From c203267866aa87994de80d2214f70deff72b7b5f Mon Sep 17 00:00:00 2001 From: SnapOtter Date: Sun, 21 Jun 2026 23:23:03 +0800 Subject: [PATCH] fix(docker): patch OS + pip image CVEs, document accepted Trivy residuals (#288) Reduces the container-image CVE surface flagged by Trivy. Genuinely fixed on every rebuild: - apt-get upgrade in the production stage pulls Ubuntu security patches for base-image packages (libgnutls30t64 3.8.3-1.1ubuntu3.5 -> ubuntu3.6, libgcrypt20, liblzma5), closing ~15 OS-package CVEs. - pip 25.1.1 -> 26.1.2 closes 4 pip CVEs (CVE-2025-8869, 2026-1703, 2026-3219, 2026-6357). Accepted via .trivyignore (canonical, reviewed): - 6 newly surfaced pnpm 9.x build-tool CVEs (fixed only in pnpm 10.x, a major migration tracked separately; pnpm runs at install/start only). - caire's bundled golang.org/x/image (esimov/caire v1.5.0 is latest and still pins x/image v0.18.0; no upstream fix). - brace-expansion 2.x ReDoS (transitive of glob; patched 5.0.6 already present; not reachable from user input). Already resolved in the current tree (clear on next scan): picomatch 4.0.4 (override), ip-address removed. Verification note: the Trivy job in release.yml depends on the intentionally gated-off docker build/publish job, so these cannot be re-scanned in CI without enabling image publishing. The image is not currently shipped. --- .trivyignore | 22 ++++++++++++++++++++++ docker/Dockerfile | 6 +++++- 2 files changed, 27 insertions(+), 1 deletion(-) diff --git a/.trivyignore b/.trivyignore index 6dcb3c55..57555172 100644 --- a/.trivyignore +++ b/.trivyignore @@ -26,3 +26,25 @@ CVE-2026-24842 CVE-2026-26960 CVE-2026-29786 CVE-2026-31802 + +# pnpm 9.x core (2026 rescan) -- same build-time-tool rationale as above; every +# one of these is fixed only in pnpm 10.x (10.0.0 / 10.28.1 / 10.28.2), a major +# breaking migration tracked separately. pnpm runs only at install/start time. +CVE-2024-47829 +CVE-2026-23888 +CVE-2026-23889 +CVE-2026-23890 +CVE-2026-24056 +CVE-2026-24131 + +# golang.org/x/image bundled in the caire binary (content-aware seam-carving +# resize, one tool). esimov/caire v1.5.0 is the latest release and still pins +# golang.org/x/image v0.18.0; there is no upstream caire build with the fixed +# x/image >=0.38.0. Re-evaluate when caire publishes a new release. +CVE-2026-33809 + +# brace-expansion: build-toolchain transitive of minimatch/glob. The patched +# instance (5.0.6) is already present; the only flagged copy is the 2.x line +# pulled by glob, whose fix is a major-version bump (5.0.5) the glob ecosystem +# has not adopted. Not reachable from user input. +CVE-2026-33750 diff --git a/docker/Dockerfile b/docker/Dockerfile index 9b2e1631..ca640219 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -195,7 +195,11 @@ RUN corepack enable && corepack prepare pnpm@9.15.4 --activate && \ # System dependencies (all platforms) # Split into runtime deps and build deps to minimize final image size. # Retry apt-get update with backoff — Ubuntu mirrors can be flaky on CI runners +# `apt-get upgrade` pulls security patches for base-image packages (e.g. +# libgnutls30t64, libgcrypt20, liblzma5) that the pinned base digest ships at an +# outdated patch level -- closes the Trivy OS-package CVEs on every rebuild. RUN for i in 1 2 3; do apt-get -o Acquire::Retries=3 update && break || sleep $((i * 15)); done && \ + apt-get upgrade -y && \ apt-get install -y --no-install-recommends \ tini \ imagemagick \ @@ -269,7 +273,7 @@ RUN ldconfig # Uses pre-built manylinux wheels where available; gcc/g++ above covers the rest. RUN --mount=type=cache,target=/root/.cache/pip \ python3 -m venv /opt/venv && \ - /opt/venv/bin/pip install --upgrade "pip==25.1.1" && \ + /opt/venv/bin/pip install --upgrade "pip==26.1.2" && \ /opt/venv/bin/pip install wheel setuptools && \ /opt/venv/bin/pip install \ Pillow==12.2.0 \