Part of: #1730 — Security: Remediate 3,147 vulnerabilities across 26 container images (Hub + Verifier)
Purpose
Anchor for all container-image findings that are accepted risk (no fix available) or deferred by explicit decision, so the severity issues (CRITICAL/HIGH/MEDIUM/LOW for Hub and Verifier) can reach a clean "DONE" state.
Current progress: 100% (test-based)
- Basis:
pnpm security:progress — all 5 accepted-risk entries (request, @babel/core, fs, aws-sdk, websocket-driver) documented with justification; no fix available / deferred.
- Re-check: re-evaluate when upstream fixes land.
Accepted risk / deferred items (from #1730 P4 table)
| Package |
Type |
Reason |
Status |
request |
npm (transitive) |
Deprecated, no fix available |
Monitor upstream; remove when parent deps drop it |
@babel/core |
npm (dev-only) |
Dev-only (jest) |
Accepted — not shipped to prod runtime |
aws-sdk v2 |
npm |
Separate migration effort |
Deferred — track as dedicated migration |
fs (npm) |
npm |
Security placeholder, not a real dependency |
Accepted — false positive |
websocket-driver |
npm |
CRITICAL advisory, no patched release |
Monitor upstream (see #1729) |
| busybox / systemd / other OS pkgs |
OS |
Handled via P0 base image rebuilds |
Close only when P0 lands |
| 2 unmapped Verifier images |
image |
Not yet identified in report |
To be mapped in Verifier issues |
Open per severity issue
Rules of engagement
Acceptance criteria
Part of: #1730 — Security: Remediate 3,147 vulnerabilities across 26 container images (Hub + Verifier)
Purpose
Anchor for all container-image findings that are accepted risk (no fix available) or deferred by explicit decision, so the severity issues (CRITICAL/HIGH/MEDIUM/LOW for Hub and Verifier) can reach a clean "DONE" state.
Current progress: 100% (test-based)
pnpm security:progress— all 5 accepted-risk entries (request, @babel/core, fs, aws-sdk, websocket-driver) documented with justification; no fix available / deferred.Accepted risk / deferred items (from #1730 P4 table)
request@babel/coreaws-sdkv2fs(npm)websocket-driverOpen per severity issue
Rules of engagement
Acceptance criteria