From 005682e9c34fc3d0ad54472b7aae52b641c38f1b Mon Sep 17 00:00:00 2001 From: Jakub Stejskal Date: Tue, 6 Oct 2026 10:32:51 +0200 Subject: [PATCH 1/8] Add weekly CVE reporting workflow Signed-off-by: Jakub Stejskal --- .github/workflows/cve-notifier.yml | 55 ++++++++++++++ configs/cve-notifier-projects.yaml | 114 +++++++++++++++++++++++++++++ 2 files changed, 169 insertions(+) create mode 100644 .github/workflows/cve-notifier.yml create mode 100644 configs/cve-notifier-projects.yaml diff --git a/.github/workflows/cve-notifier.yml b/.github/workflows/cve-notifier.yml new file mode 100644 index 0000000..ead3dbe --- /dev/null +++ b/.github/workflows/cve-notifier.yml @@ -0,0 +1,55 @@ +name: CVE Notifier + +on: + schedule: + # Every Monday at 08:00 UTC + - cron: "0 8 * * 1" + # Allow manual trigger for on-demand triggers or debug + workflow_dispatch: {} + +permissions: + contents: read + +jobs: + cve-notifier: + name: Run CVE Notifier + runs-on: ubuntu-latest + timeout-minutes: 30 + steps: + - name: Checkout github-actions + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + + - name: Checkout strimzi/cve-notifier + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + repository: strimzi/cve-notifier + ref: 467245e343da0a30a32578a4cbeb0fe0451dc94e + path: cve-notifier + + - name: Copy projects.yaml config + run: cp configs/cve-notifier-projects.yaml cve-notifier/config/projects.yaml + + - name: Set up Python + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 + with: + python-version: "3.11" + + - name: Install Poetry + run: pip install poetry + + - name: Install dependencies + working-directory: cve-notifier + run: poetry install --only main + + - name: Run CVE Notifier + working-directory: cve-notifier + run: | + poetry run security-report run \ + --config config/projects.yaml \ + --output-dir ./output \ + --refresh \ + --send-slack \ + --slack-channel "${{ secrets.SLACK_WEBHOOK_URL }}" + env: + SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} + FOSSA_API_KEY: ${{ secrets.FOSSA_API_KEY }} diff --git a/configs/cve-notifier-projects.yaml b/configs/cve-notifier-projects.yaml new file mode 100644 index 0000000..0f447c5 --- /dev/null +++ b/configs/cve-notifier-projects.yaml @@ -0,0 +1,114 @@ +schemaVersion: 2 + +report: + windowDays: 7 + containerArchitecture: amd64 + +providers: + fossa: + # Strimzi team id + team: "46084" + +repositories: + + strimzi-kafka-operator: + github: strimzi/strimzi-kafka-operator + projectName: strimzi-kafka-operator + containers: + images: + - name: strimzi/operator + component: cluster-operator + fossaProject: operator + - name: strimzi/kafka + component: kafka + fossaProject: kafka + - name: strimzi/maven-builder + component: maven-builder + fossaProject: maven-builder + - name: strimzi/buildah + component: buildah + fossaProject: buildah + + snyk: + mavenGroupIds: + - io.strimzi + targetGroups: + - id: main + displayName: "main / latest" + mavenRef: main + containerRef: latest + - id: release-1.3 + displayName: "1.3.x / 1.3.0" + mavenRef: release-1.3.x + containerRef: 1.3.0 + + fossa: + mavenProject: custom+162/operators + targetGroups: + - id: main + displayName: "main / latest" + mavenRef: main + containerRef: latest + - id: release-1.3 + displayName: "1.3.x / 1.3.0" + mavenRef: release-1.3.x + containerRef: 1.3.0 + + strimzi-kafka-bridge: + github: strimzi/strimzi-kafka-bridge + projectName: strimzi-kafka-bridge + containers: + images: + - name: strimzi/kafka-bridge + component: kafka-bridge + fossaProject: kafka-bridge-container + snyk: + mavenProjects: + - io.strimzi:kafka-bridge + targetGroups: + - id: main + displayName: "main / latest" + mavenRef: main + containerRef: latest + - id: release-1.2 + displayName: "1.2.x / 1.2.0" + mavenRef: release-1.2.x + containerRef: 1.2.0 + + fossa: + mavenProject: custom+162/kafka-bridge + targetGroups: + - id: main + displayName: "main / latest" + mavenRef: main + containerRef: latest + - id: release-1.2 + displayName: "1.2.x / 1.2.0" + mavenRef: release-1.2.x + containerRef: 1.2.0 + fossaBranch: 1.2.0 + + drain-cleaner: + github: strimzi/drain-cleaner + projectName: drain-cleaner + containers: + images: + - name: strimzi/drain-cleaner + component: drain-cleaner + fossaProject: drain-cleaner-container + snyk: + mavenProjects: + - io.strimzi:strimzi-drain-cleaner + targetGroups: + - id: main + displayName: "main / latest" + mavenRef: main + containerRef: latest + + fossa: + mavenProject: custom+162/drain-cleaner + targetGroups: + - id: main + displayName: "main / latest" + mavenRef: main + containerRef: latest From c50a6afcbac7799c75f8ae3df6515f34ec6a3543 Mon Sep 17 00:00:00 2001 From: Jakub Stejskal Date: Tue, 6 Oct 2026 11:16:26 +0200 Subject: [PATCH 2/8] Fix repo path Signed-off-by: Jakub Stejskal --- .github/workflows/cve-notifier.