feat(security): renforcement de la chaine de confiance et validation hermetique #1

Merged
durandal-admin merged 1 commit from feature/slsa-scorecard into main 2026-09-17 14:29:16 +00:00

Cette Pull Request active le controle automatise par DURANDAL Sovereign Software Factory :

  • Detection de secrets par Gitleaks
  • Analyse statique SAST par OpenGrep
  • Execution des tests unitaires hermetiques par Pytest
  • Scan de vulnerabilites CVE par Trivy
  • Generation de la nomenclature logicielle (SBOM) CycloneDX par Syft
  • Attestation cryptographique signee SLSA Build Level 3 par Tekton Chains
Cette Pull Request active le controle automatise par **DURANDAL Sovereign Software Factory** : - Detection de secrets par Gitleaks - Analyse statique SAST par OpenGrep - Execution des tests unitaires hermetiques par Pytest - Scan de vulnerabilites CVE par Trivy - Generation de la nomenclature logicielle (SBOM) CycloneDX par Syft - Attestation cryptographique signee SLSA Build Level 3 par Tekton Chains
feat(api): add /api/info endpoint and SLSA Level 3 validation tests
All checks were successful
durandal/secrets Gitleaks: 0 secret detecte (Succes)
durandal/sast OpenGrep: 0 probleme de securite dans le code source
durandal/tests Pytest: 100% des tests unitaires valides
durandal/vulnerabilities Trivy: 0 CVE critique (Crit: 0, High: 0, Med: 0)
durandal/sbom Syft: SBOM CycloneDX 1.5 (0 composants)
durandal/slsa-provenance Tekton Chains: Signature ECDSA-P256 & Transparence Rekor (SLSA L3)
durandal/pipeline DURANDAL CI Pipeline reussi (SLSA Build Level 3)
80771c6627
Author
Owner

🛡️ DURANDAL Sovereign Software Factory — Security Scorecard

PipelineRun : demo-backend-pr1-7klzs | Commit : 80771c66 | SLSA Niveau : Build Level 3

Contrôle de Sécurité Moteur / Outil Statut Résultat & Métriques
Fuite de Secrets Gitleaks v8.21.2 CONFORME 0 secret ou token dans le code source
Analyse Statique (SAST) OpenGrep / Semgrep OSS CONFORME 0 faiblesse CWE detectee
Hermétisme & Tests Pytest 8.3 (Python 3.12) ECHEC Tests executes en conteneur hermetique
Scan de Vulnérabilités Aqua Trivy 0.58.1 CONFORME 0 CVE bloquante (C:0, H:0, M:0)
Nomenclature Logicielle (SBOM) Anchore Syft 1.18 CONFORME CycloneDX 1.5 JSON (0 composants)
Attestation Cryptographique Tekton Chains + Cosign + Rekor CERTIFIÉ SLSA Build Level 3 in-toto statement enregistre

📦 Artefact OCI : harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0
🔐 Digest Immuable : sha256-verified
📜 Vérification Cosign :

cosign verify --key k8s://tekton-ci/signing-secrets harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0

Consulter les logs d'exécution sur Tekton Dashboard

### 🛡️ DURANDAL Sovereign Software Factory — Security Scorecard **PipelineRun** : `demo-backend-pr1-7klzs` | **Commit** : `80771c66` | **SLSA Niveau** : **Build Level 3** | Contrôle de Sécurité | Moteur / Outil | Statut | Résultat & Métriques | | :--- | :--- | :---: | :--- | | **Fuite de Secrets** | `Gitleaks v8.21.2` | ✅ CONFORME | 0 secret ou token dans le code source | | **Analyse Statique (SAST)** | `OpenGrep / Semgrep OSS` | ✅ CONFORME | 0 faiblesse CWE detectee | | **Hermétisme & Tests** | `Pytest 8.3 (Python 3.12)` | ❌ ECHEC | Tests executes en conteneur hermetique | | **Scan de Vulnérabilités** | `Aqua Trivy 0.58.1` | ✅ CONFORME | 0 CVE bloquante (C:0, H:0, M:0) | | **Nomenclature Logicielle (SBOM)** | `Anchore Syft 1.18` | ✅ CONFORME | CycloneDX 1.5 JSON (0 composants) | | **Attestation Cryptographique** | `Tekton Chains + Cosign + Rekor` | ✅ CERTIFIÉ | SLSA Build Level 3 in-toto statement enregistre | > 📦 **Artefact OCI** : `harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0` > 🔐 **Digest Immuable** : `sha256-verified` > 📜 **Vérification Cosign** : > ```bash > cosign verify --key k8s://tekton-ci/signing-secrets harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0 > ``` [Consulter les logs d'exécution sur Tekton Dashboard](https://tekton.durandal.aosc-portal.com/#/namespaces/tekton-ci/pipelineruns/demo-backend-pr1-7klzs)
Author
Owner

🛡️ DURANDAL Sovereign Software Factory — Security Scorecard

PipelineRun : demo-backend-pr1-run2-fmkml | Commit : 80771c66 | SLSA Niveau : Build Level 3

Contrôle de Sécurité Moteur / Outil Statut Résultat & Métriques
Fuite de Secrets Gitleaks v8.21.2 CONFORME 0 secret ou token dans le code source
Analyse Statique (SAST) OpenGrep / Semgrep OSS CONFORME 0 faiblesse CWE detectee
Hermétisme & Tests Pytest 8.3 (Python 3.12) ECHEC Tests executes en conteneur hermetique
Scan de Vulnérabilités Aqua Trivy 0.58.1 CONFORME 0 CVE bloquante (C:0, H:0, M:0)
Nomenclature Logicielle (SBOM) Anchore Syft 1.18 CONFORME CycloneDX 1.5 JSON (0 composants)
Attestation Cryptographique Tekton Chains + Cosign + Rekor CERTIFIÉ SLSA Build Level 3 in-toto statement enregistre

📦 Artefact OCI : harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0
🔐 Digest Immuable : sha256-verified
📜 Vérification Cosign :

cosign verify --key k8s://tekton-ci/signing-secrets harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0

Consulter les logs d'exécution sur Tekton Dashboard

### 🛡️ DURANDAL Sovereign Software Factory — Security Scorecard **PipelineRun** : `demo-backend-pr1-run2-fmkml` | **Commit** : `80771c66` | **SLSA Niveau** : **Build Level 3** | Contrôle de Sécurité | Moteur / Outil | Statut | Résultat & Métriques | | :--- | :--- | :---: | :--- | | **Fuite de Secrets** | `Gitleaks v8.21.2` | ✅ CONFORME | 0 secret ou token dans le code source | | **Analyse Statique (SAST)** | `OpenGrep / Semgrep OSS` | ✅ CONFORME | 0 faiblesse CWE detectee | | **Hermétisme & Tests** | `Pytest 8.3 (Python 3.12)` | ❌ ECHEC | Tests executes en conteneur hermetique | | **Scan de Vulnérabilités** | `Aqua Trivy 0.58.1` | ✅ CONFORME | 0 CVE bloquante (C:0, H:0, M:0) | | **Nomenclature Logicielle (SBOM)** | `Anchore Syft 1.18` | ✅ CONFORME | CycloneDX 1.5 JSON (0 composants) | | **Attestation Cryptographique** | `Tekton Chains + Cosign + Rekor` | ✅ CERTIFIÉ | SLSA Build Level 3 in-toto statement enregistre | > 📦 **Artefact OCI** : `harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0` > 🔐 **Digest Immuable** : `sha256-verified` > 📜 **Vérification Cosign** : > ```bash > cosign verify --key k8s://tekton-ci/signing-secrets harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0 > ``` [Consulter les logs d'exécution sur Tekton Dashboard](https://tekton.durandal.aosc-portal.com/#/namespaces/tekton-ci/pipelineruns/demo-backend-pr1-run2-fmkml)
Author
Owner

🛡️ DURANDAL Sovereign Software Factory — Security Scorecard

PipelineRun : demo-backend-pr1-run3-trl85 | Commit : 80771c66 | SLSA Niveau : Build Level 3

Contrôle de Sécurité Moteur / Outil Statut Résultat & Métriques
Fuite de Secrets Gitleaks v8.21.2 CONFORME 0 secret ou token dans le code source
Analyse Statique (SAST) OpenGrep / Semgrep OSS NON CONFORME 5 alertes detectees
Hermétisme & Tests Pytest 8.3 (Python 3.12) CONFORME Tests executes en conteneur hermetique
Scan de Vulnérabilités Aqua Trivy 0.58.1 CONFORME 0 CVE bloquante (C:0, H:0, M:0)
Nomenclature Logicielle (SBOM) Anchore Syft 1.18 CONFORME CycloneDX 1.5 JSON (0 composants)
Attestation Cryptographique Tekton Chains + Cosign + Rekor CERTIFIÉ SLSA Build Level 3 in-toto statement enregistre

📦 Artefact OCI : harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0
🔐 Digest Immuable : sha256:6c97b5476fdd39312a878608ab2bec715482fe8effc33fd0bf487bb76a668ad9
📜 Vérification Cosign :

cosign verify --key k8s://tekton-ci/signing-secrets harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0

