mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-20 23:32:19 +00:00
feat(images): Trivy-powered vulnerability scanning (#635)
* feat(images): Trivy-powered vulnerability scanning Scan container images for known CVEs via Trivy. On-demand scanning and severity badges are available on every tier; scheduled scans, scan policies, SBOM generation, and scan history are gated to Skipper+. - New TrivyService (binary detection, per-image scan, SBOM, digest cache) - Three new tables: vulnerability_scans, vulnerability_details, scan_policies - 12 routes under /api/security (scan, results, summaries, SBOM, policies, compare) - Post-deploy async scans wired into all five deploy paths, with a per-deploy opt-out toggle in the App Store deploy sheet - "scan" action type added to SchedulerService for fleet-wide recurring scans - Frontend: severity badges in Resources Hub with animated cursor detail, scan results drawer with vulnerability table and filters, and a new Security section in Settings for scan policy CRUD - Policy threshold violations dispatch a warning or critical alert based on the policy's block_on_deploy flag; deploys themselves are never blocked * fix(security): compute scan age in useEffect to satisfy react-hooks/purity
This commit is contained in:
@@ -51,6 +51,10 @@ Every self-hosted instance includes the full security stack, with advanced featu
|
||||
Long-lived JWT bearer tokens, encrypted at rest, injected automatically during proxied requests.
|
||||
</Card>
|
||||
|
||||
<Card title="Vulnerability scanning" icon="shield-virus" href="/features/vulnerability-scanning">
|
||||
Trivy-powered CVE scanning of container images, with severity badges, post-deploy automation, and policy gating.
|
||||
</Card>
|
||||
|
||||
</CardGroup>
|
||||
|
||||
## Tier availability
|
||||
@@ -66,7 +70,9 @@ Every Sencho instance includes the foundational security stack. Advanced access-
|
||||
| Encryption at rest (AES-256-GCM) | ✓ | ✓ | ✓ |
|
||||
| Rate limiting (auth + API) | ✓ | ✓ | ✓ |
|
||||
| Node-to-node authentication | ✓ | ✓ | ✓ |
|
||||
| Vulnerability scanning (on-demand + post-deploy) | ✓ | ✓ | ✓ |
|
||||
| Multi-user with RBAC (Admin, Viewer) | | ✓ | ✓ |
|
||||
| Scan policies, scheduled scans, SBOM generation | | ✓ | ✓ |
|
||||
| Advanced RBAC (Deployer, Node Admin, Auditor) | | | ✓ |
|
||||
| Scoped permissions (per-stack, per-node) | | | ✓ |
|
||||
| API tokens (scoped, expiring) | | | ✓ |
|
||||
|
||||
Reference in New Issue
Block a user