Repository navigation
Security: fix scanner findings 2026-10-05 - #272
Draft
ChiefGyk3D wants to merge 4 commits into
Draft
ChiefGyk3D wants to merge 4 commits into
ChiefGyk3D wants to merge 4 commits into
Conversation
python:3.14-slim's pinned digest (caaf356f...) still carries libpcre2-8-0 10.46-1~deb13u2, vulnerable to CVE-2026-103111. Debian has since shipped the deb13u3 point release fixing it, and the current python:3.14-slim tag now resolves to a newer digest (c3e521df...); bump the pin so the next build picks it up. Fixes #271 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The CI container build failed three times in a row with 'Connection refused' from www.sqlite.org once the base-image digest bump invalidated the cached layer. Retry connection-refused errors so a transient refusal does not fail the build. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This reverts commit a0e07bf.
The Dockerfile downloads the SQLite source; release.yml already allows the host but ci.yml did not. Main stayed green on a cached layer, and the base-image digest bump invalidated it, so harden-runner refused the connection. Same entry as release.yml. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Weekly security-scan triage. One high-severity Trivy finding, fixed by bumping the base-image digest.
FROM python:3.14-slimdigestFixes #271
Needs attention
The new digest (
sha256:c3e521df...) was verified to exist and differ from the pinned one via the Docker Hub registry API, but this sandbox has no Docker daemon/Trivy to rebuild and re-scan locally. This repo's own CI runs a Trivy image scan on every build — that will confirm whether the point-release fix landed. Same digest bump as companion PRs injumpcloud-wazuh-bridgeandnetpulse(same base image).🤖 Generated with Claude Code
https://claude.ai/code/session_01GS1ZwURfozKePu3FS9qamF
Generated by Claude Code