Skip to content

Commit 48725c5

Browse files
authored
ci(release): move CodeQL, Trivy, and Zizmor to advisory (#3693)
* ci(release): Move CodeQL, Trivy, and Zizmor to advisory * docs(ci): describe advisory static findings for tagged releases Signed-off-by: Jim Meyer <jimeyer@nvidia.com> --------- Signed-off-by: Jim Meyer <jimeyer@nvidia.com>
1 parent 0854871 commit 48725c5

3 files changed

Lines changed: 12 additions & 7 deletions

File tree

‎.github/workflows/release-tag.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -142,7 +142,7 @@ jobs:
142142
with:
143143
candidate_ref: ${{ inputs.tag || github.ref_name }}
144144
fail-on-codex-findings: true
145-
fail-on-static-findings: true
145+
fail-on-static-findings: false
146146
images: |
147147
ghcr.io/nvidia/openshell/gateway:${{ needs.compute-versions.outputs.source_sha }}
148148
ghcr.io/nvidia/openshell/sandbox:${{ needs.compute-versions.outputs.source_sha }}

‎CI.md‎

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -103,10 +103,13 @@ Actions or call it from another workflow. All applicable children analyze the
103103
candidate snapshot. Cargo Deny uses its existing NVIDIA self-hosted runner and
104104
CI container.
105105

106-
Tagged releases treat CodeQL, Trivy, Zizmor, Cargo Deny, and Codex Security
107-
findings as failures of the currently implemented qualification profile. A
108-
profile failure does not prevent a pre-release candidate's complete artifact
109-
set from being published, but it does prevent stable publication.
106+
Tagged releases treat Cargo Deny and Codex Security findings as failures of the
107+
currently implemented qualification profile. A profile failure does not prevent
108+
a pre-release candidate's complete artifact set from being published, but it
109+
does prevent stable publication. CodeQL, Trivy, and Zizmor findings are
110+
temporarily informational for tagged releases: the existing findings were
111+
reviewed and accepted for v0.1.0 and will be addressed in 0.1.x releases.
112+
Scanner failures still fail qualification.
110113

111114
```shell
112115
gh workflow run security-scan.yml --ref main \

‎architecture/build.md‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -536,8 +536,10 @@ RFC's complete qualification coverage.
536536
The tagged release workflow calls the aggregate Security Scan after publishing
537537
the candidate's commit-addressed gateway, sandbox, and supervisor images. CodeQL,
538538
Trivy, Cargo Deny, and Actionlint/Zizmor run for every release tag; Codex Security
539-
also runs for pre-release tags. High or Critical findings and scanner failures
540-
fail qualification.
539+
also runs for pre-release tags. Scanner failures, Cargo Deny advisories, and
540+
High or Critical Codex Security findings fail qualification. CodeQL, Trivy, and
541+
Zizmor findings are temporarily informational while the findings accepted for
542+
v0.1.0 are addressed in 0.1.x releases.
541543

542544
The `Release Qualification` job aggregates security, conformance, feature,
543545
Docker E2E, and VM E2E results. The currently implemented profile gates stable

0 commit comments

Comments
 (0)