This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
# Release security scan report
|
||||
|
||||
Release candidate scans were executed on the Unraid validation host on
|
||||
2026-07-27.
|
||||
|
||||
| Check | Result | Evidence |
|
||||
| --- | --- | --- |
|
||||
| Production dependency audit | Pass | `pnpm audit --prod` reported no high or critical findings. One moderate `esbuild` development-server advisory remains through `better-auth > drizzle-kit`; the affected development server is not present or exposed in the production web/worker runtime. |
|
||||
| Runtime web image | Pass | Trivy 0.69.3 with `--scanners vuln --severity HIGH,CRITICAL --ignore-unfixed --exit-code 1` reported zero findings for the Debian and Node package inventories. |
|
||||
| Runtime worker image | Pass | The same Trivy policy reported zero findings. |
|
||||
| Repository secret history | Pass | Gitleaks 8.28.0 scanned 153 commits and approximately 4.99 MB with no leaks. Two exact local-development/CI encryption fixtures are narrowly classified in `.gitleaks.toml`; no file-wide exclusion is used. |
|
||||
| Production license inventory | Pass | `pnpm licenses list --prod --json` inventoried 161 package records under 0BSD, Apache-2.0, BSD-2-Clause, BSD-3-Clause, CC-BY-4.0, ISC, LGPL-3.0-or-later, MIT, MPL-2.0 and Unlicense. No prohibited or unclassified license was found. |
|
||||
| Application security tests | Pass | The configured suite passed 2 files and 11 tests, including dependency and production-boundary checks. |
|
||||
|
||||
The Node base image originally included unused npm, Corepack and Yarn files
|
||||
with high/critical findings in their bundled tooling. Commit `601e59e` removes
|
||||
those package managers from long-running runtime images; they remain available
|
||||
only in build/migration tooling where required.
|
||||
Reference in New Issue
Block a user