Files
xiaoxia-saas/docs/ci/first-security-scan-briefing.md
T
xiaoxia cd66aace5b
CI/CD Pipeline / Unit Tests (pull_request) Failing after 16s
CI/CD Pipeline / Frontend Lint (pull_request) Failing after 17s
CI/CD Pipeline / Validate Code Quality And Tests (pull_request) Failing after 2m37s
CI/CD Pipeline / Integration Tests (pull_request) Failing after 25s
CI/CD Pipeline / Production Browser E2E (pull_request) Failing after 1558h38m45s
CI/CD Pipeline / Staging API Integration Tests (pull_request) Failing after 1558h38m45s
CI/CD Pipeline / Staging E2E Tests (pull_request) Failing after 1558h38m45s
CI/CD Pipeline / Build Production Runtime Images (pull_request) Failing after 1558h38m46s
CI/CD Pipeline / Build & Push Staging (Watchtower auto-deploy) (pull_request) Failing after 1558h38m46s
CI/CD Pipeline / Deploy Production (pull_request) Failing after 1559h10m20s
docs(ci): add first security scan briefing report
- Overview of gitleaks, pip-audit, vulture status
- Known issues: new runner stuck, black format failure
- Next steps and action items
2026-07-13 16:39:44 +08:00

4.8 KiB
Raw Blame History

首次安全扫描简报

仓库: xiaoxia/xiaoxia-saas 扫描时间: 2026-07-13 负责人: 代码审计 Agent 状态: CI Runner 环境问题导致扫描结果暂不可用,代码已提交待验证

一、概览

工具 优先级 PR 接入状态 CI 验证 扫描结果
gitleaks(密钥检测) P0 #256 ✅ 代码已提交 ⚠️ Runner 卡住 待验证
pip-audit(Python 依赖漏洞) P1 #256 ✅ 代码已提交 ⚠️ Runner 卡住 待验证
vulture(死代码检测) P2 #259 ✅ 代码已提交 ❌ black 格式失败 待验证

二、各工具详情

1. gitleaks 密钥检测(P0)

接入配置

  • 位置:validate Job 第 3 步(Verify CI environment 之后)
  • PR 模式:增量扫描(--log-opts="origin/base..HEAD"),只扫描改动文件
  • Push 模式:全量扫描
  • 阻断策略:发现密钥直接阻断合并(exit code 1)
  • 白名单:.gitleaks.toml,排除以下路径/内容:
    • .env.example、示例配置文件
    • tests/、docs/、node_modules/、site-packages/
    • 锁定文件(poetry.lock 等)
    • 占位符字符串(your-password、changeme、placeholder 等)

下载问题(已修复)

  • 问题:国内服务器直接访问 GitHub 超时(130s)
  • 修复:增加国内镜像下载源(ghproxy mirror 优先),多源 fallback
  • 修复 commit:fix(ci): add Chinese mirror for gitleaks download

CI 状态

  • Workflow Run #4075,分配到 Runner: xiaoxia-ci-runner-new-2
  • 异常:Job 状态 in_progress 但所有步骤 queued,持续超过 5 分钟
  • 判断:新 CI 服务器 Runner 执行环境问题,非代码配置问题
  • 佐证:同批次 Frontend Lint Job 在 xiaoxia-ci-runner-3 上正常执行完成

2. pip-audit Python 依赖漏洞扫描(P1)

接入配置

  • 位置:validate Job 第 5 步(Install dependencies 之后)
  • 扫描范围:requirements.txt、requirements-base.txt、requirements-dev.txt、requirements-worker.txt
  • 数据源:OSV(PyPA 官方推荐)
  • 阻断策略:告警模式,不阻断 CI
  • 计划:运行 1-2 周摸清漏洞存量后,按严重等级设置阻断阈值

CI 状态

  • 同 PR #256,因 Runner 卡住暂未执行

3. vulture 死代码检测(P2)

接入配置

  • 位置:validate Job,Run security scan (bandit) 之后
  • 置信度阈值:80%
  • 扫描范围:alembic/、apps/、packages/、scripts/
  • 排除:测试文件、迁移文件、文档、node_modules、site-packages
  • 白名单:框架自动调用代码
    • FastAPI routes / dependencies / middleware
    • SQLAlchemy models / Pydantic schemas
    • Celery tasks
    • Alembic migration functions
    • CLI scripts / 工具函数
  • 阻断策略:告警模式,不阻断 CI

CI 状态

  • Workflow Run #4054
  • 失败原因:scripts/check_migration_safety.py 不符合 black 格式
    would reformat scripts/check_migration_safety.py
    1 file would be reformatted, 376 files would be left unchanged.
    
  • 说明:非 vulture 引入的问题(vulture 步骤还没执行到),是其他 Agent 修改了迁移安全检查脚本但没跑 black 格式化
  • 建议:后端开发 Agent 在迁移安全 PR 中同步修复 black 格式问题

三、发现的其他 CI 问题

Runner 环境问题

  1. 新服务器 Runner 卡住:xiaoxia-ci-runner-new-2 上的 Job 一直停留在 queued 状态,无法执行步骤
  2. Unit Tests 快速失败:Unit Tests Job 18 秒就失败了,可能是环境/依赖问题,非代码问题
  3. Integration Tests 快速失败:24 秒失败,同样可能是环境问题

代码质量预存问题

  1. scripts/check_migration_safety.py 不符合 black 格式(可能是后端开发刚改动过)

四、下一步计划

  1. 等待 Runner 环境修复:新服务器 Runner 执行环境问题修复后,重新触发 PR #256 CI
  2. 修复 black 格式问题:确认 vulture PR #259 中的 black 格式问题由后端开发在迁移安全 PR 中修复
  3. 收集首次扫描数据:CI 跑通后,整理 gitleaks / pip-audit / vulture 的首次扫描结果
  4. 根据结果调优白名单:如有误报,及时更新 .gitleaks.toml 和 vulture_whitelist.py
  5. 推进 npm audit:前端开发完成 PR #255 后接入 npm audit

五、相关文档