Skip to content

fix(security): refresh Lambda image and dependencies - #88

Open
appleboy wants to merge 2 commits into
masterfrom
fix/trivy-security-scan
Open

appleboy wants to merge 2 commits into
masterfrom
fix/trivy-security-scan

Conversation

@appleboy

@appleboy appleboy commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Pin the patched upstream Lambda image by immutable digest and update vulnerable example Go dependencies. Align the example CI and README with Go 1.26, and restrict live deployments to master.

Related issues

N/A — repository-wide Trivy audit requested; no issue identifiers supplied.

AI authorship

  • AI was used
  • Tool / model: OpenAI Codex
  • AI-authored files: entrypoint.sh, .github/workflows/ci.yml, Dockerfile, README.md, example/go.mod, example/go.sum
  • Human line-by-line reviewed: None — not yet reviewed by a human.

Change classification

Core: action runtime changes affect consuming workflows; request two reviewers including the owner.

Plan reference

Restore the existing Trivy gate, preserve action inputs/entrypoint behavior, and verify before committing. Do not lower vulnerability severities or ignore CVEs.

Compatibility and scan-policy verification

Network-disabled amd64 debug parsing confirms empty layers/architectures become empty lists and six explicit list values remain intact. No AWS operations performed.

Verification

Checkout fix/trivy-security-scan at 2784329de6b7edce3d672d8248b3a17c3cd5b307 and run from lambda-action/. Prerequisites: Trivy 0.69.3 with the current vulnerability DB, Docker with linux/amd64 support, Go 1.26+, actionlint for modified workflows. Local commands were wrapped with rtk; Docker ran in Colima. No service credentials needed.

Command Status Observed result
trivy fs --scanners vuln,secret --severity CRITICAL,HIGH --exit-code 1 . Passed No findings at the configured severity after the fix.
git diff --check master...HEAD Passed No whitespace errors.
docker build --platform linux/amd64 -t lambda-action:trivy-fix . Passed Image built in local Colima Docker.
trivy image --scanners vuln --severity CRITICAL --exit-code 1 lambda-action:trivy-fix Passed 0 CRITICAL; local image was exported with docker save and scanned using --input. Existing CI still reports HIGH via SARIF.
docker run --rm --platform linux/amd64 --entrypoint /bin/drone-lambda lambda-action:trivy-fix --help Passed Expected executable and CLI options available.
cd example && go test ./... Passed Example compiles on Go 1.26.7; package has no test files.
actionlint .github/workflows/ci.yml Passed Updated Go matrix and default-branch filter valid.

Behavioral scenario

Run the filesystem scan above; expect exit 0. Build and scan the image with the commands above; expect exit 0 and zero CRITICAL vulnerabilities. Run CLI help without credentials; expect usage output without contacting a service.

Execution status: Passed locally. GitHub PR checks will independently run after creation; no hosted result is claimed here. Live notification/deployment checks were not run because they affect external services.

Cleanup: docker image rm lambda-action:trivy-fix removes the test image.

Security check

No credentials in the diff. Existing scan severities remain intact. No vulnerability exceptions added.

Risk and rollback

Upstream runtime/dependency upgrades may affect service integration; review compatibility before merging. Revert this commit to restore the previous image and configuration.

Reviewer guide

Review .github/workflows/ci.yml, Dockerfile, README.md, example/go.mod, example/go.sum. Confirm the Trivy PR jobs finish successfully and review any remaining HIGH findings in uploaded SARIF. Service integration requires owner review in a disposable environment.

Hosted verification

Trivy Security Scan passed at 2784329de6b7edce3d672d8248b3a17c3cd5b307: https://github.com/appleboy/lambda-action/actions/runs/37485829797

- Pin the patched Lambda runtime image
- Update vulnerable example dependencies and Go setup
- Keep deployment jobs on the default branch
- Keep omitted list inputs empty after the runtime upgrade
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant