72f47592a9
CI/CD Pipeline / Dedup Check - skip PR tests when covered by push pipeline (push) Has been cancelled
CI/CD Pipeline / Check if frontend-only change (push) Has been cancelled
CI/CD Pipeline / Validate - Style (push) Has been cancelled
CI/CD Pipeline / Validate - Security (push) Has been cancelled
CI/CD Pipeline / Validate - Python (mypy + alembic) (push) Has been cancelled
CI/CD Pipeline / Unit Tests (push) Has been cancelled
CI/CD Pipeline / Integration Tests (push) Has been cancelled
CI/CD Pipeline / Frontend Lint (push) Has been cancelled
CI/CD Pipeline / Frontend Unit Tests (push) Has been cancelled
CI/CD Pipeline / PR Build API Image (push) Has been cancelled
CI/CD Pipeline / PR Build Web Image (push) Has been cancelled
CI/CD Pipeline / PR Build Worker Image (push) Has been cancelled
CI/CD Pipeline / Check push changed paths (push) Has been cancelled
CI/CD Pipeline / Build Staging API Image (push) Has been cancelled
CI/CD Pipeline / Build Staging Web Image (push) Has been cancelled
CI/CD Pipeline / Build Staging Worker Image (push) Has been cancelled
CI/CD Pipeline / Retag skipped Staging API Image (push) Has been cancelled
CI/CD Pipeline / Retag skipped Staging Web Image (push) Has been cancelled
CI/CD Pipeline / Retag skipped Staging Worker Image (push) Has been cancelled
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (push) Has been cancelled
CI/CD Pipeline / Staging E2E Tests (push) Has been cancelled
CI/CD Pipeline / Staging API Integration Tests (push) Has been cancelled
CI/CD Pipeline / Build Production API Image (push) Has been cancelled
CI/CD Pipeline / Build Production Web Image (push) Has been cancelled
CI/CD Pipeline / Build Production Worker Image (push) Has been cancelled
CI/CD Pipeline / Deploy Production (push) Has been cancelled
CI/CD Pipeline / Production Browser E2E (push) Has been cancelled
CI/CD Pipeline / ACR Image Cleanup (push) Has been cancelled
CI/CD Pipeline / Canary Release to Production (push) Has been cancelled
CI/CD Pipeline / CI Gate (push) Has been cancelled
CI/CD Pipeline / Dedup Check - skip PR tests when covered by push pipeline (pull_request) Has been cancelled
CI/CD Pipeline / Check if frontend-only change (pull_request) Has been cancelled
CI/CD Pipeline / Validate - Style (pull_request) Has been cancelled
CI/CD Pipeline / Validate - Security (pull_request) Has been cancelled
CI/CD Pipeline / Validate - Python (mypy + alembic) (pull_request) Has been cancelled
CI/CD Pipeline / Unit Tests (pull_request) Has been cancelled
CI/CD Pipeline / Integration Tests (pull_request) Has been cancelled
CI/CD Pipeline / Frontend Lint (pull_request) Has been cancelled
CI/CD Pipeline / Frontend Unit Tests (pull_request) Has been cancelled
CI/CD Pipeline / PR Build API Image (pull_request) Has been cancelled
CI/CD Pipeline / PR Build Web Image (pull_request) Has been cancelled
CI/CD Pipeline / PR Build Worker Image (pull_request) Has been cancelled
CI/CD Pipeline / Check push changed paths (pull_request) Has been cancelled
CI/CD Pipeline / Build Staging API Image (pull_request) Has been cancelled
CI/CD Pipeline / Build Staging Web Image (pull_request) Has been cancelled
CI/CD Pipeline / Build Staging Worker Image (pull_request) Has been cancelled
CI/CD Pipeline / Retag skipped Staging API Image (pull_request) Has been cancelled
CI/CD Pipeline / Retag skipped Staging Web Image (pull_request) Has been cancelled
CI/CD Pipeline / Retag skipped Staging Worker Image (pull_request) Has been cancelled
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (pull_request) Has been cancelled
