WP-20/21: vulnerability management with Trivy and mail notifications
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled

Trivy scanner adapter (rootfs + image JSON, parsed and deduplicated),
findings repository, scan diff that keeps first_seen, marks disappeared
findings fixed and skips failed targets, vulnerability_scan job (daily by
default), digest mail for new findings at or above a configurable severity,
/api/vulnerabilities routes, Vulnerabilities page with severity tiles,
filters, details and acknowledge, notification threshold in settings.
Deploy script installs Trivy from the Aqua apt repository.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-02 22:45:57 +02:00
parent 5c6e09ad10
commit 872f4373ff
13 changed files with 801 additions and 94 deletions

View File

@ -196,12 +196,13 @@ async fn new_findings_at_or_above_threshold_trigger_one_mail() {
]),
)]);
svc.scan(&VecLog::default()).await.unwrap();
let sent = f.mailer.0.lock().unwrap();
assert_eq!(sent.len(), 1);
assert!(sent[0].1.contains("1 new"), "{}", sent[0].1);
assert!(sent[0].2.contains("CVE-3"));
assert!(!sent[0].2.contains("CVE-4"), "below threshold");
drop(sent);
{
let sent = f.mailer.0.lock().unwrap();
assert_eq!(sent.len(), 1);
assert!(sent[0].1.contains("1 new"), "{}", sent[0].1);
assert!(sent[0].2.contains("CVE-3"));
assert!(!sent[0].2.contains("CVE-4"), "below threshold");
}
f.settings
.set_notify_min_severity(Severity::Low)