WP-20/21: vulnerability management with Trivy and mail notifications
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled

Trivy scanner adapter (rootfs + image JSON, parsed and deduplicated),
findings repository, scan diff that keeps first_seen, marks disappeared
findings fixed and skips failed targets, vulnerability_scan job (daily by
default), digest mail for new findings at or above a configurable severity,
/api/vulnerabilities routes, Vulnerabilities page with severity tiles,
filters, details and acknowledge, notification threshold in settings.
Deploy script installs Trivy from the Aqua apt repository.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-02 22:45:57 +02:00
parent 5c6e09ad10
commit 872f4373ff
13 changed files with 801 additions and 94 deletions

View File

@ -41,6 +41,14 @@ fi
# add settings introduced later to an existing .env
ssh "$HOST" "grep -q '^MASTER_KEY=' $DIR/.env || echo MASTER_KEY=$(openssl rand -hex 32) >> $DIR/.env"
echo "== trivy (vulnerability scanner)"
ssh "$HOST" 'command -v trivy >/dev/null || {
apt-get install -y -q wget apt-transport-https gnupg >/dev/null
wget -qO- https://aquasecurity.github.io/trivy-repo/deb/public.key | gpg --dearmor -o /usr/share/keyrings/trivy.gpg
echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" > /etc/apt/sources.list.d/trivy.list
apt-get update -q >/dev/null && apt-get install -y -q trivy >/dev/null
}; trivy --version | head -1'
echo "== systemd"
ssh "$HOST" "cat > /etc/systemd/system/monitoring.service" <<UNIT
[Unit]