Skip to content

Process-agent CI

Process-agent CI #93

Workflow file for this run

name: PR290 published-digest evidence
on:
workflow_dispatch:
permissions: {}
concurrency:
group: pr290-published-evidence
cancel-in-progress: false
env:
IMAGE: quay.io/stackstate/stackstate-k8s-process-agent
jobs:
published-image-evidence:
name: Published full-image evidence (${{ matrix.arch }})
runs-on: ${{ matrix.runner }}
permissions:
contents: read
strategy:
fail-fast: false
matrix:
include:
- arch: amd64
runner: ubuntu-24.04
digest: sha256:271e7ac612adc3b89c10aa1bdbc463e4f62d7645c59f3938f27aa2c5500dcc8b
- arch: arm64
runner: ubuntu-24.04-arm
digest: sha256:c5deb88549c25db1f42568f7d6bed7f6b5ae1bac1b6785540e97425ef48135de
steps:
- name: Check out reviewed source and exceptions
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
with:
ref: fe7d17e97be17d62ac0ae1cf0760826cc6303f43
persist-credentials: false
- name: Install cosign
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6
- name: Verify original signed index and runtime membership
env:
ARCH: ${{ matrix.arch }}
PLATFORM_DIGEST: ${{ matrix.digest }}
run: |
set -euo pipefail
mkdir -p reports
index="${IMAGE}@sha256:6635bd08a5fa43b7f5668a838d9a59042f41eb0603264b465067192bd1b0a112"
docker buildx imagetools inspect --raw "${index}" > reports/published-index.json
jq -e --arg arch "${ARCH}" --arg digest "${PLATFORM_DIGEST}" '.manifests[] | select(.platform.architecture == $arch and .platform.os == "linux" and .digest == $digest)' reports/published-index.json > reports/platform-descriptor.json
cosign verify --certificate-oidc-issuer=https://token.actions.githubusercontent.com --certificate-identity=https://github.com/StackVista/stackstate-process-agent/.github/workflows/ci.yml@refs/pull/290/merge "${index}" > reports/index-signature.json 2> reports/index-signature-verification.log
- name: Resolve and inspect published architecture image
id: published
env:
ARCH: ${{ matrix.arch }}
PLATFORM_DIGEST: ${{ matrix.digest }}
run: |
set -euo pipefail
mkdir -p reports
digest="${IMAGE}@${PLATFORM_DIGEST}"
docker pull --platform "linux/${ARCH}" "${digest}"
echo "image=${digest}" >> "${GITHUB_OUTPUT}"
docker image inspect "${digest}" > reports/image-inspect.json
printf '%s\n' "${digest}" > reports/image-digest.txt
test "$(docker image inspect --format '{{.Architecture}}' "${digest}")" = "${ARCH}"
test "$(docker image inspect --format '{{index .Config.Labels "org.opencontainers.image.revision"}}' "${digest}")" = fe7d17e97be17d62ac0ae1cf0760826cc6303f43
docker run --rm --entrypoint /opt/stackstate-agent/bin/agent/process-agent "${digest}" -version | tee reports/version.txt
grep -F 'Version: fe7d17e9' reports/version.txt
container="$(docker create "${digest}")"
docker cp "${container}:/opt/stackstate-agent/bin/agent/process-agent" /tmp/pr290-process-agent
docker rm "${container}"
sha256sum /tmp/pr290-process-agent > reports/binary-sha256.txt
- name: Scan published digest with current VEX and separate secrets
uses: StackVista/image-pipeline/.github/actions/scan-image@6284a6fc006a7cc46a7f00d02c50d5f21b117b63
with:
image: ${{ steps.published.outputs.image }}
mode: inform
severity: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL
with-grype: true
exceptions-path: exceptions
upload-sarif: false
sarif-category: pr290-published-${{ matrix.arch }}
- name: Record inventory, consumed VEX, and evaluator output
env:
SCANNED_IMAGE: ${{ steps.published.outputs.image }}
ARCH: ${{ matrix.arch }}
run: |
set -euo pipefail
go version -m /tmp/pr290-process-agent > reports/binary-modules.txt
grep -F 'vcs.revision=fe7d17e97be17d62ac0ae1cf0760826cc6303f43' reports/binary-modules.txt
grep -F 'vcs.modified=false' reports/binary-modules.txt
trivy image --format cyclonedx --output reports/inventory.cdx.json "${SCANNED_IMAGE}"
jq -r '.components[]? | select(.purl // "" | startswith("pkg:rpm/")) | [.name, .version, .purl] | @tsv' reports/inventory.cdx.json | sort > reports/rpm-inventory.txt
test -s reports/rpm-inventory.txt
cp exceptions/GO-2026-5932.yaml reports/GO-2026-5932.yaml
mkdir reports/consumed-vex
while IFS= read -r document; do
if [[ "${document}" == */stackvista/*/pkg/golang/github.com/containerd/containerd/scan.openvex.json ]]; then
cp "${document}" reports/consumed-vex/containerd.openvex.json
fi
done < reports/grype-vex-documents.txt
test -s reports/consumed-vex/containerd.openvex.json
sha256sum reports/consumed-vex/containerd.openvex.json > reports/consumed-vex/SHA256SUMS
image-pipeline-evaluate --image "${SCANNED_IMAGE}" --severity UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL --mode inform --trivy-json reports/trivy.json --grype-json reports/grype.json --exceptions exceptions --sarif reports/image-pipeline.sarif 2>&1 | tee reports/evaluator.txt
jq -n --arg source fe7d17e97be17d62ac0ae1cf0760826cc6303f43 --arg workflow_sha "${GITHUB_SHA}" --arg run "${GITHUB_RUN_ID}" --arg arch "${ARCH}" --arg image "${SCANNED_IMAGE}" '{source:$source,workflow_sha:$workflow_sha,run:$run,arch:$arch,image:$image}' > reports/provenance.json
(cd reports && find . -type f ! -name SHA256SUMS -print0 | sort -z | xargs -0 sha256sum) > reports/SHA256SUMS
- name: Retain published full-image evidence
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: pr290-published-evidence-${{ matrix.arch }}
path: reports/
retention-days: 90
if-no-files-found: error