-
-
Notifications
You must be signed in to change notification settings - Fork 174
feat(hooks): CI annotations and SARIF upload for scanner findings #2631
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Andriy Knysh (aknysh)
merged 38 commits into
main
from
osterman/scanner-ci-annotations-results
Jun 24, 2026
Merged
Changes from all commits
Commits
Show all changes
38 commits
Select commit
Hold shift + click to select a range
9be79d9
feat(hooks): surface scanner findings in CI job summary + fix Checkov…
osterman 77297c1
docs(roadmap): link scanner CI-summary milestone to PR #2617
osterman 0cc205b
docs(roadmap): classify Infracost as a cost tool, not a security scanner
osterman c18ea52
feat(hooks): native CI annotations + SARIF Code Scanning upload for s…
osterman f6e8f16
docs(roadmap): link scanner CI annotations/results milestone to PR #2631
osterman 32f8e60
docs(hooks): clarify GitHub Advanced Security is a paid GitHub add-on…
osterman 5db20e8
chore: update ci annotations and actions
osterman 86197e6
test: add native CI e2e fixture
osterman 0e894b6
feat(hooks): surface scanner findings in CI job summary + fix Checkov…
osterman 693683f
docs(roadmap): link scanner CI-summary milestone to PR #2617
osterman 39cbc31
docs(roadmap): classify Infracost as a cost tool, not a security scanner
osterman 2ab39f7
feat(hooks): native CI annotations + SARIF Code Scanning upload for s…
osterman 0094e45
docs(roadmap): link scanner CI annotations/results milestone to PR #2631
osterman e256f7d
docs(hooks): clarify GitHub Advanced Security is a paid GitHub add-on…
osterman 35a0d04
chore: update ci annotations and actions
osterman cd2c067
test: add native CI e2e fixture
osterman 73cb30a
Normalize AWS auth endpoint config
osterman e1d6502
Merge branch 'osterman/scanner-ci-annotations-results' of https://git…
osterman 72b942a
Fix screengrab build command list
osterman 9e68d71
Fix CI annotations and validation failures
osterman 3adfafd
Update quick-start acceptance snapshots
osterman 9748333
Normalize SARIF paths for scanner hooks
osterman 975b7ed
Fix native scanner CI annotations
osterman 069b688
Scope scanner SARIF category to tool name and event-scoped preflight
osterman 4cc5c41
Scope Native CI to scanner-related path changes
osterman ab68a24
Reduce native CI scanner findings to one per scanner
osterman c6988ff
Fix doubled SARIF paths for workdir-relative scanner output
osterman fcc017f
Fix native CI apply by keeping scanner targets Floci-applyable
osterman 9c195ff
Exclude no-color.org from link check (CI timeouts)
osterman c77e335
Test scanner inline-ignore directives in native CI fixture
osterman 9bbd482
Route KMS to Floci in native CI fixture provider config
osterman da4dabd
Merge remote-tracking branch 'origin/main' into osterman/scanner-ci-a…
osterman a037a43
Merge remote-tracking branch 'origin/main' into osterman/scanner-ci-a…
osterman 603b36e
fix: address code-review findings on scanner CI branch
osterman 9d4a07a
test(ci): cover CI-reporting helpers to clear 80% patch gate
osterman 4c8f5a4
Merge remote-tracking branch 'origin/main' into osterman/scanner-ci-a…
osterman d261c78
Merge remote-tracking branch 'origin/main' into osterman/scanner-ci-a…
osterman 4798f81
Merge branch 'main' into osterman/scanner-ci-annotations-results
aknysh File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,169 @@ | ||
