The mirror created the seven issues that had never reached the board (management#33-39) and wrote each new iid back into its file. Without the writeback the next run would create duplicates instead of recognising its own work. Group check after the run: the issue drift class is empty - 27 findings down to 20, 7 hints to 0, and not a single GitLab issue without a canonical file. What remains is unrelated to the board: seventeen commit-hygiene findings parked in #0053 and three component declarations. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1.4 KiB
1.4 KiB
type, id, status, created, milestone, priority, area, related, gitlab_iid
| type | id | status | created | milestone | priority | area | related | gitlab_iid | ||
|---|---|---|---|---|---|---|---|---|---|---|
| issue | 0051 | open | 2026-08-14 | M5 | high | security |
|
37 |
CVE-Remediation-Pass: Schwachstellen-Report abarbeiten
Problem / Motivation
Die Trivy-CVE-Pipeline meldet über 29 Images ~5400 CVEs (126 CRITICAL, 1222 HIGH, Rest
MEDIUM/LOW), Spitzenreiter goauthentik/server:2026.2.3 mit 369 CRIT+HIGH. #0025 deckt
nur die Alarm-Zustellung ab — die eigentliche Behebung fehlte als eigenes Issue.
Acceptance
- Nach Schwere × Fixbarkeit priorisiert (CRITICAL zuerst; „fixed available" vor
won't-fix; exponiert vor intern) — Methode als Runbook
/betrieb/sicherheitim Wiki. - Top-Offender mit verfügbarem Fix behoben: v.a. Authentik-Update (mit Backup), eigene
Images (
axion-backup,axion-secret-rotation,clamav-http-scanner) auf aktueller Base neu gebaut, ESS-Bump → Delta im Grafana-CVE-Dashboard sichtbar. - won't-fix / nicht-exponierte CVEs mitigiert oder in
.trivyignoremit Begründung + Review-Datum suppress-t. - Re-Scan zeigt deutlich gesunkene CRITICAL/HIGH.
Notes
Hängt eng an der Update-Kadenz (#0052) — Updaten ist der Haupthebel gegen die CVEs.
Methode/Runbook: /betrieb/sicherheit; Update-Prozess: /betrieb/upgrades.