Block a user
ci-security (latest)
Published 2026-08-31 02:01:25 -04:00 by bvandeusen
Installation
docker pull git.fabledsword.com/bvandeusen/ci-security:latestsha256:d3f62d72d94df71fed8827b2209363a5af60515cb22d4490acb70e3a69bcad18
About this package
CI image: FabledSentry scanner toolchain (gitleaks + semgrep + osv-scanner + trivy)
Image Layers
| # debian.sh --arch 'amd64' out/ 'trixie' '@1787529600' |
| ENV PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin |
| ENV LANG=C.UTF-8 |
| RUN /bin/sh -c set -eux; apt-get update; apt-get install -y --no-install-recommends ca-certificates netbase tzdata ; apt-get dist-clean # buildkit |
| ENV GPG_KEY=7169605F62C751356D054A26A821E680E5FA6305 |
| ENV PYTHON_VERSION=3.12.14 |
| ENV PYTHON_SHA256=5c8462af5790baf43a321a1559dbe0db06d1be4300fb85fb53c40060668e548a |
| RUN /bin/sh -c set -eux; savedAptMark="$(apt-mark showmanual)"; apt-get update; apt-get install -y --no-install-recommends dpkg-dev gcc gnupg libbluetooth-dev libbz2-dev libc6-dev libdb-dev libffi-dev libgdbm-dev liblzma-dev libncursesw5-dev libreadline-dev libsqlite3-dev libssl-dev make tk-dev uuid-dev wget xz-utils zlib1g-dev ; wget -O python.tar.xz "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz"; echo "$PYTHON_SHA256 *python.tar.xz" | sha256sum -c -; wget -O python.tar.xz.asc "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz.asc"; GNUPGHOME="$(mktemp -d)"; export GNUPGHOME; gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$GPG_KEY"; gpg --batch --verify python.tar.xz.asc python.tar.xz; gpgconf --kill all; rm -rf "$GNUPGHOME" python.tar.xz.asc; mkdir -p /usr/src/python; tar --extract --directory /usr/src/python --strip-components=1 --file python.tar.xz; rm python.tar.xz; cd /usr/src/python; gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; ./configure --build="$gnuArch" --enable-loadable-sqlite-extensions --enable-optimizations --enable-option-checking=fatal --enable-shared $(test "${gnuArch%%-*}" != 'riscv64' && echo '--with-lto') --with-ensurepip ; nproc="$(nproc)"; EXTRA_CFLAGS="$(dpkg-buildflags --get CFLAGS)"; LDFLAGS="$(dpkg-buildflags --get LDFLAGS)"; LDFLAGS="${LDFLAGS:-} -Wl,--strip-all"; arch="$(dpkg --print-architecture)"; arch="${arch##*-}"; case "$arch" in amd64|arm64) EXTRA_CFLAGS="${EXTRA_CFLAGS:-} -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer"; ;; i386) ;; *) EXTRA_CFLAGS="${EXTRA_CFLAGS:-} -fno-omit-frame-pointer"; ;; esac; make -j "$nproc" "EXTRA_CFLAGS=${EXTRA_CFLAGS:-}" "LDFLAGS=${LDFLAGS:-}" ; rm python; make -j "$nproc" "EXTRA_CFLAGS=${EXTRA_CFLAGS:-}" "LDFLAGS=${LDFLAGS:-} -Wl,-rpath='\$\$ORIGIN/../lib'" python ; make install; cd /; rm -rf /usr/src/python; find /usr/local -depth \( \( -type d -a \( -name test -o -name tests -o -name idle_test \) \) -o \( -type f -a \( -name '*.pyc' -o -name '*.pyo' -o -name 'libpython*.a' \) \) \) -exec rm -rf '{}' + ; ldconfig; apt-mark auto '.*' > /dev/null; apt-mark manual $savedAptMark; find /usr/local -type f -executable -not \( -name '*tkinter*' \) -exec ldd '{}' ';' | awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); printf "*%s\n", so }' | sort -u | xargs -rt dpkg-query --search | awk 'sub(":$", "", $1) { print $1 }' | sort -u | xargs -r apt-mark manual ; apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; apt-get dist-clean; export PYTHONDONTWRITEBYTECODE=1; python3 --version; pip3 --version # buildkit |
| RUN /bin/sh -c set -eux; for src in idle3 pip3 pydoc3 python3 python3-config; do dst="$(echo "$src" | tr -d 3)"; [ -s "/usr/local/bin/$src" ]; [ ! -e "/usr/local/bin/$dst" ]; ln -svT "$src" "/usr/local/bin/$dst"; done # buildkit |
| CMD ["python3"] |
| LABEL org.opencontainers.image.source=https://git.fabledsword.com/bvandeusen/CI-runner org.opencontainers.image.description=CI image: FabledSentry scanner toolchain (gitleaks + semgrep + osv-scanner + trivy) org.opencontainers.image.licenses=MIT |
| SHELL [/bin/bash -eo pipefail -c] |
| ARG NODE_MAJOR=24 |
| ARG GITLEAKS_VERSION=v8.18.4 |
| ARG SEMGREP_VERSION=1.86.0 |
| ARG OSV_SCANNER_VERSION=v2.0.0 |
| ARG TRIVY_VERSION=0.58.1 |
| COPY scripts/install-common.sh /tmp/install-common.sh # buildkit |
| RUN |5 NODE_MAJOR=24 GITLEAKS_VERSION=v8.18.4 SEMGREP_VERSION=1.86.0 OSV_SCANNER_VERSION=v2.5.0 TRIVY_VERSION=0.73.0 /bin/bash -eo pipefail -c NODE_MAJOR=${NODE_MAJOR} bash /tmp/install-common.sh && rm /tmp/install-common.sh # buildkit |
| RUN |5 NODE_MAJOR=24 GITLEAKS_VERSION=v8.18.4 SEMGREP_VERSION=1.86.0 OSV_SCANNER_VERSION=v2.5.0 TRIVY_VERSION=0.73.0 /bin/bash -eo pipefail -c GITLEAKS_NOV="${GITLEAKS_VERSION#v}" && curl -fsSL "https://github.com/gitleaks/gitleaks/releases/download/${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_NOV}_linux_x64.tar.gz" -o /tmp/gitleaks.tar.gz && tar -xzf /tmp/gitleaks.tar.gz -C /usr/local/bin gitleaks && chmod +x /usr/local/bin/gitleaks && rm /tmp/gitleaks.tar.gz # buildkit |
| RUN |5 NODE_MAJOR=24 GITLEAKS_VERSION=v8.18.4 SEMGREP_VERSION=1.86.0 OSV_SCANNER_VERSION=v2.5.0 TRIVY_VERSION=0.73.0 /bin/bash -eo pipefail -c pip install --no-cache-dir "setuptools<81" "semgrep==${SEMGREP_VERSION}" # buildkit |
| RUN |5 NODE_MAJOR=24 GITLEAKS_VERSION=v8.18.4 SEMGREP_VERSION=1.86.0 OSV_SCANNER_VERSION=v2.5.0 TRIVY_VERSION=0.73.0 /bin/bash -eo pipefail -c OSV_NOV="${OSV_SCANNER_VERSION#v}" && { curl -fsSL "https://github.com/google/osv-scanner/releases/download/${OSV_SCANNER_VERSION}/osv-scanner_linux_amd64" -o /usr/local/bin/osv-scanner || curl -fsSL "https://github.com/google/osv-scanner/releases/download/${OSV_SCANNER_VERSION}/osv-scanner_${OSV_NOV}_linux_amd64" -o /usr/local/bin/osv-scanner ; } && chmod +x /usr/local/bin/osv-scanner # buildkit |
| RUN |5 NODE_MAJOR=24 GITLEAKS_VERSION=v8.18.4 SEMGREP_VERSION=1.86.0 OSV_SCANNER_VERSION=v2.5.0 TRIVY_VERSION=0.73.0 /bin/bash -eo pipefail -c curl -fsSL "https://github.com/aquasecurity/trivy/releases/download/v${TRIVY_VERSION}/trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz" -o /tmp/trivy.tar.gz && tar -xzf /tmp/trivy.tar.gz -C /usr/local/bin trivy && rm /tmp/trivy.tar.gz # buildkit |
| COPY security-rules/ /opt/security-rules/ # buildkit |
| ENV PIP_NO_CACHE_DIR=1 PIP_DISABLE_PIP_VERSION_CHECK=1 FABLED_SECURITY_RULES=/opt/security-rules |
| RUN |5 NODE_MAJOR=24 GITLEAKS_VERSION=v8.18.4 SEMGREP_VERSION=1.86.0 OSV_SCANNER_VERSION=v2.5.0 TRIVY_VERSION=0.73.0 /bin/bash -eo pipefail -c gitleaks version && semgrep --version && osv-scanner --version && trivy --version && node --version && git --version && test -f /opt/security-rules/semgrep-family.yml && test -f /opt/security-rules/gitleaks-family.toml && semgrep --validate --config /opt/security-rules/semgrep-family.yml # buildkit |
Labels
| Key | Value |
|---|---|
| org.opencontainers.image.description | CI image: FabledSentry scanner toolchain (gitleaks + semgrep + osv-scanner + trivy) |
| org.opencontainers.image.licenses | MIT |
| org.opencontainers.image.source | https://git.fabledsword.com/bvandeusen/CI-runner |