| name: Native CI | ||
|
|
||
| on: | ||
| pull_request: | ||
| types: [opened, synchronize, reopened] | ||
| # Only run when something this E2E actually exercises changes, so unrelated | ||
| # PRs aren't spammed with scanner SARIF/code-scanning annotations. | ||
| paths: | ||
| # The E2E fixture + its validation test-case. | ||
| - "tests/fixtures/scenarios/native-ci-e2e/**" | ||
| - "tests/test-cases/native-ci-e2e.yaml" | ||
| # The workflow itself. | ||
| - ".github/workflows/native-ci.yml" | ||
| # The feature this E2E exercises, so scanner/CI source changes still run it. | ||
| - "pkg/ci/**" | ||
| - "pkg/hooks/**" | ||
| - "actions/cache/**" | ||
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| contents: read | ||
| pull-requests: write | ||
| security-events: write | ||
| statuses: write | ||
|
|
||
| env: | ||
| ATMOS_NATIVE_CI_WORKDIR: tests/fixtures/scenarios/native-ci-e2e | ||
| ATMOS_VERSION_CHECK_ENABLED: "false" | ||
| NATIVE_CI_TRIVY_VERSION: "0.70.0" | ||
| NATIVE_CI_KICS_VERSION: "2.1.20" | ||
|
|
||
| jobs: | ||
| terraform-plan: | ||
| name: "[native ci] terraform plan" | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 20 | ||
|
|
||
| services: | ||
| floci: | ||
| image: floci/floci@sha256:c88ec20bf221630dd195d38a14eeb0ac52ddfa72c37ebb3c8aa17f63ae27c5f2 # 1.5.23 | ||
| ports: | ||
| - 4566:4566 | ||
|
|
||
| steps: | ||
| - name: Check out code | ||
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | ||
| with: | ||
| persist-credentials: false | ||
|
|
||
| - name: Set up Go | ||
| uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6 | ||
| with: | ||
| go-version-file: "go.mod" | ||
|
|
||
| - name: Build Atmos | ||
| run: | | ||
| make build-linux | ||
| echo "${{ github.workspace }}/build" >> "$GITHUB_PATH" | ||
|
|
||
| - name: Restore Atmos native CI cache | ||
| uses: ./actions/cache | ||
| env: | ||
| ATMOS_CHDIR: ${{ env.ATMOS_NATIVE_CI_WORKDIR }} | ||
|
|
||
| - name: Validate native CI fixture | ||
| working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }} | ||
| run: atmos validate stacks | ||
|
|
||
| - name: Mirror Terraform providers | ||
| working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }} | ||
| run: atmos terraform cache mirror bucket -s test --platform=linux_amd64 --format=json | ||
|
|
||
| - name: Install scanner tools for native CI fixture | ||
| run: | | ||
| scanner_bin="$RUNNER_TEMP/native-ci-scanners/bin" | ||
| scanner_assets="$RUNNER_TEMP/native-ci-scanners/assets" | ||
| mkdir -p "$scanner_bin" "$scanner_assets" | ||
|
|
||
| # Download and verify the Trivy binary against its published checksum | ||
| # before extracting, so a tampered or corrupted archive never executes. | ||
| curl -fsSL \ | ||
| -o "$RUNNER_TEMP/trivy.tar.gz" \ | ||
| "https://github.com/aquasecurity/trivy/releases/download/v${NATIVE_CI_TRIVY_VERSION}/trivy_${NATIVE_CI_TRIVY_VERSION}_Linux-64bit.tar.gz" | ||
| curl -fsSL \ | ||
| -o "$RUNNER_TEMP/trivy_checksums.txt" \ | ||
| "https://github.com/aquasecurity/trivy/releases/download/v${NATIVE_CI_TRIVY_VERSION}/trivy_${NATIVE_CI_TRIVY_VERSION}_checksums.txt" | ||
| trivy_sha="$(grep " trivy_${NATIVE_CI_TRIVY_VERSION}_Linux-64bit.tar.gz$" "$RUNNER_TEMP/trivy_checksums.txt" | awk '{print $1}')" | ||
| echo "${trivy_sha} $RUNNER_TEMP/trivy.tar.gz" | sha256sum -c - | ||
