The nightly security audit workflow detected one or more findings.
Pro Pushes prueft build.yml::Security gates denselben Stack,
aber zwischen Pushes neu veroeffentlichte Advisories bleiben sonst
unbemerkt — dieser Nightly schliesst die Luecke (Hintergrund:
scripts/open-security-audit-issue.sh Header).
Full step output is attached as workflow artifact
security-audit-34730572645 (.tmp/security/*.log); the
tails below show the relevant Vulnerability-Tabelle.
govulncheck (apps/api) — tail
1.26.6: Pulling from library/golang
1da3cb2f93f2: Pulling fs layer
68b64c51cda3: Pulling fs layer
ec935196e6a0: Pulling fs layer
bb2704c1c1eb: Pulling fs layer
fa55d8c7975b: Pulling fs layer
5bf265a321f3: Pulling fs layer
4f4fb700ef54: Pulling fs layer
fa55d8c7975b: Waiting
5bf265a321f3: Waiting
4f4fb700ef54: Waiting
bb2704c1c1eb: Waiting
68b64c51cda3: Download complete
1da3cb2f93f2: Verifying Checksum
1da3cb2f93f2: Download complete
ec935196e6a0: Verifying Checksum
ec935196e6a0: Download complete
5bf265a321f3: Verifying Checksum
5bf265a321f3: Download complete
4f4fb700ef54: Verifying Checksum
4f4fb700ef54: Download complete
fa55d8c7975b: Verifying Checksum
fa55d8c7975b: Download complete
bb2704c1c1eb: Verifying Checksum
bb2704c1c1eb: Download complete
1da3cb2f93f2: Pull complete
68b64c51cda3: Pull complete
ec935196e6a0: Pull complete
bb2704c1c1eb: Pull complete
fa55d8c7975b: Pull complete
5bf265a321f3: Pull complete
4f4fb700ef54: Pull complete
Digest: sha256:0d1d3a794be25f809dd2cb3160d8c73276c4056a9f8242a138e908ddeee7b6b6
Status: Downloaded newer image for golang:1.26.6
go: downloading golang.org/x/vuln v1.1.4
go: downloading golang.org/x/telemetry v0.0.0-20240522233618-39ace7a40ae7
go: downloading golang.org/x/mod v0.22.0
go: downloading golang.org/x/tools v0.29.0
go: downloading golang.org/x/sync v0.10.0
No vulnerabilities found.
pnpm audit (TS workspace) — tail
#17 3.022
#17 3.022 ╭──────────────────────────────────────────────╮
#17 3.022 │ │
#17 3.022 │ Update available! 11.20.0 → 12.4.1. │
#17 3.022 │ Changelog: https://pnpm.io/v/12.4.1 │
#17 3.022 │ To update, run: corepack use pnpm@12.4.1 │
#17 3.022 │ │
#17 3.022 ╰──────────────────────────────────────────────╯
#17 3.022
#17 3.813 Progress: resolved 435, reused 0, downloaded 435, added 102
#17 4.295 Progress: resolved 435, reused 0, downloaded 435, added 435, done
#17 4.593 [WARN] Failed to create bin at /workspace/apps/analyzer-service/node_modules/.bin/m-trace. ENOENT: no such file or directory, open '/workspace/packages/stream-analyzer/dist/cli/main.cjs'
#17 4.636
#17 4.636 devDependencies:
#17 4.636 + @playwright/test 1.59.1
#17 4.636 + eslint 10.3.0
#17 4.636 + eslint-plugin-svelte 3.17.1
#17 4.636 + globals 17.6.0
#17 4.636 + hls.js 1.6.16
#17 4.636 + svelte-eslint-parser 1.6.0
#17 4.636 + tsup 8.5.1
#17 4.636 + typescript 6.0.3
#17 4.636 + typescript-eslint 8.59.1
#17 4.636 + vitest 4.1.5
#17 4.636
#17 4.686 ✓ Lockfile passes supply-chain policies (515 entries in 3.9s)
#17 4.714 Done in 4.5s using pnpm v11.20.0
#17 DONE 7.7s
#18 [audit 1/1] RUN pnpm audit --audit-level high
#18 0.687 15 vulnerabilities found
#18 0.687 Severity: 2 low | 13 moderate
#18 DONE 0.7s
#19 exporting to image
#19 exporting layers
#19 exporting layers 4.2s done
#19 writing image sha256:d5d2f9635a2e58c190eca69d1b66d0cd481a367c5819e0dee184b67caa0417dc done
#19 naming to docker.io/library/m-trace-ts:audit done
#19 DONE 4.2s
Trivy image scan — tail
#17 3.176 CLI tsup v8.5.1
#17 3.177 CLI Target: es2022
#17 3.178 CLI Cleaning output folder
#17 3.178 ESM Build start
#17 3.178 CJS Build start
#17 3.369 CJS dist/main.cjs 6.62 KB
#17 3.369 CJS ⚡️ Build success in 191ms
#17 3.369 ESM dist/main.js 6.58 KB
#17 3.369 ESM ⚡️ Build success in 191ms
#17 DONE 3.6s
#18 [build 11/11] RUN pnpm --filter @pt9912/analyzer-service deploy --prod /deploy
#18 1.124 Packages are copied from the content-addressable store to the virtual store.
