Skip to content

Security: fix scanner findings 2026-10-05 - #272

Draft
ChiefGyk3D wants to merge 4 commits into
mainfrom
claude/security-scan-2026-10-05
Draft

ChiefGyk3D wants to merge 4 commits into
mainfrom
claude/security-scan-2026-10-05

Conversation

@ChiefGyk3D

Copy link
Copy Markdown
Owner

Summary

Weekly security-scan triage. One high-severity Trivy finding, fixed by bumping the base-image digest.

Alert → Issue Tool Severity Change made
CVE-2026-103111 (libpcre2-8-0) → #271 Trivy high Bumped FROM python:3.14-slim digest

Fixes #271

Needs attention

The new digest (sha256:c3e521df...) was verified to exist and differ from the pinned one via the Docker Hub registry API, but this sandbox has no Docker daemon/Trivy to rebuild and re-scan locally. This repo's own CI runs a Trivy image scan on every build — that will confirm whether the point-release fix landed. Same digest bump as companion PRs in jumpcloud-wazuh-bridge and netpulse (same base image).

🤖 Generated with Claude Code

https://claude.ai/code/session_01GS1ZwURfozKePu3FS9qamF


Generated by Claude Code

python:3.14-slim's pinned digest (caaf356f...) still carries
libpcre2-8-0 10.46-1~deb13u2, vulnerable to CVE-2026-103111. Debian has
since shipped the deb13u3 point release fixing it, and the current
python:3.14-slim tag now resolves to a newer digest (c3e521df...); bump
the pin so the next build picks it up.

Fixes #271

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
ChiefGyk3D and others added 3 commits October 7, 2026 23:02
The CI container build failed three times in a row with 'Connection
refused' from www.sqlite.org once the base-image digest bump invalidated
the cached layer. Retry connection-refused errors so a transient refusal
does not fail the build.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The Dockerfile downloads the SQLite source; release.yml already allows
the host but ci.yml did not. Main stayed green on a cached layer, and the
base-image digest bump invalidated it, so harden-runner refused the
connection. Same entry as release.yml.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] high Trivy: CVE-2026-103111 in libpcre2-8-0 (base image)

1 participant