| tar -xzf "$RUNNER_TEMP/trivy.tar.gz" -C "$scanner_bin" trivy | ||
|
|
||
| # Download and verify the KICS binary against its published checksum | ||
| # before extracting. | ||
| curl -fsSL \ | ||
| -o "$RUNNER_TEMP/kics.tar.gz" \ | ||
| "https://github.com/Checkmarx/kics/releases/download/v${NATIVE_CI_KICS_VERSION}/kics_${NATIVE_CI_KICS_VERSION}_linux_amd64.tar.gz" | ||
| curl -fsSL \ | ||
| -o "$RUNNER_TEMP/kics_checksums.txt" \ | ||
| "https://github.com/Checkmarx/kics/releases/download/v${NATIVE_CI_KICS_VERSION}/checksums.txt" | ||
| kics_sha="$(grep " kics_${NATIVE_CI_KICS_VERSION}_linux_amd64.tar.gz$" "$RUNNER_TEMP/kics_checksums.txt" | awk '{print $1}')" | ||
| echo "${kics_sha} $RUNNER_TEMP/kics.tar.gz" | sha256sum -c - | ||
| tar -xzf "$RUNNER_TEMP/kics.tar.gz" -C "$scanner_bin" kics | ||
|
|
||
| # The KICS query assets (extracted-info.zip) have no published checksum, | ||
| # so they cannot be verified the same way. They are data, not an executable. | ||
| curl -fsSL \ | ||
| -o "$RUNNER_TEMP/kics-extracted-info.zip" \ | ||
| "https://github.com/Checkmarx/kics/releases/download/v${NATIVE_CI_KICS_VERSION}/extracted-info.zip" | ||
| unzip -q "$RUNNER_TEMP/kics-extracted-info.zip" -d "$scanner_assets/kics" | ||
|
|
||
| chmod +x "$scanner_bin/trivy" "$scanner_bin/kics" | ||
| echo "$scanner_bin" >> "$GITHUB_PATH" | ||
| echo "KICS_QUERIES_PATH=$scanner_assets/kics/assets/queries" >> "$GITHUB_ENV" | ||
|
|
||
| - name: Terraform plan | ||
| id: terraform-plan | ||
| working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }} | ||
| env: | ||
| ATMOS_CI_GITHUB_TOKEN: ${{ github.token }} | ||
| GITHUB_TOKEN: ${{ github.token }} | ||
| run: atmos terraform plan bucket -s test | ||
|
|
||
| terraform-apply: | ||
| name: "[native ci] terraform apply" | ||
| needs: terraform-plan | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 20 | ||
|
|
||
| services: | ||
| floci: | ||
| image: floci/floci@sha256:c88ec20bf221630dd195d38a14eeb0ac52ddfa72c37ebb3c8aa17f63ae27c5f2 # 1.5.23 | ||
| ports: | ||
| - 4566:4566 | ||
|
|
||
| steps: | ||
| - name: Check out code | ||
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | ||
| with: | ||
| persist-credentials: false | ||
|
|
||
| - name: Set up Go | ||
| uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6 | ||
| with: | ||
| go-version-file: "go.mod" | ||
|
|
||
| - name: Build Atmos | ||
| run: | | ||
| make build-linux | ||
| echo "${{ github.workspace }}/build" >> "$GITHUB_PATH" | ||
|
|
||
| - name: Restore Atmos native CI cache | ||
| uses: ./actions/cache | ||
| env: | ||
| ATMOS_CHDIR: ${{ env.ATMOS_NATIVE_CI_WORKDIR }} | ||
|
|
||
| - name: Validate native CI fixture | ||
| working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }} | ||
| run: atmos validate stacks | ||
|
|
||
| - name: Mirror Terraform providers | ||
| working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }} | ||
| run: atmos terraform cache mirror bucket -s test --platform=linux_amd64 --format=json | ||
|
|
||
| - name: Terraform apply | ||
| id: terraform-apply | ||
| working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }} | ||
| env: | ||
| ATMOS_CI_GITHUB_TOKEN: ${{ github.token }} | ||
| GITHUB_TOKEN: ${{ github.token }} | ||
| run: atmos terraform apply bucket -s test -auto-approve |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.