Commit Graph

2 Commits

Author SHA1 Message Date
Anso c9cd6990d2 feat(images): Trivy-powered vulnerability scanning (#635)
* feat(images): Trivy-powered vulnerability scanning

Scan container images for known CVEs via Trivy. On-demand scanning and
severity badges are available on every tier; scheduled scans, scan
policies, SBOM generation, and scan history are gated to Skipper+.

- New TrivyService (binary detection, per-image scan, SBOM, digest cache)
- Three new tables: vulnerability_scans, vulnerability_details, scan_policies
- 12 routes under /api/security (scan, results, summaries, SBOM, policies, compare)
- Post-deploy async scans wired into all five deploy paths, with a
  per-deploy opt-out toggle in the App Store deploy sheet
- "scan" action type added to SchedulerService for fleet-wide recurring scans
- Frontend: severity badges in Resources Hub with animated cursor detail,
  scan results drawer with vulnerability table and filters, and a new
  Security section in Settings for scan policy CRUD
- Policy threshold violations dispatch a warning or critical alert based on
  the policy's block_on_deploy flag; deploys themselves are never blocked

* fix(security): compute scan age in useEffect to satisfy react-hooks/purity
2026-04-16 15:03:36 -04:00
Anso 4c5aa73196 docs: add security architecture overview page (#634)
Add docs/security.mdx with the full auth stack as the lead section:
password auth, SSO (5 providers + generic OIDC), TOTP MFA, JWT sessions,
API tokens, RBAC (5 roles), audit logging, AES-256-GCM encryption,
rate limiting, and node-to-node authentication.

Includes tier availability matrix, permission matrix, production
hardening checklist, and vulnerability reporting section. Links to
dedicated feature pages for configuration details.

Add navigation entry in docs.json Reference group.
2026-04-16 09:01:15 -04:00