Skip to content

Add workflow to generate pre-filled risk exception documents from Trivy scans - #138

Merged
DanielSass merged 5 commits into
mainfrom
meh/auto-exception-doc
Sep 28, 2026
Merged

DanielSass merged 5 commits into
mainfrom
meh/auto-exception-doc

Conversation

@mehansen

Copy link
Copy Markdown
Contributor

Related Issue

  • The risk exception docs required before promoting images with CRITICAL/HIGH vulnerabilities are currently written by hand. This automates the boilerplate so the team only needs to fill in the justification part.

Changes Proposed

  • New workflow generate-risk-exception-doc.yml: builds the lambda image at a given ref, scans with Trivy, and uploads a risk-exception.md artifact.
  • New generateRiskExceptionTemplate() in security-summary.js that renders per-CVE tables (package, version, fix availability, reference) with blank justification/mitigation/timeline fields. Writes nothing when there are no findings.

Additional Information

  • Severities and image/Dockerfile are configurable via env vars (currently set to CRITICAL,HIGH).

Testing

  • Ran against my branch here and verified that the generated doc matches the HIGH vulnerabilities we currently have for the repo.

Checklist for Primary Reviewer

  • Any large-scale changes have been deployed and smoke tested
  • Any content updates (user-facing error messages, etc) have been approved by content team
  • Any dependencies introduced have been vetted and discussed

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

🔒 Security Scan Results

⚠️ Found 3 vulnerabilities

Severity Total
🟠 High 2
🟡 Medium 1

📦 did-lambda

Severity Count
🟠 High 2
🟡 Medium 1

View detailed results: Security tab
Last updated: 2026-09-28 15:59:46 UTC

@mehansen
mehansen marked this pull request as ready for review September 25, 2026 21:12
@mehansen
mehansen requested a review from a team as a code owner September 25, 2026 21:12
kevinfiol
kevinfiol previously approved these changes Sep 26, 2026

@kevinfiol kevinfiol left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good 👍 Thanks for updating the documentation as well.

DanielSass
DanielSass previously approved these changes Sep 28, 2026
@DanielSass
DanielSass dismissed stale reviews from kevinfiol and themself via 765bf92 September 28, 2026 15:58
@DanielSass
DanielSass merged commit 74958a8 into main Sep 28, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants