ghproxy mirror 优先),多源 fallback +- 修复 commit:`fix(ci): add Chinese mirror for gitleaks download` + +**CI 状态** +- Workflow Run #4075,分配到 Runner: `xiaoxia-ci-runner-new-2` +- 异常:Job 状态 `in_progress` 但所有步骤 `queued`,持续超过 5 分钟 +- 判断:新 CI 服务器 Runner 执行环境问题,非代码配置问题 +- 佐证:同批次 Frontend Lint Job 在 `xiaoxia-ci-runner-3` 上正常执行完成 + +### 2. pip-audit Python 依赖漏洞扫描(P1) + +**接入配置** +- 位置:validate Job 第 5 步(Install dependencies 之后) +- 扫描范围:`requirements.txt`、`requirements-base.txt`、`requirements-dev.txt`、`requirements-worker.txt` +- 数据源:OSV(PyPA 官方推荐) +- 阻断策略:告警模式,不阻断 CI +- 计划:运行 1-2 周摸清漏洞存量后,按严重等级设置阻断阈值 + +**CI 状态** +- 同 PR #256,因 Runner 卡住暂未执行 + +### 3. vulture 死代码检测(P2) + +**接入配置** +- 位置:validate Job,Run security scan (bandit) 之后 +- 置信度阈值:80% +- 扫描范围:`alembic/`、`apps/`、`packages/`、`scripts/` +- 排除:测试文件、迁移文件、文档、node_modules、site-packages +- 白名单:框架自动调用代码 + - FastAPI routes / dependencies / middleware + - SQLAlchemy models / Pydantic schemas + - Celery tasks + - Alembic migration functions + - CLI scripts / 工具函数 +- 阻断策略:告警模式,不阻断 CI + +**CI 状态** +- Workflow Run #4054 +- 失败原因:`scripts/check_migration_safety.py` 不符合 black 格式 + ``` + would reformat scripts/check_migration_safety.py + 1 file would be reformatted, 376 files would be left unchanged. + ``` +- 说明:非 vulture 引入的问题(vulture 步骤还没执行到),是其他 Agent 修改了迁移安全检查脚本但没跑 black 格式化 +- 建议:后端开发 Agent 在迁移安全 PR 中同步修复 black 格式问题 + +## 三、发现的其他 CI 问题 + +### Runner 环境问题 +1. **新服务器 Runner 卡住**:`xiaoxia-ci-runner-new-2` 上的 Job 一直停留在 queued 状态,无法执行步骤 +2. **Unit Tests 快速失败**:Unit Tests Job 18 秒就失败了,可能是环境/依赖问题,非代码问题 +3. **Integration Tests 快速失败**:24 秒失败,同样可能是环境问题 + +### 代码质量预存问题 +1. `scripts/check_migration_safety.py` 不符合 black 格式(可能是后端开发刚改动过) + +## 四、下一步计划 + +1. **等待 Runner 环境修复**:新服务器 Runner 执行环境问题修复后,重新触发 PR #256 CI +2. **修复 black 格式问题**:确认 vulture PR #259 中的 black 格式问题由后端开发在迁移安全 PR 中修复 +3. **收集首次扫描数据**:CI 跑通后,整理 gitleaks / pip-audit / vulture 的首次扫描结果 +4. **根据结果调优白名单**:如有误报,及时更新 `.gitleaks.toml` 和 `vulture_whitelist.py` +5. **推进 npm audit**:前端开发完成 PR #255 后接入 npm audit + +## 五、相关文档 + +- [安全工具接入方案](docs/ci/代码安全扫描CI集成方案_report.md) +- [安全工具路线图](docs/ci/security-scanning-roadmap.md) +- [gitleaks 白名单配置](../.gitleaks.toml) +- [vulture 配置](../vulture.conf) +- [vulture 白名单](../vulture_whitelist.py)