Skip to content

feat: reduce noise from vulnerability scanning - #1440

Draft
Ron (rjaegers) wants to merge 2 commits into
mainfrom
feature/reduce-vulnerability-noise
Draft

feat: reduce noise from vulnerability scanning#1440
Ron (rjaegers) wants to merge 2 commits into
mainfrom
feature/reduce-vulnerability-noise

Conversation

@rjaegers

Copy link
Copy Markdown
Member

🚀 Hey, I have created a Pull Request

Description of changes

This pull request introduces a comprehensive noise-reduction strategy for vulnerability scanning, aiming to ensure that only actionable and relevant findings are surfaced to maintainers. The changes filter out vulnerabilities with no available fixes and kernel-package CVEs that cannot be exploited in containers, and document this approach for transparency and future review. Both Trivy scanners (in CI and MegaLinter) are updated to apply these filters consistently.

Vulnerability scanning noise reduction:

  • Added a Rego policy (.github/linters/kernel-findings.rego) to suppress all findings for packages whose names start with linux-, as kernel packages cannot be exploited inside containers.
  • Updated .github/workflows/vulnerability-scan.yml to:
    • Use ignore_unfixed: true to suppress vulnerabilities without upstream fixes.
    • Apply the new Rego policy via the TRIVY_IGNORE_POLICY environment variable.
    • Refactored the build matrix to specify the correct Dockerfile for each flavor, and improved permissions for security and clarity.

MegaLinter configuration:

  • Updated .mega-linter.yml to pass both --ignore-unfixed and the new Rego policy to Trivy, ensuring consistent filtering in repository scans.

Documentation:

  • Added an Architecture Decision Record (docs/adr/0001-vulnerability-scanning-noise-reduction.md) detailing the rationale, implementation, and implications of the noise-reduction approach for vulnerability scanning.

✔️ Checklist

  • I have followed the contribution guidelines for this repository
  • I have added tests for new behavior, and have not broken any existing tests
  • I have added or updated relevant documentation
  • I have verified that all added components are accounted for in the SBOM
  • I understand the image size delta and agree the functionality justifies it

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-base:edgeghcr.io/philips-software/amp-devcontainer-base:pr-1440

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 90.43 MB 90.43 MB +332 B (+0%) 🔼
linux/arm64 88.39 MB 88.4 MB +1.14 kB (+0%) 🔼

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 23 0 0 0.3s
✅ DOCKERFILE hadolint 4 0 0 0.36s
✅ JSON npm-package-json-lint yes no no 0.53s
✅ JSON prettier 46 8 0 0 0.85s
✅ JSON v8r 46 0 0 13.0s
⚠️ MARKDOWN markdownlint 14 0 3 0 1.08s
✅ MARKDOWN markdown-table-formatter 14 0 0 0 0.24s
✅ REPOSITORY betterleaks yes no no 1.12s
✅ REPOSITORY checkov yes no no 21.56s
✅ REPOSITORY git_diff yes no no 0.02s
✅ REPOSITORY grype yes no no 76.02s
⚠️ REPOSITORY osv-scanner yes 2 no 1.62s
✅ REPOSITORY secretlint yes no no 2.87s
✅ REPOSITORY syft yes no no 6.24s
✅ REPOSITORY trivy yes no no 11.23s
✅ REPOSITORY trivy-sbom yes no no 0.36s
✅ REPOSITORY trufflehog yes no no 3.68s
⚠️ SPELL lychee 119 2 0 11.67s
✅ YAML prettier 36 0 0 0 1.84s
✅ YAML v8r 36 0 0 10.41s
✅ YAML yamllint 36 0 0 1.07s

Detailed Issues

⚠️ SPELL / lychee - 2 errors
📝 Summary
---------------------
🔍 Total..........160
🔗 Unique.........132
✅ Successful.....153
⏳ Timeouts.........0
🔀 Redirected......21
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........2
⛔ Unsupported......2

Errors in .github/CONTRIBUTING.md
[ERROR] https://www.conventionalcommits.org/en/v1.0.0/ (at 89:64) | Connection failed. Check network connectivity and firewall settings

