fix(security): scope Trivy private-key ignore to vendored openssl doc (false positive) - #116
Conversation
Trivy's Secret scanner flags 2x HIGH AsymmetricPrivateKey (rule id:
private-key) in
packrat/lib/x86_64-pc-linux-gnu/3.4.1/openssl/doc/keys.html. That file is
vendored upstream documentation for the R "openssl" package; the PEM blocks
are EXAMPLE keys emitted by the doc's own write_pem() demonstration, not a
live credential. This is a false positive.
Add a path-scoped, documented suppression instead of globally disabling the
rule:
- .trivyignore.yaml scopes the `private-key` ignore to
packrat/lib/**/openssl/doc/keys.html only.
- trivy.yaml sets `ignorefile: .trivyignore.yaml` so the YAML ignore is
applied on a bare `trivy fs .` (Trivy 0.71.x auto-detects only a plain,
non-path-scoped .trivyignore).
Real private keys committed anywhere else in the repo still fail the scan
(verified: same key content at another path still reports HIGH).
Local verification (trivy 0.71.1, fresh DB):
trivy fs . --scanners vuln,secret,misconfig --severity CRITICAL,HIGH --ignore-unfixed
before: 2 HIGH private-key after: 0 (no new CRITICAL/HIGH introduced)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RTAMs4bpSZS77Xe3RQjv9P
OpenCode Review Overview
Pull request overviewOpenCode reviewed the current-head bounded evidence and found no blocking issues. FindingsNo blocking findings. SummaryApproval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (2 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (2 files)"]
R1 --> V1["required checks"]
|
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head bounded evidence and found no blocking issues.
Findings
No blocking findings.
Summary
Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including .trivyignore.yaml, trivy.yaml.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports test coverage as not applicable because no supported changed source files or package manifests were found.
Docstring coverage: coverage execution evidence reports docstring coverage as not applicable because no supported changed source files or package manifests were found.
DAG: CodeGraph/source-backed behavior map connects .trivyignore.yaml to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source checks are delegated to configured OpenCode web_search/Context7/DeepWiki sources when applicable; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: Playwright visual, DOM locator, ARIA snapshot, console, and responsive evidence were checked when a web UI surface was present; for non-web surfaces, API/CLI/log/docs/workflow interaction evidence was reviewed instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.
- Result: APPROVE
- Reason: The PR addresses a false positive in Trivy's secret scanner by scoping the private-key ignore to vendored OpenSSL documentation, which is a valid and safe change.
- Head SHA:
2fe1dd127cdce16fade77478d2ee59c43da1c88d - Workflow run: 28900616041
- Workflow attempt: 1
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (2 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (2 files)"]
R1 --> V1["required checks"]
Brings the scoped Trivy private-key suppression (trivy.yaml + .trivyignore.yaml, #116) so the required trivy-fs gate stops failing on the vendored openssl doc example key (verified false positive). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RTAMs4bpSZS77Xe3RQjv9P
Brings the scoped Trivy private-key suppression (trivy.yaml + .trivyignore.yaml, #116) so the required trivy-fs gate stops failing on the vendored openssl doc example key (verified false positive). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RTAMs4bpSZS77Xe3RQjv9P
Brings the scoped Trivy private-key suppression (trivy.yaml + .trivyignore.yaml, #116) so the required trivy-fs gate stops failing on the vendored openssl doc example key (verified false positive). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RTAMs4bpSZS77Xe3RQjv9P
Brings the scoped Trivy private-key suppression (trivy.yaml + .trivyignore.yaml, #116) so the required trivy-fs gate stops failing on the vendored openssl doc example key (verified false positive). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RTAMs4bpSZS77Xe3RQjv9P
Finding
Trivy's Secret scanner reports 2× HIGH
AsymmetricPrivateKey(rule id:private-key) in:This file is vendored upstream documentation for the R
opensslpackage (checked in underpackrat/for reproducible builds). The PEM blocks are example keys printed by the doc's ownwrite_pem()demonstration — published upstream example material, not a live credential. It is a false positive.Fix
A path-scoped, documented suppression — not a global disable of the rule:
.trivyignore.yaml— ignores ruleprivate-keyforpackrat/lib/**/openssl/doc/keys.htmlonly.trivy.yaml— setsignorefile: .trivyignore.yamlso the YAML ignore applies on a baretrivy fs .. (Trivy 0.71.x auto-detects only a plain, line-based.trivyignore, which cannot scope a rule to a path; thetrivy.yamlcompanion is what enables path scoping without weakening detection elsewhere.)Real private keys committed anywhere else in the repo still fail the scan — verified by copying the same key content to another path, which still reports HIGH.
Local verification (Trivy 0.71.1, fresh vuln DB)
Command (identical before and after):
No application/build/runtime behavior is affected — only scanner configuration is added.
🤖 Generated with Claude Code