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/cve-notifier.yml b/.github/workflows/cve-notifier.yml index ead3dbe..e7cf113 100644 --- a/.github/workflows/cve-notifier.yml +++ b/.github/workflows/cve-notifier.yml @@ -19,10 +19,12 @@ jobs: - name: Checkout github-actions uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Checkout strimzi/cve-notifier + # Checkout CVE notifier tool + # It is expected to checkout it from frawless user + - name: Checkout frawless/cve-notifier uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - repository: strimzi/cve-notifier + repository: frawless/cve-notifier ref: 467245e343da0a30a32578a4cbeb0fe0451dc94e path: cve-notifier From 46300f7432f83a3ac607df80915f8f4f3056b588 Mon Sep 17 00:00:00 2001 From: Jakub Stejskal Date: Tue, 6 Oct 2026 11:22:13 +0200 Subject: [PATCH 3/8] Change ref Signed-off-by: Jakub Stejskal --- .github/workflows/cve-notifier.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/cve-notifier.yml b/.github/workflows/cve-notifier.yml index e7cf113..afb96c5 100644 --- a/.github/workflows/cve-notifier.yml +++ b/.github/workflows/cve-notifier.yml @@ -25,7 +25,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: frawless/cve-notifier - ref: 467245e343da0a30a32578a4cbeb0fe0451dc94e + ref: 467245e1eb8cbfb6aee22619cb05c95a79a839e1 path: cve-notifier - name: Copy projects.yaml config From 21bf18355adde376f97d8252249cc9997a278416 Mon Sep 17 00:00:00 2001 From: Jakub Stejskal Date: Tue, 6 Oct 2026 11:30:48 +0200 Subject: [PATCH 4/8] Set SNYK_ORG_ID Signed-off-by: Jakub Stejskal --- .github/workflows/cve-notifier.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/cve-notifier.yml b/.github/workflows/cve-notifier.yml index afb96c5..f99ac42 100644 --- a/.github/workflows/cve-notifier.yml +++ b/.github/workflows/cve-notifier.yml @@ -55,3 +55,4 @@ jobs: env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} FOSSA_API_KEY: ${{ secrets.FOSSA_API_KEY }} + SNYK_ORG_ID: ${{ secrets.SNYK_ORG_ID }} From 4793f3eb7379801284caea72b646cb914f20e5b0 Mon Sep 17 00:00:00 2001 From: Jakub Stejskal Date: Tue, 6 Oct 2026 11:51:46 +0200 Subject: [PATCH 5/8] Add snyk and fossa options Signed-off-by: Jakub Stejskal --- .github/workflows/cve-notifier.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/cve-notifier.yml b/.github/workflows/cve-notifier.yml index f99ac42..789dcb3 100644 --- a/.github/workflows/cve-notifier.yml +++ b/.github/workflows/cve-notifier.yml @@ -50,6 +50,8 @@ jobs: --config config/projects.yaml \ --output-dir ./output \ --refresh \ + --slack \ + --fossa \ --send-slack \ --slack-channel "${{ secrets.SLACK_WEBHOOK_URL }}" env: From af2db31c5c5fabb1105d542a5d73a93defe5976d Mon Sep 17 00:00:00 2001 From: Jakub Stejskal Date: Tue, 6 Oct 2026 11:52:46 +0200 Subject: [PATCH 6/8] COrrect option Signed-off-by: Jakub Stejskal --- .github/workflows/cve-notifier.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/cve-notifier.yml b/.github/workflows/cve-notifier.yml index 789dcb3..49d9e40 100644 --- a/.github/workflows/cve-notifier.yml +++ b/.github/workflows/cve-notifier.yml @@ -50,7 +50,7 @@ jobs: --config config/projects.yaml \ --output-dir ./output \ --refresh \ - --slack \ + --snyk \ --fossa \ --send-slack \ --slack-channel "${{ secrets.SLACK_WEBHOOK_URL }}" From 331f704a2c1f0c87ddc0640585bfb923c16faac8 Mon Sep 17 00:00:00 2001 From: Jakub Stejskal Date: Tue, 6 Oct 2026 12:42:58 +0200 Subject: [PATCH 7/8] Use newer version with fix for sending messages Signed-off-by: Jakub Stejskal --- .github/workflows/cve-notifier.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/cve-notifier.yml b/.github/workflows/cve-notifier.yml index 49d9e40..3c4cffa 100644 --- a/.github/workflows/cve-notifier.yml +++ b/.github/workflows/cve-notifier.yml @@ -25,7 +25,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: frawless/cve-notifier - ref: 467245e1eb8cbfb6aee22619cb05c95a79a839e1 + ref: 39bd3f7b0339578fb83b9e6d7029fd8e6b361a43 path: cve-notifier - name: Copy projects.yaml config From e786796ee93aa9434102dfa7c46b81d8155f3975 Mon Sep 17 00:00:00 2001 From: Jakub Stejskal Date: Tue, 6 Oct 2026 12:59:33 +0200 Subject: [PATCH 8/8] Update python installer Signed-off-by: Jakub Stejskal --- .github/workflows/cve-notifier.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/cve-notifier.yml b/.github/workflows/cve-notifier.yml index 3c4cffa..070d3cd 100644 --- a/.github/workflows/cve-notifier.yml +++ b/.github/workflows/cve-notifier.yml @@ -32,7 +32,7 @@ jobs: run: cp configs/cve-notifier-projects.yaml cve-notifier/config/projects.yaml - name: Set up Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.11"