build(infra): run ClamAV in compose and on the cluster (closes #191) #193

Merged
not merged 5 commits from build/191-clamav into main 2026-10-02 07:53:17 +00:00
Showing only changes of commit f93b4a4426 - Show all commits
@@ -33,8 +33,10 @@ and that makes it an ADR (CLAUDE.md §14).
**no NuGet package** for it (nClam and similar). **no NuGet package** for it (nClam and similar).
4. **Fail closed:** if clamd can't be reached, the upload is refused (503). Nothing is 4. **Fail closed:** if clamd can't be reached, the upload is refused (503). Nothing is
stored and the document wait stays open. We never store an unscanned file. stored and the document wait stays open. We never store an unscanned file.
5. **Type check:** content must start with `%PDF-`. This refuses a renamed executable 5. **Type check:** content must also start with `%PDF-`, checked **after** the scan.
before the scan, and it costs nothing. clamd matches EICAR (and many real signatures) only at the start of a file, so a type
check in front of the scan would report malware as merely "not a PDF". The check also
refuses a renamed non-PDF that is clean.
## Consequences ## Consequences