WP-20/21: vulnerability management with Trivy and mail notifications
Trivy scanner adapter (rootfs + image JSON, parsed and deduplicated), findings repository, scan diff that keeps first_seen, marks disappeared findings fixed and skips failed targets, vulnerability_scan job (daily by default), digest mail for new findings at or above a configurable severity, /api/vulnerabilities routes, Vulnerabilities page with severity tiles, filters, details and acknowledge, notification threshold in settings. Deploy script installs Trivy from the Aqua apt repository. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
@ -295,8 +295,8 @@ if not, the listed assumptions apply.
|
||||
### Milestone 2 – Update management (delivered 2026-09-02)
|
||||
WP-02 remainder, WP-10, WP-11, WP-12. Verified against the real host: 430 packages, microk8s overview with 16 workloads.
|
||||
|
||||
### Milestone 3 – Vulnerability management (planned)
|
||||
WP-20, WP-21.
|
||||
### Milestone 3 – Vulnerability management (delivered 2026-09-02)
|
||||
WP-20, WP-21. Trivy is installed by the deploy script.
|
||||
|
||||
### Milestone 4 – Backup management (planned)
|
||||
WP-30, WP-31, WP-32.
|
||||
@ -358,8 +358,8 @@ The server is reachable via `ssh softvisor` (as root). Findings from the inspect
|
||||
| WP-10 | M2 | done | 2026-09-02; snaps inventoried, no upstream check |
|
||||
| WP-11 | M2 | done | 2026-09-02; runs as root via systemd, sudoers scoping deferred to WP-41; log via polling |
|
||||
| WP-12 | M2 | done | 2026-09-02; overview, restart, scale, set image; upstream tag check not done |
|
||||
| WP-20 | M3 | todo | |
|
||||
| WP-21 | M3 | todo | |
|
||||
| WP-20 | M3 | done | 2026-09-02; Trivy rootfs + image scans, diff with first/last seen, fixed detection |
|
||||
| WP-21 | M3 | done | 2026-09-02; findings UI, acknowledge, mail digest with severity threshold; dashboard widget in WP-40 |
|
||||
| WP-30 | M4 | todo | |
|
||||
| WP-31 | M4 | todo | |
|
||||
| WP-32 | M4 | todo | |
|
||||
|
||||
Reference in New Issue
Block a user