#18 1.124 Content-addressable store is at: /root/.local/share/pnpm/store/v11
#18 1.124 Virtual store is at: ../deploy/node_modules/.pnpm
#18 1.135 ../deploy | Progress: resolved 1, reused 0, downloaded 0, added 0
#18 1.136 ../deploy | +1 +
#18 1.614 ../deploy | Progress: resolved 1, reused 1, downloaded 0, added 1, done
#18 DONE 1.7s
#19 [runtime 5/5] COPY --from=build /deploy ./
#19 DONE 0.1s
#20 exporting to image
#20 exporting layers
#20 exporting layers 0.2s done
#20 writing image sha256:92fa90caa9898e9a8167ccb37d2e6c8646ab2060b51730f7cf8bde5a696eccf2 done
#20 naming to docker.io/library/mtrace-analyzer-service:scan done
#20 DONE 0.2s
mkdir -p .security/.trivy-cache
# `.security/.trivyignore` wird pro Image aus
# `.security/vulnignore.yaml` generiert (single-source-of-truth +
# audit trail). Der Generator bricht ab, falls ein Eintrag das
# `expires`-Datum ueberschritten hat — Wartungsregel laut
# Scope-Filterung verhindert, dass ein CVE-Ignore
# fuer ein Runtime-Image global alle Image-Scans maskiert.
bash scripts/render-trivyignore.sh mtrace-api
render-trivyignore: CVE-2026-11822 expired (2026-09-12) — renew or remove the entry.
render-trivyignore: CVE-2026-11824 expired (2026-09-12) — renew or remove the entry.
make: *** [Makefile:891: image-scan] Error 1
Reaction
- Identify the failing check(s) above and read the full log in the
artifact.
- govulncheck: bump the offending Go dependency in
apps/api/go.mod, run make vuln-check locally to confirm.
- pnpm audit: either bump the offending package or add a
pnpm.overrides entry in the root package.json (same
pattern as picomatch/devalue). Re-run
make lock-refresh && make audit-ts locally.
- Trivy image scan: identify the OS package or layer responsible
in the offending Dockerfile and bump the base image / package
version. If a finding is a knowingly accepted risk, add an entry
to .security/vulnignore.yaml with an expires date
(max 30 days) and a justification — make image-scan regenerates
the per-image .trivyignore automatically.
- Push the fix; the next Nightly verifies that the gate is green
again. If the issue stays open beyond 7 days, escalate via the
Tranche-3 risks backlog (docs/plan/planning/risks-backlog.md).
The nightly security audit workflow detected one or more findings.
Pro Pushes prueft
build.yml::Security gatesdenselben Stack,aber zwischen Pushes neu veroeffentlichte Advisories bleiben sonst
unbemerkt — dieser Nightly schliesst die Luecke (Hintergrund:
scripts/open-security-audit-issue.shHeader).successsuccessfailureFull step output is attached as workflow artifact
security-audit-34730572645(.tmp/security/*.log); thetails below show the relevant Vulnerability-Tabelle.
govulncheck (apps/api) — tail
pnpm audit (TS workspace) — tail
Trivy image scan — tail
Reaction
artifact.
apps/api/go.mod, runmake vuln-checklocally to confirm.pnpm.overridesentry in the rootpackage.json(samepattern as
picomatch/devalue). Re-runmake lock-refresh && make audit-tslocally.in the offending Dockerfile and bump the base image / package
version. If a finding is a knowingly accepted risk, add an entry
to
.security/vulnignore.yamlwith anexpiresdate(max 30 days) and a justification —
make image-scanregeneratesthe per-image
.trivyignoreautomatically.again. If the issue stays open beyond 7 days, escalate via the
Tranche-3 risks backlog (
docs/plan/planning/risks-backlog.md).