fix(docker): patch OS + pip image CVEs, document accepted Trivy residuals (#288)

Reduces the container-image CVE surface flagged by Trivy.

Genuinely fixed on every rebuild:
- apt-get upgrade in the production stage pulls Ubuntu security patches
  for base-image packages (libgnutls30t64 3.8.3-1.1ubuntu3.5 -> ubuntu3.6,
  libgcrypt20, liblzma5), closing ~15 OS-package CVEs.
- pip 25.1.1 -> 26.1.2 closes 4 pip CVEs (CVE-2025-8869, 2026-1703,
  2026-3219, 2026-6357).

Accepted via .trivyignore (canonical, reviewed):
- 6 newly surfaced pnpm 9.x build-tool CVEs (fixed only in pnpm 10.x, a
  major migration tracked separately; pnpm runs at install/start only).
- caire's bundled golang.org/x/image (esimov/caire v1.5.0 is latest and
  still pins x/image v0.18.0; no upstream fix).
- brace-expansion 2.x ReDoS (transitive of glob; patched 5.0.6 already
  present; not reachable from user input).

Already resolved in the current tree (clear on next scan): picomatch
4.0.4 (override), ip-address removed.

Verification note: the Trivy job in release.yml depends on the
intentionally gated-off docker build/publish job, so these cannot be
re-scanned in CI without enabling image publishing. The image is not
currently shipped.
This commit is contained in:
SnapOtter
2026-06-21 23:23:03 +08:00
committed by GitHub
parent dba8a85a80
commit c203267866
2 changed files with 27 additions and 1 deletions
+5 -1
View File
@@ -195,7 +195,11 @@ RUN corepack enable && corepack prepare pnpm@9.15.4 --activate && \
# System dependencies (all platforms)
# Split into runtime deps and build deps to minimize final image size.
# Retry apt-get update with backoff — Ubuntu mirrors can be flaky on CI runners
# `apt-get upgrade` pulls security patches for base-image packages (e.g.
# libgnutls30t64, libgcrypt20, liblzma5) that the pinned base digest ships at an
# outdated patch level -- closes the Trivy OS-package CVEs on every rebuild.
RUN for i in 1 2 3; do apt-get -o Acquire::Retries=3 update && break || sleep $((i * 15)); done && \
apt-get upgrade -y && \
apt-get install -y --no-install-recommends \
tini \
imagemagick \
@@ -269,7 +273,7 @@ RUN ldconfig
# Uses pre-built manylinux wheels where available; gcc/g++ above covers the rest.
RUN --mount=type=cache,target=/root/.cache/pip \
python3 -m venv /opt/venv && \
/opt/venv/bin/pip install --upgrade "pip==25.1.1" && \
/opt/venv/bin/pip install --upgrade "pip==26.1.2" && \
/opt/venv/bin/pip install wheel setuptools && \
/opt/venv/bin/pip install \
Pillow==12.2.0 \