# Offline localhost validation results

Completed 2026-09-11 on AlmaLinux 9.8 x86_64.

**Functional tests passed with networking disabled. The bundled ZAP image failed
both vulnerability release gates. The local web fixture produced ZAP warnings.**

| Check | Result | Evidence |
|---|---|---|
| Entire bundle SHA256 verification | PASS, exit 0 | integrity.log |
| Native offline acceptance | PASS, exit 0 | offline-acceptance.log |
| Gitleaks synthetic secret | Detected; expected failing gate | offline-acceptance.log |
| Trivy vulnerable Python fixture and SBOM | Detected; CycloneDX parsed | offline-acceptance.log |
| Syft inventory and Grype fixture gate | requests identified; High/Critical blocked with exit 2 | offline-acceptance.log |
| Clean Grype fixture / missing DB | Clean input accepted; missing database rejected | offline-acceptance.log |
| Cosign signature and tamper rejection | PASS | offline-acceptance.log |
| Trivy scan of bundled ZAP archive | Scan works; release gate BLOCKED, exit 1 | trivy-image/trivy-image.json |
| Syft/Grype scan of bundled ZAP archive | Scan works; release gate BLOCKED, exit 2 | grype-image/grype.json |
| Image CycloneDX SBOMs | Both parsed with nonempty component inventories | trivy-image/image.cdx.json, grype-image/sbom.cdx.json |
| Offline Podman image import | PASS | container-load.log |
| Container adapter | Smoke, signing, tamper rejection, evidence packaging PASS | container-adapter.log |
| ZAP localhost crawl and report generation | Functional PASS; baseline exit 2 for 3 WARN rules | zap-localhost.log, zap-reports/zap.html |
| ZAP container isolation | NetworkMode=none, no published application port | zap-container-inspect.json |

## Security findings

Scanned `my-devsecops/images/zap-stable-amd64.tar`, not a user application.

| Scanner | High/Critical matches | Unique advisory IDs within those matches | Matches with a fixed version listed |
|---|---:|---:|---:|
| Trivy | 509 | 339 | 108 |
| Grype | 451 | 209 | 102 |

Counts overlap across tools and packages; do not add them to get a vulnerability
total. Differences in inventory and matching rules are expected. These are
scanner findings requiring triage, not confirmed exploitable vulnerabilities.
The existing severity gates correctly prevented approval. Review the full JSON
reports and update/rebuild the scanner's base image, bundled packages and add-ons
on a connected staging station before reimport and retest. Merely passing this
functional harness does not waive findings or approve the image for deployment.

ZAP scanned only the disposable Python HTTP page at `http://127.0.0.1:8765`.
It reported missing X-Content-Type-Options, server-version disclosure and missing
Content-Security-Policy. Those three WARN rules produced baseline exit 2, which
would block the default release gate. The harness intentionally accepts expected
fixture findings while requiring successful crawling and valid reports.

The native scans used Trivy DB UpdatedAt 2026-09-08T19:09:56.811508+00:00,
Java DB UpdatedAt 2026-09-09T01:11:59.619689+00:00, and the Grype snapshot built
2026-09-10T06:30:24Z. Default freshness checks remained enabled. No Internet
access or data refresh was needed for these tests.

## Scope and remaining validation

This demonstrates standalone offline scanner execution, archive scanning,
container operation and localhost passive DAST. It does not validate RHEL 9.6
RPM installation, OpenSCAP profiles, SELinux/FIPS behavior on the target, actual
application coverage, authenticated/active DAST, or Jira/Gitea/Drone/SonarQube/
openQA integration. Those services were not configured or exercised by this test.

The inherited scanner container includes Gitleaks, Trivy, Cosign and ZAP;
Syft/Grype were tested using the newer native bundle binaries. This test does not
claim that the inherited container contains Syft/Grype.

See [README.md](README.md) for exact repeat commands and isolation details.
