Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

History

29 Commits

Repository files navigation

Secure

This repository is the central, auditable inventory of security evidence for the uug-ai organization. It gives security officers and engineering teams one place to review software composition, known vulnerabilities, security-control coverage, and trends across projects.

This repository is public by design so customers, users, security officers, and engineering teams can inspect the available evidence. A missing or stale record is a coverage gap, not proof that a project has no vulnerabilities. Everything committed here is public information and must be approved for external disclosure.

Evidence inventory

Area Location State
SPDX SBOMs sboms/ Automated daily
SBOM coverage sboms/index.json Automated daily
Container vulnerability scans containers/ Automated daily
Container scan coverage containers/index.json Awaiting first scan
Critical/high vulnerability aggregate cves/ Automated with container scans
Critical/high occurrence data cves/index.json Awaiting first scan
Security metrics metrics/ Planned
Protection controls controls/control-register.md Initial assessment register

Container image security overview

Generated at 2026-08-16T04:01:01Z from the newest tagged GHCR image available for each approved project. Scores use the highest detected severity: 100 clean, 80 low, 60 medium, 30 high, and 0 critical. An unavailable image is a coverage gap, not a clean result.

Repository Scan Risk Score Tag Critical High Medium Low Fixable C/H Report
factory scanned High 30/100 latest 0 25 9 0 0/24 Trivy
hub-anpr scanned Critical 0/100 latest 11 204 302 245 0/22 Trivy
hub-api scanned High 30/100 latest 0 26 10 0 0/24 Trivy
hub-cleanup scanned High 30/100 latest 0 8 0 0 0/8 Trivy
hub-frontend scanned Clean 100/100 latest 0 0 0 0 0/0 Trivy
hub-loitering scanned High 30/100 latest 0 24 8 0 0/24 Trivy
hub-monitor-device scanned Critical 0/100 latest 1 26 10 0 1/25 Trivy
hub-objecttracking scanned High 30/100 latest-gpu 0 42 528 103 0/42 Trivy
hub-pipeline-analysis scanned High 30/100 latest 0 22 7 0 0/22 Trivy
hub-pipeline-classifier scanned Critical 0/100 latest 23 268 1199 835 1/20 Trivy
hub-pipeline-counting scanned Critical 0/100 latest 1 25 8 0 1/25 Trivy
hub-pipeline-dominantcolors scanned Critical 0/100 latest 1 25 9 0 1/25 Trivy
hub-pipeline-event scanned High 30/100 latest 0 17 4 0 0/17 Trivy
hub-pipeline-export scanned High 30/100 latest 0 23 7 0 0/23 Trivy
hub-pipeline-monitor scanned Critical 0/100 latest 1 24 8 0 1/24 Trivy
hub-pipeline-notification scanned Critical 0/100 latest 1 26 10 0 1/25 Trivy
hub-pipeline-notification-test scanned High 30/100 latest 0 24 16 0 0/23 Trivy
hub-pipeline-redaction scanned High 30/100 latest 0 33 384 45 0/33 Trivy
hub-pipeline-sequence scanned High 30/100 latest 0 22 7 0 0/22 Trivy
hub-pipeline-sprite scanned Critical 0/100 latest 1 25 8 0 1/25 Trivy
hub-pipeline-throttler scanned Critical 0/100 latest 2 41 36 2 2/41 Trivy
hub-pipeline-thumbnail scanned Critical 0/100 latest 1 25 9 0 1/25 Trivy
hub-proxy unavailable Unavailable - - 0 0 0 0 0/0 -
hub-reactivatesubscriptions unavailable Unavailable - - 0 0 0 0 0/0 -
hub-vault-forwarder unavailable Unavailable - - 0 0 0 0 0/0 -
hub-workflows scanned High 30/100 latest 0 22 7 0 0/22 Trivy
vault scanned High 30/100 latest 0 23 9 0 0/22 Trivy

SBOM quality overview

Generated at 2026-08-16T02:43:27Z. Quality combines document metadata (20%), package identity (30%), licensing (20%), provenance (15%), and relationships (15%).

Legend: 馃煝 85-100, 馃煛 70-84, 馃煚 50-69, 馃敶 0-49 or unavailable. This measures SBOM completeness, not vulnerability severity.

Repository Collection Quality Score Packages Versioned Licensed PURL Details
factory collected 馃煚 Needs work 66/100 162 100% 64% 100% BreakdownSPDX
hub-anpr collected 馃煚 Needs work 68/100 52 100% 85% 100% BreakdownSPDX
hub-api collected 馃煚 Needs work 68/100 160 100% 89% 100% BreakdownSPDX
hub-cleanup collected 馃煚 Needs work 68/100 47 100% 83% 100% BreakdownSPDX
hub-frontend collected 馃煚 Needs work 69/100 1225 100% 99% 100% BreakdownSPDX
hub-loitering collected 馃煚 Needs work 68/100 49 100% 84% 100% BreakdownSPDX
hub-monitor-device collected 馃煚 Needs work 68/100 79 100% 87% 100% BreakdownSPDX
hub-objecttracking collected 馃煚 Needs work 67/100 35 100% 74% 100% BreakdownSPDX
hub-pipeline-analysis collected 馃煚 Needs work 68/100 63 100% 83% 100% BreakdownSPDX
hub-pipeline-classifier collected 馃煚 Needs work 68/100 59 100% 88% 100% BreakdownSPDX
hub-pipeline-counting collected 馃煚 Needs work 68/100 48 100% 81% 100% BreakdownSPDX
hub-pipeline-dominantcolors collected 馃煚 Needs work 68/100 60 100% 88% 100% BreakdownSPDX
hub-pipeline-event collected 馃煚 Needs work 67/100 29 100% 79% 100% BreakdownSPDX
hub-pipeline-export collected 馃煚 Needs work 68/100 58 100% 84% 100% BreakdownSPDX
hub-pipeline-monitor collected 馃煚 Needs work 68/100 65 100% 86% 100% BreakdownSPDX
hub-pipeline-notification collected 馃煚 Needs work 68/100 95 100% 88% 100% BreakdownSPDX
hub-pipeline-notification-test collected 馃煚 Needs work 68/100 65 100% 83% 100% BreakdownSPDX
hub-pipeline-redaction collected 馃煚 Needs work 68/100 49 100% 86% 100% BreakdownSPDX
hub-pipeline-sequence collected 馃煚 Needs work 68/100 60 100% 85% 100% BreakdownSPDX
hub-pipeline-sprite collected 馃煚 Needs work 68/100 58 100% 83% 100% BreakdownSPDX
hub-pipeline-throttler collected 馃煚 Needs work 68/100 53 100% 83% 100% BreakdownSPDX
hub-pipeline-thumbnail collected 馃煚 Needs work 68/100 61 100% 85% 100% BreakdownSPDX
hub-proxy collected 馃煚 Needs work 65/100 26 100% 58% 100% BreakdownSPDX
hub-reactivatesubscriptions collected 馃煚 Needs work 67/100 63 100% 78% 100% BreakdownSPDX
hub-vault-forwarder collected 馃煚 Needs work 69/100 8 100% 88% 100% BreakdownSPDX
hub-workflows collected 馃煚 Needs work 68/100 85 100% 88% 100% BreakdownSPDX
vault collected 馃煚 Needs work 69/100 1654 100% 99% 100% BreakdownSPDX

SBOM collection

The Collect product SBOMs workflow runs daily at 02:17 UTC and can also be started manually. It:

  1. Lists repositories visible to the read-only organization token and selects names beginning with hub plus the exact factory and vault repositories, except repositories explicitly excluded after retirement.
  2. Downloads each selected repository's SPDX SBOM from GitHub's Dependency Graph API.
  3. Writes collection metadata to sboms/<repository>/status.json and, when available, the document to sboms/<repository>/sbom.spdx.json.
  4. Scores document metadata, package identity, licensing, provenance, and SPDX relationships, then updates the quality table above.
  5. Updates sboms/index.json with collection status, quality metrics, and coverage totals.
  6. Preserves the last successful document and marks it stale when a refresh fails.
  7. Commits changed evidence with the repository-scoped GitHub Actions token. Rejected non-fast-forward pushes are rebased onto the latest main and retried up to three times.

The collector ignores every repository outside hub*, factory, and vault. It also excludes the retired hub-background-notifcation-digest, hub-license, hub-mobile, hub-pipeline, hub-pipeline-classifier-yolov3, and hub-pipeline-licenseplate repositories. When the scope changes, generated directories and index entries that are no longer selected are removed during the next successful collection. Archived or private target repositories are included when visible to the token, so grant private access only when the repository name and SBOM are approved for public disclosure.

Container image scanning

The Scan product container images workflow runs separately each day at 03:47 UTC and can be started manually. It uses the approved repositories in sboms/index.json, discovers the newest tagged ghcr.io/uug-ai/<repository> package version, scans its immutable digest with Trivy, and writes raw reports plus summary metadata under containers/. It also groups critical and high findings by advisory identifier under cves/, counting each affected package record as one occurrence and listing the unique affected repositories and package versions. Medium and lower findings remain available in the raw reports but are not included in the CVE aggregate.

Projects without a matching tagged image remain visible as unavailable. Transient package or scanner failures preserve the last successful report as stale. The root overview scores the highest detected severity as 100 clean, 80 low, 60 medium, 30 high, or 0 critical and shows vulnerability and fixable critical/high counts. This is a triage score, not a guarantee that an image is secure.

Required setup

Grant the existing TOKEN organization secret to this repository. The workflow uses it only to read organization repositories and their SBOMs. The token should ideally be owned by a dedicated automation account and limited to:

  • Repository access to the hub*, factory, and vault repositories whose SBOMs are approved for public disclosure.
  • Contents: read repository permission; metadata read access is implicit.
  • read:packages scope and access to each GHCR package approved for public vulnerability reporting.
  • No write permissions.

An existing token with broader permissions will work, but reducing it to these permissions limits the impact of accidental exposure or workflow compromise.

The repository's Actions settings must allow GITHUB_TOKEN to write contents so the workflow can push refreshed evidence. If main is protected against direct pushes, grant the security bot an appropriate bypass or change the final step to open a pull request.

GitHub Dependency Graph must be enabled for each target repository. Target repositories where it is disabled or inaccessible remain visible in the index as unavailable rather than silently disappearing.

Trust model

  • The evidence repository is public to provide transparent, reviewable security information.
  • Cross-repository credentials are read-only and scoped to collection.
  • Generated records retain their source repository and API endpoint.
  • Workflow actions are pinned to immutable commit SHAs.
  • Collection errors are evidence and remain visible in the coverage index.
  • Changes to controls and manually maintained assessments require review.

Do not store credentials, private repository evidence that has not been approved for disclosure, exploit details, customer data, or confidential incident material in this repository. Use the approved private incident process for sensitive operational information.

Development

The collector uses only the Go standard library.

GOWORK=off go test ./...
GH_TOKEN=<read-only-token> GOWORK=off go run ./cmd/collect-sboms
GOWORK=off go run ./cmd/collect-sboms -refresh-existing
export GH_TOKEN=<read-only-token>
export TRIVY_USERNAME=<token-owner>
export TRIVY_PASSWORD="$GH_TOKEN"
GOWORK=off go run ./cmd/scan-containers

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages