Skip to content

fix: resolve sonarqube security findings#1373

Merged
Ron (rjaegers) merged 12 commits into
mainfrom
fix/resolve-sonarqube-security-findings
Jul 21, 2026
Merged

fix: resolve sonarqube security findings#1373
Ron (rjaegers) merged 12 commits into
mainfrom
fix/resolve-sonarqube-security-findings

Conversation

@rjaegers

@rjaegers Ron (rjaegers) commented Jul 21, 2026

Copy link
Copy Markdown
Member

🚀 Hey, I have created a Pull Request

Description of changes

This pull request updates the development container Dockerfiles for C++ and Rust to improve supply chain security, reproducibility, and consistency in dependency management. It also makes minor improvements to GitHub Actions workflows. The most important changes are grouped below.

C++ Devcontainer Improvements:

  • Added explicit version pinning and checksum verification for CPM.cmake and include-what-you-use (IWYU) by downloading these dependencies in the Docker build and installing from local sources, rather than fetching at build time. This improves reproducibility and supply chain security. [1] [2] [3] [4] [5] [6]
  • Improved installation steps for binaries (e.g., ccache, xwin) by using install -m 0755 instead of cp, ensuring correct permissions.
  • Updated update-alternatives commands to use quoted paths for improved safety.

Rust Devcontainer Improvements:

  • Switched to downloading, verifying (with minisign), and installing a prebuilt cargo-binstall binary with checksum validation, instead of fetching and extracting directly from GitHub. This enhances supply chain security and reproducibility. [1] [2] [3] [4]
  • Updated environment and path references to match the new installation location for cargo-binstall.
  • Minor quoting improvements for variable usage.

CI Workflow Improvements:

  • Updated npm install and npm ci commands in GitHub Actions to use --ignore-scripts, improving CI security by preventing arbitrary script execution during dependency installation. [1] [2]
  • Updated the diffoci tool to version 0.1.8 with checksum verification in the build workflow, improving security and reliability of image comparison.

✔️ Checklist

  • I have followed the contribution guidelines for this repository
  • I have added tests for new behavior, and have not broken any existing tests
  • I have added or updated relevant documentation
  • I have verified that all added components are accounted for in the SBOM
  • I understand the image size delta and agree the functionality justifies it

Copilot AI review requested due to automatic review settings July 21, 2026 09:29
@rjaegers
Ron (rjaegers) requested a review from a team as a code owner July 21, 2026 09:29

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aims to address SonarQube security findings by hardening dependency installation steps in GitHub Actions and tightening wget behavior in devcontainer Dockerfiles and workflows.

Changes:

  • Updates npm install/ci steps to use --ignore-scripts in CI/action contexts.
  • Modifies multiple wget invocations (and bumps diffoci to v0.1.8) to add redirect-related flags.
  • Adjusts devcontainer build download steps for Rust and C++ flavors.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
.github/workflows/wc-build-push.yml Bumps diffoci download and changes wget flags used during container diff generation.
.github/workflows/wc-acceptance-test.yml Runs npm ci with --ignore-scripts before Playwright installation.
.github/actions/container-size-diff/action.yml Runs npm install with --ignore-scripts for the composite action’s runtime deps.
.devcontainer/rust/Dockerfile Changes wget flags for downloading/extracting cargo-binstall.
.devcontainer/cpp/Dockerfile Changes wget flags for downloading ARM toolchain, IWYU source, and CPM.cmake.

Comment thread .github/workflows/wc-build-push.yml Outdated
Comment thread .devcontainer/rust/Dockerfile Outdated
Comment thread .devcontainer/cpp/Dockerfile Outdated
Comment thread .devcontainer/cpp/Dockerfile Outdated
Comment thread .devcontainer/cpp/Dockerfile Outdated
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Test Results

 25 files  ±0   25 suites  ±0   19m 53s ⏱️ + 1m 47s
 48 tests ±0   48 ✅ ±0  0 💤 ±0  0 ❌ ±0 
201 runs  ±0  201 ✅ ±0  0 💤 ±0  0 ❌ ±0 

Results for commit a1a9077. ± Comparison against base commit 6eb6ce8.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 23 0 0 0.27s
✅ DOCKERFILE hadolint 4 0 0 0.3s
✅ JSON npm-package-json-lint yes no no 0.51s
✅ JSON prettier 44 6 0 0 0.86s
✅ JSON v8r 44 0 0 17.19s
✅ MARKDOWN markdownlint 13 0 0 0 1.17s
✅ MARKDOWN markdown-table-formatter 13 0 0 0 0.34s
✅ REPOSITORY betterleaks yes no no 1.53s
✅ REPOSITORY checkov yes no no 30.0s
✅ REPOSITORY gitleaks yes no no 1.17s
✅ REPOSITORY git_diff yes no no 0.01s
✅ REPOSITORY grype yes no no 67.94s
⚠️ REPOSITORY osv-scanner yes 1 no 0.78s
✅ REPOSITORY secretlint yes no no 2.45s
✅ REPOSITORY syft yes no no 2.79s
✅ REPOSITORY trivy yes no no 15.1s
✅ REPOSITORY trivy-sbom yes no no 0.4s
✅ REPOSITORY trufflehog yes no no 6.79s
⚠️ SPELL lychee 113 1 0 29.91s
✅ YAML prettier 33 0 0 0 1.38s
✅ YAML v8r 33 0 0 15.11s
✅ YAML yamllint 33 0 0 1.36s

Detailed Issues

⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........154
🔗 Unique.........126
✅ Successful.....148
⏳ Timeouts.........0
🔀 Redirected......19
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden

Hint: Followed 19 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 1 error
Scanning dir .
Starting filesystem walk for root: /
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned .devcontainer/docs/requirements.txt file and found 14 packages
Scanned test/embedded-rust/workspace/cortex-m/Cargo.lock file and found 20 packages
Scanned test/embedded-rust/workspace/cortex-mf/Cargo.lock file and found 20 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned package-lock.json file and found 73 packages
End status: 105 dirs visited, 342 inodes visited, 8 Extract calls, 33.352706ms elapsed, 33.352906ms wall time

Total 2 packages affected by 2 known vulnerabilities (0 Critical, 0 High, 0 Medium, 0 Low, 2 Unknown) from 1 ecosystem.
0 vulnerabilities can be fixed.

+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+
| OSV URL                           | CVSS | ECOSYSTEM | PACKAGE    | VERSION | FIXED VERSION | SOURCE                                            |
+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+
| https://osv.dev/RUSTSEC-2026-0110 |      | crates.io | bare-metal | 0.2.5   | --            | test/embedded-rust/workspace/cortex-m/Cargo.lock  |
| https://osv.dev/RUSTSEC-2026-0110 |      | crates.io | bare-metal | 0.2.5   | --            | test/embedded-rust/workspace/cortex-mf/Cargo.lock |
+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-base:edgeghcr.io/philips-software/amp-devcontainer-base:pr-1373

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 75.35 MB 75.35 MB +15 B (+0%) 🔼
linux/arm64 73.43 MB 73.43 MB 86 B (0%) 🔽

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-docs:edgeghcr.io/philips-software/amp-devcontainer-docs:pr-1373

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 200.14 MB 200.14 MB +171 B (+0%) 🔼
linux/arm64 196.35 MB 196.35 MB 167 B (0%) 🔽

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-rust:edgeghcr.io/philips-software/amp-devcontainer-embedded-rust:pr-1373

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 469.09 MB 468.96 MB 127.22 kB (-0.03%) 🔽
linux/arm64 419.91 MB 419.92 MB +5.38 kB (+0%) 🔼

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-cpp:edgeghcr.io/philips-software/amp-devcontainer-cpp:pr-1373

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 372.13 MB 372.13 MB 165 B (0%) 🔽
linux/arm64 352.26 MB 352.26 MB +4.07 kB (+0%) 🔼

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-rust:edgeghcr.io/philips-software/amp-devcontainer-rust:pr-1373

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 406.01 MB 406.07 MB +52.9 kB (+0.01%) 🔼
linux/arm64 357.6 MB 357.66 MB +67.15 kB (+0.02%) 🔼

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-cpp:edgeghcr.io/philips-software/amp-devcontainer-embedded-cpp:pr-1373

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 560.5 MB 560.5 MB +879 B (+0%) 🔼
linux/arm64 538.95 MB 538.95 MB +3.6 kB (+0%) 🔼

@rjaegers
Ron (rjaegers) temporarily deployed to acceptance-testing July 21, 2026 10:22 — with GitHub Actions Inactive
@rjaegers
Ron (rjaegers) temporarily deployed to acceptance-testing July 21, 2026 11:03 — with GitHub Actions Inactive
wget's --https-only does not work for single file downloads, it only works in recursive mode
Comment thread .devcontainer/rust/Dockerfile Fixed
@rjaegers
Ron (rjaegers) temporarily deployed to acceptance-testing July 21, 2026 14:09 — with GitHub Actions Inactive
Comment thread .devcontainer/cpp/Dockerfile Fixed
@rjaegers
Ron (rjaegers) temporarily deployed to acceptance-testing July 21, 2026 15:04 — with GitHub Actions Inactive
@sonarqubecloud

Copy link
Copy Markdown

@rjaegers
Ron (rjaegers) temporarily deployed to acceptance-testing July 21, 2026 15:24 — with GitHub Actions Inactive
@rjaegers
Ron (rjaegers) added this pull request to the merge queue Jul 21, 2026
Merged via the queue into main with commit a18bcf8 Jul 21, 2026
92 checks passed
@rjaegers
Ron (rjaegers) deleted the fix/resolve-sonarqube-security-findings branch July 21, 2026 16:03
@github-actions

Copy link
Copy Markdown
Contributor

Pull Request Report (#1373)

Static measures

Description Value
Number of added lines 87
Number of deleted lines 22
Number of changed files 5
Number of commits 12
Number of reviews 4
Number of comments (w/o review comments) 9
Number of reviews that contains a comment to resolve 3
Number of reviews that requested a change from the author 0
Number of reviews that approved the Pull Request 1
Get the total number of participants of a Pull Request 6

Time related measures

Description Value
PR lead time (from creation to close of PR) 6.6 Hours
Time that was spend on the branch before the PR was created 14 Sec
Time that was spend on the branch before the PR was merged 6.6 Hours
Time to merge after last review 39.5 Min

Status check related measures

Description Value
Total runtime for last status check run (Workflow for PR) 1.7 Hours
Total time spend in last status check run on PR 21.2 Min

@github-actions

Copy link
Copy Markdown
Contributor

🎉 Hooray! The changes in this pull request went live with the release of v8.0.1 🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants