Trivyãµãã©ã€ãã§ãŒã³æ»æ â ã»ãã¥ãªãã£ããŒã«ããå¶åšãã«ãªã£ãæ¥
ãTrivyãã£ãŠããã»ãã¥ãªãã£ããŒã«ãæ»æãããã£ãŠèãããã ãã©ãã»ãã¥ãªãã£ããŒã«ãæ»æãããã£ãŠã©ãããããšïŒ
Trivy㯠Aqua Security ãéçºããŠããOSSã®ã»ãã¥ãªãã£ã¹ãã£ãã§ãã³ã³ããã€ã¡ãŒãžãã³ãŒãã®è匱æ§ãæ€åºããŠãããããŒã«ã ãã2026幎3æ19æ¥ããã®Trivyã®GitHub ActionsïŒtrivy-actionãšsetup-trivyïŒãæ»æè ã°ã«ãŒããTeamPCPãã«ä¹ã£åããããã ãã€ãŸããã»ãã¥ãªãã£ã®çªäººããã®ãã®ãäŸµå ¥å£ã«ãªã£ãŠããŸã£ããã ãã
GitHub Actionsãä¹ã£åãããã£ãŠãå ·äœçã«ã¯äœãèµ·ããã®ïŒ
GitHub Actionsã§ã¯ããŒãžã§ã³ããã¿ã°ãã§ç®¡çããŠãããã ãã©ãæ»æè ã¯aquasecurity/trivy-actionã®76åã®ã¿ã°ãšãsetup-trivyã®å š7ã¿ã°ãæ¹ãããããã ããImposter Commitããšããææ³ã§ãæ£èŠã®ãªããžããªã«èŠããããåœã®ã³ããããçŽã蟌ãŸããŠãã¿ã°ã®åç §å ãæªæããã³ãŒãã«å·®ãæ¿ãããã ãã
ããã§äœãçãŸãã¡ãã£ãã®ïŒ
CI/CDãã€ãã©ã€ã³ã§äœ¿ãããŠããã·ãŒã¯ã¬ããæ å ±ãæ ¹ãããçãããããAWS IAMã®èªèšŒæ å ±ãSlackãDiscordã®ãŠã§ãããã¯URLããã®ä»ã®ç°å¢å€æ°ã«å ¥ã£ãŠããAPIããŒãªã©ãæ¹ãããããActionãå®è¡ããããšããã€ãã©ã€ã³ã®ã¡ã¢ãªäžã«ããã·ãŒã¯ã¬ãããåéããŠå€éšã«éä¿¡ããä»çµã¿ã ã£ããã ã
çãã ããŒã¿ã¯ã©ããã£ãŠå€ã«éã£ãã®ïŒãã¬ãªãããã«ããä»çµã¿ããã£ãã®ïŒ
ããªãå·§åŠã ã£ãããçªåããããŒã¿ã¯AES-256ãšRSA-4096ã§æå·åããŠãããã¿ã€ãã¹ã¯ã¯ããã£ã³ã°ïŒæ£èŠãã¡ã€ã³ã«äŒŒããåœãã¡ã€ã³ïŒã®ãµãŒããŒã«ã¢ããããŒãããŠãããã ãæå·åãããŠããããããããã¯ãŒã¯ç£èŠã§äžèº«ãèŠãŠãäœãéãããŠãããåãããªããéä¿¡å ã®ãã¡ã€ã³ãäžèŠãããšæ£èŠã£ãœããããæ°ã¥ãã«ããã£ããã ãã
Trivyã ããããªããŠä»ã®ããŒã«ã«ãåºãã£ãã£ãŠèãããã©ãæ¬åœãªã®ïŒ
ãããªãã ãTrivyã®æ»æã§çªåããèªèšŒæ å ±ã䜿ã£ãŠãCheckmarxã®KICS GitHub ActionãLiteLLMã®PyPIããã±ãŒãžã«ãæ»æãæ³¢åãããããããããµãã©ã€ãã§ãŒã³æ»æãã®æããšããã§ã1ã€ã®ããŒã«ã䟵害ãããšãããããåŸãèªèšŒæ å ±ã§èã¥ãåŒã«å¥ã®ãããžã§ã¯ãã«ãäŸµå ¥ã§ããŠããŸããã ã
