kubernetes / kubernetes/sig-security

[govulncheck] Generate VEX documents from `govulncheck` output

Open
#116 33 comments 2 reactions 0 assignees View on GitHub
area/dependency kind/feature sig/architecture sig/docs sig/release sig/security
Dominant language
Go
Stars
249
Forks
82
Avg merge
7d 12h
Merged PRs (30d)
2

Description

## WHAT
As part of #95 we have now setup `govulncheck` to run on each PR and periodically on master + stable release branches as part of `verify` jobs.

`govulncheck` has now added support for openvex: https://pkg.go.dev/golang.org/x/vuln@v1.1.2/internal/openvex

We should explore if it make sense to add VEX documents as part of each of our releases going forward.

## WHY

This will partially solve the issue of k8s maintainers being requested to provide input on whether a specific CVE is affecting k/k or not by preemptively generating VEX documents for the CVEs where Kubernetes is unaffected. This will also allow us to codify the policy mentioned here: https://github.com/kubernetes/community/blob/6c75205e1b67a84d5784502dd27d1a0e04192021/contributors/devel/sig-release/cherry-picks.md?plain=1#L65

>To illustrate the point, dependency updates that just aim to silence some scanners and do not fix any vulnerable code are NOT eligible for cherry-picks.

Some examples:

https://github.com/kubernetes/kubernetes/issues/121370
https://github.com/kubernetes/kubernetes/issues/122424
https://github.com/kubernetes/kubernetes/issues/119227
https://github.com/kubernetes/kubernetes/issues/122952
and many more before `govulncheck` was introduced

## HOW

We need a trusted way to generate the VEX document, where following properties are desired:

* The VEX document is auto-generated
* The VEX document can be modified if needed by a small trusted list of k8s org members
* The VEX document can not be tampered
* The VEX document generation or modification supports non-repudiation
* The VEX document can be version controlled with git

Open to ideas on the how and we can all explore possible options together.

## WHO

This would need collaboration between SIG Security, Docs, Architecture and Release.

## WHERE

We may potentially host it besides https://kubernetes.io/docs/reference/issues-security/official-cve-feed/ but of course other ideas or placements are welcome!

## NOTES
Part of #3, related https://github.com/kubernetes/kubernetes/issues/121454

## Work being Done

- [ ] https://github.com/kubernetes/kubernetes/pull/125864
- [ ] https://github.com/kubernetes/kubernetes/issues/125863
- [ ] https://github.com/kubernetes/kubernetes/issues/125865

/sig security architecture docs release
/area dependency
/kind feature

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the govulncheck setup from #95, the OpenVEX support in golang.org/x/vuln, and the related work in PR 125864 and issues 125863 and 125865. Compare options for trusted generation, controlled modification, tamper resistance, non-repudiation, and Git versioning; done means an agreed cross-SIG approach for publishing VEX documents.

Written by the indexing model from the issue text.

Assessment

Tech stack
git, go
Domain
documentation, release, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.