Consulter les logs d'exécution sur Tekton Dashboard

### 🛡️ DURANDAL Sovereign Software Factory — Security Scorecard **PipelineRun** : `demo-backend-pr1-run3-trl85` | **Commit** : `80771c66` | **SLSA Niveau** : **Build Level 3** | Contrôle de Sécurité | Moteur / Outil | Statut | Résultat & Métriques | | :--- | :--- | :---: | :--- | | **Fuite de Secrets** | `Gitleaks v8.21.2` | ✅ CONFORME | 0 secret ou token dans le code source | | **Analyse Statique (SAST)** | `OpenGrep / Semgrep OSS` | ❌ NON CONFORME | 5 alertes detectees | | **Hermétisme & Tests** | `Pytest 8.3 (Python 3.12)` | ✅ CONFORME | Tests executes en conteneur hermetique | | **Scan de Vulnérabilités** | `Aqua Trivy 0.58.1` | ✅ CONFORME | 0 CVE bloquante (C:0, H:0, M:0) | | **Nomenclature Logicielle (SBOM)** | `Anchore Syft 1.18` | ✅ CONFORME | CycloneDX 1.5 JSON (0 composants) | | **Attestation Cryptographique** | `Tekton Chains + Cosign + Rekor` | ✅ CERTIFIÉ | SLSA Build Level 3 in-toto statement enregistre | > 📦 **Artefact OCI** : `harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0` > 🔐 **Digest Immuable** : `sha256:6c97b5476fdd39312a878608ab2bec715482fe8effc33fd0bf487bb76a668ad9` > 📜 **Vérification Cosign** : > ```bash > cosign verify --key k8s://tekton-ci/signing-secrets harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0 > ``` [Consulter les logs d'exécution sur Tekton Dashboard](https://tekton.durandal.aosc-portal.com/#/namespaces/tekton-ci/pipelineruns/demo-backend-pr1-run3-trl85)
Author
Owner

🛡️ DURANDAL Sovereign Software Factory — Security Scorecard

PipelineRun : demo-backend-pr1-run4-z9l22 | Commit : 80771c66 | SLSA Niveau : Build Level 3

Contrôle de Sécurité Moteur / Outil Statut Résultat & Métriques
Fuite de Secrets Gitleaks v8.21.2 CONFORME 0 secret ou token dans le code source
Analyse Statique (SAST) OpenGrep / Semgrep OSS CONFORME 0 faiblesse CWE detectee
Hermétisme & Tests Pytest 8.3 (Python 3.12) CONFORME Tests executes en conteneur hermetique
Scan de Vulnérabilités Aqua Trivy 0.58.1 CONFORME 0 CVE bloquante (C:0, H:0, M:0)
Nomenclature Logicielle (SBOM) Anchore Syft 1.18 CONFORME CycloneDX 1.5 JSON (0 composants)
Attestation Cryptographique Tekton Chains + Cosign + Rekor CERTIFIÉ SLSA Build Level 3 in-toto statement enregistre

📦 Artefact OCI : harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0
🔐 Digest Immuable : sha256:b3ba0395bdd34352347c150d649c40f92d1d9a7fb87e7de1ab4c42eaf39049d1
📜 Vérification Cosign :

cosign verify --key k8s://tekton-ci/signing-secrets harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0

Consulter les logs d'exécution sur Tekton Dashboard

### 🛡️ DURANDAL Sovereign Software Factory — Security Scorecard **PipelineRun** : `demo-backend-pr1-run4-z9l22` | **Commit** : `80771c66` | **SLSA Niveau** : **Build Level 3** | Contrôle de Sécurité | Moteur / Outil | Statut | Résultat & Métriques | | :--- | :--- | :---: | :--- | | **Fuite de Secrets** | `Gitleaks v8.21.2` | ✅ CONFORME | 0 secret ou token dans le code source | | **Analyse Statique (SAST)** | `OpenGrep / Semgrep OSS` | ✅ CONFORME | 0 faiblesse CWE detectee | | **Hermétisme & Tests** | `Pytest 8.3 (Python 3.12)` | ✅ CONFORME | Tests executes en conteneur hermetique | | **Scan de Vulnérabilités** | `Aqua Trivy 0.58.1` | ✅ CONFORME | 0 CVE bloquante (C:0, H:0, M:0) | | **Nomenclature Logicielle (SBOM)** | `Anchore Syft 1.18` | ✅ CONFORME | CycloneDX 1.5 JSON (0 composants) | | **Attestation Cryptographique** | `Tekton Chains + Cosign + Rekor` | ✅ CERTIFIÉ | SLSA Build Level 3 in-toto statement enregistre | > 📦 **Artefact OCI** : `harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0` > 🔐 **Digest Immuable** : `sha256:b3ba0395bdd34352347c150d649c40f92d1d9a7fb87e7de1ab4c42eaf39049d1` > 📜 **Vérification Cosign** : > ```bash > cosign verify --key k8s://tekton-ci/signing-secrets harbor.durandal.aosc-portal.com/durandal/demo-backend:v1.1.0 > ``` [Consulter les logs d'exécution sur Tekton Dashboard](https://tekton.durandal.aosc-portal.com/#/namespaces/tekton-ci/pipelineruns/demo-backend-pr1-run4-z9l22)
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
durandal-admin/demo-backend!1
No description provided.