ãã¡ã®ãããžã§ã¯ãã§ãGitHub Actions䜿ã£ãŠããã ãã©ã倧äžå€«ãªã®ããªâŠïŒå¯Ÿçã£ãŠããã®ïŒ
ãŸããTrivyã䜿ã£ãŠããå Žåã¯ããã«å®å šãªããŒãžã§ã³ã«æŽæ°ããŠããtrivy v0.69.3ãtrivy-action v0.35.0ãsetup-trivy v0.2.6ãä¿®æ£æžã¿ã ãããããŠäžçªå€§äºãªå¯Ÿçã¯ãGitHub Actionsãã¿ã°æå®ã§ã¯ãªãã³ãããããã·ã¥ã§ãã³çãããããšãããšãã°trivy-action@v0.35.0ã§ã¯ãªããtrivy-action@abcdef1234567890ã®ããã«SHAããã·ã¥ã§æå®ãããã ãã¿ã°ã¯å·®ãæ¿ãããããã©ãããã·ã¥ã¯æ¹ããã§ããªããããã
ããã·ã¥ã§æå®ããã°å®å šã£ãŠããšãªãã ãïŒã§ãå šéšã®Actionãããã·ã¥æå®ã«ããã®ã¯å€§å€ããâŠ
ãããã«æéã¯ããããã©ãDependabotãRenovateãšãã£ãããŒã«ã䜿ãã°ãããã·ã¥æå®ã®Actionãèªåã§ã¢ããããŒãææ¡ããŠãããããããšãGitHubåŽããã¿ã°ã®äžå€æ§ããä¿èšŒããä»çµã¿ã®è°è«ãé²ãã§ãããã ããããããCI/CDã®ã·ãŒã¯ã¬ããã«ã¯æå°æš©éã®ååã培åºããããšãæ¬åœã«å¿ èŠãªæš©éã ããä»äžããŠãäžãäžæŒããŠã被害ãæå°éã«æããã®ã倧åã ãã
OSSã£ãŠèª°ã§ã䜿ããŠäŸ¿å©ã ãã©ããããããªã¹ã¯ããããã ãâŠ
ãããä»ãŸãã«æ¥çå šäœã§è°è«ãããŠãããã€ã³ãã ããOSSã®ãµãã©ã€ãã§ãŒã³ã¯ãä¿¡é Œã®é£éãã§æãç«ã£ãŠãããã©ããã®é£éã®ã©ãã1ã€ãç Žããããšå šäœã厩ãããã ããSBOMïŒãœãããŠã§ã¢éšå衚ïŒã§äŸåé¢ä¿ãå¯èŠåããããSLSAãSigstoreã®ãããªãã¬ãŒã ã¯ãŒã¯ã§ãã«ãã®æ¥æŽãæ€èšŒå¯èœã«ããåãçµã¿ãæ¥éã«åºãã£ãŠãããã
ã»ãã¥ãªãã£ããŒã«ãå®ãããã®ã»ãã¥ãªãã£ãå¿ èŠã£ãŠããªãã ãäžæè°ãªæãâŠ
ãŸãã«ãã®éãã§ãã誰ãçªäººãèŠåŒµãã®ãããšããå€å žçãªåããã®ãã®ã ããä»åã®äºä»¶ã¯ãã»ãã¥ãªãã£ããŒã«ã ãããšãã£ãŠç¡æ¡ä»¶ã«ä¿¡é ŒããŠã¯ãããªããšããæèšãæ¥çå šäœã«çªãã€ããããããŒã«ã®å°å ¥ã ãã§ãªãããã®ããŒã«èªäœã®äŸçµŠçµè·¯ã®å®å šæ§ãŸã§æ€èšŒããããŒããã©ã¹ãçãªçºæ³ããCI/CDã«ãå¿ èŠãªæä»£ã«ãªã£ããã ãã