Process-agent CI #93
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: PR290 published-digest evidence | |
| on: | |
| workflow_dispatch: | |
| permissions: {} | |
| concurrency: | |
| group: pr290-published-evidence | |
| cancel-in-progress: false | |
| env: | |
| IMAGE: quay.io/stackstate/stackstate-k8s-process-agent | |
| jobs: | |
| published-image-evidence: | |
| name: Published full-image evidence (${{ matrix.arch }}) | |
| runs-on: ${{ matrix.runner }} | |
| permissions: | |
| contents: read | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - arch: amd64 | |
| runner: ubuntu-24.04 | |
| digest: sha256:271e7ac612adc3b89c10aa1bdbc463e4f62d7645c59f3938f27aa2c5500dcc8b | |
| - arch: arm64 | |
| runner: ubuntu-24.04-arm | |
| digest: sha256:c5deb88549c25db1f42568f7d6bed7f6b5ae1bac1b6785540e97425ef48135de | |
| steps: | |
| - name: Check out reviewed source and exceptions | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| ref: fe7d17e97be17d62ac0ae1cf0760826cc6303f43 | |
| persist-credentials: false | |
| - name: Install cosign | |
| uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 | |
| - name: Verify original signed index and runtime membership | |
| env: | |
| ARCH: ${{ matrix.arch }} | |
| PLATFORM_DIGEST: ${{ matrix.digest }} | |
| run: | | |
| set -euo pipefail | |
| mkdir -p reports | |
| index="${IMAGE}@sha256:6635bd08a5fa43b7f5668a838d9a59042f41eb0603264b465067192bd1b0a112" | |
| docker buildx imagetools inspect --raw "${index}" > reports/published-index.json | |
| jq -e --arg arch "${ARCH}" --arg digest "${PLATFORM_DIGEST}" '.manifests[] | select(.platform.architecture == $arch and .platform.os == "linux" and .digest == $digest)' reports/published-index.json > reports/platform-descriptor.json | |
| cosign verify --certificate-oidc-issuer=https://token.actions.githubusercontent.com --certificate-identity=https://github.com/StackVista/stackstate-process-agent/.github/workflows/ci.yml@refs/pull/290/merge "${index}" > reports/index-signature.json 2> reports/index-signature-verification.log | |
| - name: Resolve and inspect published architecture image | |
| id: published | |
| env: | |
| ARCH: ${{ matrix.arch }} | |
| PLATFORM_DIGEST: ${{ matrix.digest }} | |
| run: | | |
| set -euo pipefail | |
| mkdir -p reports | |
| digest="${IMAGE}@${PLATFORM_DIGEST}" | |
| docker pull --platform "linux/${ARCH}" "${digest}" | |
| echo "image=${digest}" >> "${GITHUB_OUTPUT}" | |
| docker image inspect "${digest}" > reports/image-inspect.json | |
| printf '%s\n' "${digest}" > reports/image-digest.txt | |
| test "$(docker image inspect --format '{{.Architecture}}' "${digest}")" = "${ARCH}" | |
| test "$(docker image inspect --format '{{index .Config.Labels "org.opencontainers.image.revision"}}' "${digest}")" = fe7d17e97be17d62ac0ae1cf0760826cc6303f43 | |
| docker run --rm --entrypoint /opt/stackstate-agent/bin/agent/process-agent "${digest}" -version | tee reports/version.txt | |
| grep -F 'Version: fe7d17e9' reports/version.txt | |
| container="$(docker create "${digest}")" | |
| docker cp "${container}:/opt/stackstate-agent/bin/agent/process-agent" /tmp/pr290-process-agent | |
| docker rm "${container}" | |
| sha256sum /tmp/pr290-process-agent > reports/binary-sha256.txt | |
| - name: Scan published digest with current VEX and separate secrets | |
| uses: StackVista/image-pipeline/.github/actions/scan-image@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 | |
| with: | |
| image: ${{ steps.published.outputs.image }} | |
| mode: inform | |
| severity: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL | |
| with-grype: true | |
| exceptions-path: exceptions | |
| upload-sarif: false | |
| sarif-category: pr290-published-${{ matrix.arch }} | |
| - name: Record inventory, consumed VEX, and evaluator output | |
| env: | |
| SCANNED_IMAGE: ${{ steps.published.outputs.image }} | |
| ARCH: ${{ matrix.arch }} | |
| run: | | |
| set -euo pipefail | |
| go version -m /tmp/pr290-process-agent > reports/binary-modules.txt | |
| grep -F 'vcs.revision=fe7d17e97be17d62ac0ae1cf0760826cc6303f43' reports/binary-modules.txt | |
| grep -F 'vcs.modified=false' reports/binary-modules.txt | |
| trivy image --format cyclonedx --output reports/inventory.cdx.json "${SCANNED_IMAGE}" | |
| jq -r '.components[]? | select(.purl // "" | startswith("pkg:rpm/")) | [.name, .version, .purl] | @tsv' reports/inventory.cdx.json | sort > reports/rpm-inventory.txt | |
| test -s reports/rpm-inventory.txt | |
| cp exceptions/GO-2026-5932.yaml reports/GO-2026-5932.yaml | |
| mkdir reports/consumed-vex | |
| while IFS= read -r document; do | |
| if [[ "${document}" == */stackvista/*/pkg/golang/github.com/containerd/containerd/scan.openvex.json ]]; then | |
| cp "${document}" reports/consumed-vex/containerd.openvex.json | |
| fi | |
| done < reports/grype-vex-documents.txt | |
| test -s reports/consumed-vex/containerd.openvex.json | |
| sha256sum reports/consumed-vex/containerd.openvex.json > reports/consumed-vex/SHA256SUMS | |
| image-pipeline-evaluate --image "${SCANNED_IMAGE}" --severity UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL --mode inform --trivy-json reports/trivy.json --grype-json reports/grype.json --exceptions exceptions --sarif reports/image-pipeline.sarif 2>&1 | tee reports/evaluator.txt | |
| jq -n --arg source fe7d17e97be17d62ac0ae1cf0760826cc6303f43 --arg workflow_sha "${GITHUB_SHA}" --arg run "${GITHUB_RUN_ID}" --arg arch "${ARCH}" --arg image "${SCANNED_IMAGE}" '{source:$source,workflow_sha:$workflow_sha,run:$run,arch:$arch,image:$image}' > reports/provenance.json | |
| (cd reports && find . -type f ! -name SHA256SUMS -print0 | sort -z | xargs -0 sha256sum) > reports/SHA256SUMS | |
| - name: Retain published full-image evidence | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a | |
| with: | |
| name: pr290-published-evidence-${{ matrix.arch }} | |
| path: reports/ | |
| retention-days: 90 | |
| if-no-files-found: error |