CI/CD Pipeline / Staging E2E Tests (pull_request) Has been cancelled
CI/CD Pipeline / Staging API Integration Tests (pull_request) Has been cancelled
CI/CD Pipeline / Build Production API Image (pull_request) Has been cancelled
CI/CD Pipeline / Build Production Web Image (pull_request) Has been cancelled
CI/CD Pipeline / Build Production Worker Image (pull_request) Has been cancelled
CI/CD Pipeline / Deploy Production (pull_request) Has been cancelled
CI/CD Pipeline / Production Browser E2E (pull_request) Has been cancelled
CI/CD Pipeline / ACR Image Cleanup (pull_request) Has been cancelled
CI/CD Pipeline / Canary Release to Production (pull_request) Has been cancelled
CI/CD Pipeline / CI Gate (pull_request) Has been cancelled
AI Code Review / AI Code Review (pull_request) Has been cancelled
PR Automation / Auto Approve on CI Green (pull_request) Has been cancelled
PR Automation / Auto Merge on CI Green + Approved (pull_request) Has been cancelled
Preview Deploy / Deploy Preview Environment (pull_request) Has been cancelled
ACR Cleanup / ACR Image Cleanup (pull_request_target) Successful in 5m45s
Preview Cleanup / Cleanup Preview Environment (pull_request) Successful in 6m8s
问题:Gitea Actions cache 返回损坏归档时(cache EOF/deserialization failed), pip install pip-audit/detect-secrets/vulture 因 hash mismatch 直接 exit 1, 导致 validate-security/validate-style 整体失败。 修复: - detect-secrets/pip-audit/vulture 安装加 --no-cache-dir - pip-audit 安装失败后 graceful skip(本身是 advisory-only) - detect-secrets 安装失败后重试一次 --no-binary - vulture 安装失败后 skip 死代码检测(本身是 advisory-only)
142 lines
4.4 KiB
Bash
Executable File
142 lines
4.4 KiB
Bash
Executable File
#!/bin/bash
|
||
# CI Validate: 安全扫描(validate-security)
|
||
# 包含:密钥扫描、bandit 安全扫描(仅告警)、pip-audit 依赖漏洞(仅告警)、CI 脚本语法校验
|
||
set -eu
|
||
|
||
echo "=== CI Validate: 安全扫描 ==="
|
||
|
||
# --- 密钥检测 ---
|
||
echo ""
|
||
echo "=== [1/4] Secret detection (detect-secrets) ==="
|
||
python3 -m pip install -q --no-cache-dir detect-secrets || {
|
||
echo "⚠️ detect-secrets install failed, retrying without cache..."
|
||
python3 -m pip install -q --no-cache-dir --no-binary :all: detect-secrets || {
|
||
echo "❌ detect-secrets install failed after retry"
|
||
exit 1
|
||
}
|
||
}
|
||
detect-secrets --version
|
||
|
||
detect-secrets scan \
|
||
--all-files \
|
||
--exclude-files '(^|/)(tests|test|e2e|__tests__|spec|docs|node_modules|site-packages|migrations|alembic|.gitea|.git|.pytest_cache|.next|dist|build)/' \
|
||
--exclude-files '\.(md|rst|txt|lock|example|sample|min\.js|min\.css|spec\.ts|test\.ts|test\.py)$' \
|
||
--exclude-files '(package-lock|yarn\.lock|poetry\.lock|Pipfile\.lock)$' \
|
||
--disable-plugin Base64HighEntropyString \
|
||
--disable-plugin HexHighEntropyString \
|
||
--disable-plugin BasicAuthDetector \
|
||
--disable-plugin KeywordDetector \
|
||
--disable-plugin IPPublicDetector \
|
||
> /tmp/secrets-scan.json 2>&1
|
||
|
||
FOUND=$(python3 -c "
|
||
import json
|
||
try:
|
||
with open('/tmp/secrets-scan.json') as f:
|
||
data = json.load(f)
|
||
results = data.get('results', {})
|
||
total = sum(len(v) for v in results.values())
|
||
print(total)
|
||
except Exception:
|
||
print('error')
|
||
")
|
||
|
||
echo "Secrets detected: $FOUND"
|
||
if [ "$FOUND" != "0" ] && [ "$FOUND" != "error" ]; then
|
||
echo ""
|
||
echo "=== Secret details ==="
|
||
python3 -c "
|
||
import json
|
||
with open('/tmp/secrets-scan.json') as f:
|
||
data = json.load(f)
|
||
for fpath, items in data.get('results', {}).items():
|
||
for item in items:
|
||
line = item.get('line_number', '?')
