Repository navigation
Replace Snyk scans with Trivy - #557
Open
pvannierop wants to merge 4 commits into
Open
pvannierop wants to merge 4 commits into
pvannierop wants to merge 4 commits into
Conversation
- trivy.yaml: PR gate on fixable HIGH/CRITICAL findings (was snyk.yaml with --severity-threshold=high --fail-on=upgradable), plus a job summary with all findings - scheduled-trivy.yaml: weekly code base scan, SARIF to Code scanning - scheduled-trivy-docker.yaml: weekly base image scan (OS packages, like Snyk's --exclude-app-vulns), SARIF to Code scanning - .github/trivy-lock.init.gradle: locks runtimeClasspath, so Trivy can read the Gradle dependencies - .trivyignore.yaml: empty ignore list (Trivy 0.74 needs the file to exist) - Remove .snyk. Its ignores were only meant to quiet Snyk until this move, so they are not carried over and Trivy reports those findings. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Locking only needs the dependency graph, not the files. Resolving files fails in multi-module Android builds (radar-commons-android), and the lock script is kept the same in every RADAR-base repo. On this build the lockfile is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Ignore 7 HIGH findings until 2027-04-05, with the reason per entry: certifi and urllib3 1.26.x in the appserver-legacy migration script (fixed only in urllib3 2.x / current certifi; not part of the image). The remaining findings are fixed by the security PR into dev.
The branch filter was copied from the Snyk workflow, which listed main, but this repo's default branch is master. Release PRs into master weren't scanned.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces the Snyk GitHub Actions scans with Trivy, as part of the move away from Snyk across RADAR-base.
snyk.yaml: PR gate,--severity-threshold=high --fail-on=upgradabletrivy.yaml: PR gate on fixable HIGH/CRITICAL findings (--severity HIGH,CRITICAL --ignore-unfixed), plus a job summary that lists every finding at every severityscheduled-snyk.yaml: weekly scan, SARIF uploadscheduled-trivy.yaml: weekly scan of all severities, SARIF to Code scanning (categorytrivy-dependencies)scheduled-snyk-docker.yamlscheduled-trivy-docker.yaml: weekly base image scan (--pkg-types os).snyk.trivyignore.yaml(no entries; the file must exist for Trivy 0.74)Gradle dependencies are visible to Trivy only through lockfiles, so the workflows first lock
runtimeClasspathwith.github/trivy-lock.init.gradle, the same classpath the Snyk gate scanned (--configuration-matching="^runtimeClasspath$"). Build tooling and test dependencies don't fail the gate. Actions are pinned by commit SHA and Trivy to v0.74.0.Snyk ignores are not carried over: they were added to quiet Snyk until this move, so Trivy reports those findings.
Local dry run on
dev(Trivy 0.74.0): all: {'HIGH': 65, 'MEDIUM': 84, 'CRITICAL': 11, 'LOW': 8}, gate (fixable HIGH/CRITICAL): {'HIGH': 65, 'CRITICAL': 11}.Merge this after the security PR #556: until then
devstill has the old dependency versions, so this PR's own Trivy check is expected to fail.Follow-ups for maintainers: if branch protection or a ruleset requires the Snyk
securitycheck, the Trivy job keeps that name. The scheduled workflows only run from the default branch, so they start once this is released. Old Snyk alerts in Code scanning can be closed in bulk (tool:Snyk), and Snyk's own GitHub integration and theSNYK_TOKENsecret can be removed once no repo uses them.🤖 Generated with Claude Code