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden

Hint: Followed 21 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ MARKDOWN / markdownlint - 3 errors
docs/adr/0001-vulnerability-scanning-noise-reduction.md:9:401 error MD013/line-length Line length [Expected: 400; Actual: 450]
docs/adr/0001-vulnerability-scanning-noise-reduction.md:36:401 error MD013/line-length Line length [Expected: 400; Actual: 540]
docs/adr/0001-vulnerability-scanning-noise-reduction.md:38:401 error MD013/line-length Line length [Expected: 400; Actual: 423]
⚠️ REPOSITORY / osv-scanner - 2 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned .devcontainer/docs/requirements.txt file and found 14 packages
Scanned package-lock.json file and found 73 packages
Scanned test/embedded-rust/workspace/cortex-mf/Cargo.lock file and found 20 packages
Scanned test/embedded-rust/workspace/cortex-m/Cargo.lock file and found 20 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned .github/actions/update-vscode-extensions/package-lock.json file and found 288 packages
End status: 83 dirs visited, 282 inodes visited, 9 Extract calls, 45.069982ms elapsed, 45.070223ms wall time

Total 3 packages affected by 4 known vulnerabilities (0 Critical, 2 High, 0 Medium, 0 Low, 2 Unknown) from 2 ecosystems.
2 vulnerabilities can be fixed.

+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| OSV URL                             | CVSS | ECOSYSTEM | PACKAGE               | VERSION | FIXED VERSION | SOURCE                                            |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| https://osv.dev/RUSTSEC-2026-0110   |      | crates.io | bare-metal            | 0.2.5   | --            | test/embedded-rust/workspace/cortex-m/Cargo.lock  |
| https://osv.dev/RUSTSEC-2026-0110   |      | crates.io | bare-metal            | 0.2.5   | --            | test/embedded-rust/workspace/cortex-mf/Cargo.lock |
| https://osv.dev/GHSA-mh99-v99m-4gvg | 7.5  | npm       | brace-expansion (dev) | 5.0.7   | 5.0.8         | package-lock.json                                 |
| https://osv.dev/GHSA-rgw5-rvv9-x895 | 7.5  | npm       | brace-expansion (dev) | 5.0.7   | 5.0.9         | package-lock.json                                 |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+

See detailed reports in MegaLinter artifacts

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-rust:edgeghcr.io/philips-software/amp-devcontainer-rust:pr-1440

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 446.34 MB 446.34 MB +37 B (+0%) 🔼
linux/arm64 396.26 MB 396.26 MB +947 B (+0%) 🔼

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-docs:edgeghcr.io/philips-software/amp-devcontainer-docs:pr-1440

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 221.96 MB 221.96 MB 54 B (0%) 🔽
linux/arm64 218.08 MB 218.08 MB +771 B (+0%) 🔼

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-rust:edgeghcr.io/philips-software/amp-devcontainer-embedded-rust:pr-1440

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 513.08 MB 513.08 MB 154 B (0%) 🔽
linux/arm64 462.66 MB 462.66 MB +862 B (+0%) 🔼

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-cpp:edgeghcr.io/philips-software/amp-devcontainer-cpp:pr-1440

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 410.63 MB 410.63 MB +2.35 kB (+0%) 🔼
linux/arm64 391.06 MB 391.07 MB +1.73 kB (+0%) 🔼

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-cpp:edgeghcr.io/philips-software/amp-devcontainer-embedded-cpp:pr-1440

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 612.84 MB 612.84 MB +650 B (+0%) 🔼
linux/arm64 592.51 MB 592.51 MB 1.26 kB (0%) 🔽

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Test Results

 25 files  ± 0   26 suites  +1   19m 6s ⏱️ -57s
 49 tests + 1   48 ✅ ± 0  0 💤 ±0  1 ❌ +1 
188 runs   - 21  187 ✅  - 22  0 💤 ±0  1 ❌ +1 

For more details on these failures, see this check.

Results for commit c8c8312. ± Comparison against base commit 4ef16b6.

♻️ This comment has been updated with latest results.

Signed-off-by: Ron <45816308+rjaegers@users.noreply.github.com>
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant