WP-20/21: vulnerability management with Trivy and mail notifications
Trivy scanner adapter (rootfs + image JSON, parsed and deduplicated), findings repository, scan diff that keeps first_seen, marks disappeared findings fixed and skips failed targets, vulnerability_scan job (daily by default), digest mail for new findings at or above a configurable severity, /api/vulnerabilities routes, Vulnerabilities page with severity tiles, filters, details and acknowledge, notification threshold in settings. Deploy script installs Trivy from the Aqua apt repository. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
@ -41,6 +41,14 @@ fi
|
||||
# add settings introduced later to an existing .env
|
||||
ssh "$HOST" "grep -q '^MASTER_KEY=' $DIR/.env || echo MASTER_KEY=$(openssl rand -hex 32) >> $DIR/.env"
|
||||
|
||||
echo "== trivy (vulnerability scanner)"
|
||||
ssh "$HOST" 'command -v trivy >/dev/null || {
|
||||
apt-get install -y -q wget apt-transport-https gnupg >/dev/null
|
||||
wget -qO- https://aquasecurity.github.io/trivy-repo/deb/public.key | gpg --dearmor -o /usr/share/keyrings/trivy.gpg
|
||||
echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" > /etc/apt/sources.list.d/trivy.list
|
||||
apt-get update -q >/dev/null && apt-get install -y -q trivy >/dev/null
|
||||
}; trivy --version | head -1'
|
||||
|
||||
echo "== systemd"
|
||||
ssh "$HOST" "cat > /etc/systemd/system/monitoring.service" <<UNIT
|
||||
[Unit]
|
||||
|
||||
Reference in New Issue
Block a user