|
||
stype = item.get('type', '?')
|
||
hashed = item.get('hashed_secret', '')[:16]
|
||
print(f' {fpath}:{line} [{stype}] {hashed}...')
|
||
"
|
||
echo ""
|
||
echo "ERROR: Potential secrets detected in code!"
|
||
exit 1
|
||
fi
|
||
echo "✅ Secret scan passed"
|
||
|
||
# --- Bandit 安全扫描(仅告警)---
|
||
echo ""
|
||
echo "=== [2/4] Security scan (bandit, advisory only) ==="
|
||
set +e
|
||
bandit -r apps packages -q -ll
|
||
BANDIT_EXIT=$?
|
||
set -e
|
||
if [ "$BANDIT_EXIT" -ne 0 ]; then
|
||
echo "⚠️ Bandit found security issues (advisory mode - not blocking CI)"
|
||
else
|
||
echo "✅ Bandit security scan passed"
|
||
fi
|
||
|
||
# --- Pip-audit 依赖漏洞扫描(仅告警)---
|
||
echo ""
|
||
echo "=== [3/4] Python dependency vulnerability scan (pip-audit, advisory only) ==="
|
||
python3 -m pip install -q --no-cache-dir pip-audit || {
|
||
echo "⚠️ pip-audit install failed (cache issue?), retrying..."
|
||
python3 -m pip install -q --no-cache-dir pip-audit || {
|
||
echo "⚠️ pip-audit unavailable, skipping dependency vulnerability scan (advisory)"
|
||
pip-audit --version 2>/dev/null || true
|
||
}
|
||
}
|
||
if command -v pip-audit >/dev/null 2>&1 || python3 -m pip show pip-audit >/dev/null 2>&1; then
|
||
pip-audit --version
|
||
EXIT_CODE=0
|
||
for req_file in requirements.txt requirements-base.txt requirements-dev.txt; do
|
||
if [ -f "$req_file" ]; then
|
||
echo "--- Scanning $req_file ---"
|
||
pip-audit -r "$req_file" --desc on 2>&1 | head -40 || EXIT_CODE=$?
|
||
echo ""
|
||
fi
|
||
done
|
||
echo "pip-audit scan completed (advisory mode - warnings only, not blocking CI)"
|
||
else
|
||
echo "⚠️ pip-audit not available, skipping dependency vulnerability scan (advisory)"
|
||
fi
|
||
|
||
# --- CI脚本语法校验 ---
|
||
echo ""
|
||
echo "=== [4/4] CI & shell scripts syntax validation ==="
|
||
SYNTAX_ERROR=0
|
||
# 检查所有 CI shell 脚本
|
||
for script in scripts/ci/*.sh; do
|
||
if [ -f "$script" ]; then
|
||
if ! bash -n "$script" 2>&1; then
|
||
echo "❌ 语法错误: $script"
|
||
SYNTAX_ERROR=1
|
||
fi
|
||
fi
|
||
done
|
||
# 检查所有 CI Python 脚本语法
|
||
for script in scripts/ci/*.py; do
|
||
if [ -f "$script" ]; then
|
||
if ! python3 -m py_compile "$script" 2>&1; then
|
||
echo "❌ Python语法错误: $script"
|
||
SYNTAX_ERROR=1
|
||
fi
|
||
fi
|
||
done
|
||
# 检查 .gitea/workflows 下的脚本(如果有)
|
||
for script in .gitea/workflows/*.sh; do
|
||
if [ -f "$script" ]; then
|
||
if ! bash -n "$script" 2>&1; then
|
||
echo "❌ 语法错误: $script"
|
||
SYNTAX_ERROR=1
|
||
fi
|
||
fi
|
||
done
|
||
if [ "$SYNTAX_ERROR" -ne 0 ]; then
|
||
echo "❌ CI脚本语法校验失败,见上方错误"
|
||
exit 1
|
||
fi
|
||
echo "✅ All CI scripts syntax OK"
|
||
|
||
echo ""
|
||
echo "=== CI Validate: 安全扫描 全部通过 ✅ ==="
|