Skip to content

Commit 80bb659

Browse files
committed
ci(osv-scanner): fix argument list too long error
1 parent 640567c commit 80bb659

2 files changed

Lines changed: 33 additions & 36 deletions

File tree

‎.github/workflows/osv-scanner-pr.yml‎

Lines changed: 12 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -30,39 +30,37 @@ jobs:
3030
actions: read
3131
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@a345acffa64b0eaede81a3d9aae6141214d9c8fc" # v2.6.0
3232
with:
33-
export-results: true
3433
fail-on-vuln: false
3534
check:
3635
runs-on: ubuntu-latest
3736
needs: osv-scanner-pr
3837
steps:
38+
# The results are read from the uploaded artifacts rather than from the
39+
# reusable workflow's job outputs: a large output passed to a step via
40+
# env (or inline) exceeds the kernel's per-string exec limit and the
41+
# runner fails to start bash with "Argument list too long".
42+
- name: Download OSV scan results
43+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
44+
with:
45+
pattern: "*-json-results"
46+
merge-multiple: true
47+
path: ${{ runner.temp }}/osv
3948
- name: Check OSV scan results
4049
shell: bash
41-
env:
42-
# Passed through the environment rather than interpolated into the
43-
# script body. The runner injects these out-of-band, so the scanner
44-
# JSON can never break out of the surrounding shell context no matter
45-
# what it contains or how large it is.
46-
NEW_RESULTS: ${{ needs.osv-scanner-pr.outputs.new-results }}
47-
OLD_RESULTS: ${{ needs.osv-scanner-pr.outputs.old-results }}
4850
run: |
4951
set -euo pipefail
5052
IFS=$'\n\t'
51-
# printf is a bash builtin, so the (potentially very large) values are
52-
# written to disk without hitting the ARG_MAX command-line limit.
53-
printf '%s' "${NEW_RESULTS}" > "${RUNNER_TEMP}/new_results.json"
54-
printf '%s' "${OLD_RESULTS}" > "${RUNNER_TEMP}/old_results.json"
5553
# Fail if any vulnerability present in the new results is absent from
5654
# the old results, i.e. the PR introduces it. Read via process
5755
# substitution rather than a pipe so the rc assignment is not lost in
5856
# a subshell, and use a fixed-string match for the exact vuln id.
5957
rc=0
6058
while read -r vid; do
61-
if ! grep -qF -e "\"${vid}\"" "${RUNNER_TEMP}/old_results.json"; then
59+
if ! grep -qF -e "\"${vid}\"" "${RUNNER_TEMP}/osv/old-results.json"; then
6260
rc=1
6361
>&2 echo "error: PR introduces new vulnerability ${vid} (see step 'scan > osv-scanner-pr > Run osv-scanner-reporter' for details)"
6462
fi
65-
done < <(jq -r '.results[]?.packages[]?.vulnerabilities[]?.id' "${RUNNER_TEMP}/new_results.json")
63+
done < <(jq -r '.results[]?.packages[]?.vulnerabilities[]?.id' "${RUNNER_TEMP}/osv/new-results.json")
6664
if [ "${rc}" -ne 0 ]; then
6765
exit 1
6866
fi

‎.github/workflows/osv-scanner.yml‎

Lines changed: 21 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -32,38 +32,37 @@ jobs:
3232
actions: read
3333
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@a345acffa64b0eaede81a3d9aae6141214d9c8fc" # v2.6.0
3434
with:
35-
export-results: true
3635
fail-on-vuln: false
3736
check:
3837
runs-on: ubuntu-latest
3938
needs: osv-scanner
4039
steps:
40+
# The results are read from the uploaded artifact rather than from the
41+
# reusable workflow's job outputs: a large output passed to a step via
42+
# env (or inline) exceeds the kernel's per-string exec limit and the
43+
# runner fails to start bash with "Argument list too long".
44+
- name: Download OSV scan results
45+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
46+
with:
47+
name: OSV Scanner SARIF file
48+
path: ${{ runner.temp }}/osv
4149
- name: Check OSV scan results
4250
shell: bash
43-
env:
44-
# Passed through the environment rather than interpolated into the
45-
# script body. The runner injects this out-of-band, so the scanner
46-
# JSON can never break out of the surrounding shell context no matter
47-
# what it contains or how large it is.
48-
RESULTS: ${{ needs.osv-scanner.outputs.results }}
4951
run: |
5052
set -euo pipefail
5153
IFS=$'\n\t'
52-
# printf is a bash builtin, so the (potentially very large) value is
53-
# written to disk without hitting the ARG_MAX command-line limit.
54-
printf '%s' "${RESULTS}" > "${RUNNER_TEMP}/results.json"
55-
# jq expression:
56-
# - iterate packages -> vulnerabilities -> full osv entry -> severity[] (type, score)
57-
# - extract numeric scores for CVSS types (cvss_v3 or numeric severity[].score)
58-
# - compare to threshold
59-
if jq '
60-
.results[]
61-
| .packages[]?
62-
| .vulnerabilities[]?
63-
| ( .severity[]?.score // "" ) as $s
64-
| select($s != "")
65-
| ($s | tonumber) >= 4.0
66-
' "${RUNNER_TEMP}/results.json" | grep -q -e . ; then
54+
# Each rule in the SARIF report is a vulnerability found by the scan,
55+
# with its worst numeric CVSS score in the security-severity property.
56+
# A jq failure (e.g. missing or malformed report) aborts the step via
57+
# set -e instead of being mistaken for "no vulnerabilities".
58+
count="$(jq '
59+
[ .runs[].tool.driver.rules[]?
60+
| .properties["security-severity"] // empty
61+
| tonumber
62+
| select(. >= 4.0) ]
63+
| length
64+
' "${RUNNER_TEMP}/osv/results.sarif")"
65+
if [ "${count}" -gt 0 ]; then
6766
>&2 echo "error: found one or more vulnerabilities with a medium or higher severity (see step 'scan > osv-scanner > Run osv-scanner-reporter' for details)"
6867
exit 1
6968
fi

0 commit comments

Comments
 (0)