Skip to content

Security: accepted-risk / deferred container image findings (transversal) #1758

Description

@ajile-in

Part of: #1730 — Security: Remediate 3,147 vulnerabilities across 26 container images (Hub + Verifier)

Purpose

Anchor for all container-image findings that are accepted risk (no fix available) or deferred by explicit decision, so the severity issues (CRITICAL/HIGH/MEDIUM/LOW for Hub and Verifier) can reach a clean "DONE" state.

Current progress: 100% (test-based)

  • Basis: pnpm security:progress — all 5 accepted-risk entries (request, @babel/core, fs, aws-sdk, websocket-driver) documented with justification; no fix available / deferred.
  • Re-check: re-evaluate when upstream fixes land.

Accepted risk / deferred items (from #1730 P4 table)

Package Type Reason Status
request npm (transitive) Deprecated, no fix available Monitor upstream; remove when parent deps drop it
@babel/core npm (dev-only) Dev-only (jest) Accepted — not shipped to prod runtime
aws-sdk v2 npm Separate migration effort Deferred — track as dedicated migration
fs (npm) npm Security placeholder, not a real dependency Accepted — false positive
websocket-driver npm CRITICAL advisory, no patched release Monitor upstream (see #1729)
busybox / systemd / other OS pkgs OS Handled via P0 base image rebuilds Close only when P0 lands
2 unmapped Verifier images image Not yet identified in report To be mapped in Verifier issues

Open per severity issue

  • Hub CRITICAL — residual findings to be triaged here
  • Hub HIGH — residual findings to be triaged here
  • Hub MEDIUM — residual findings to be triaged here
  • Hub LOW — residual findings to be triaged here
  • Verifier CRITICAL — residual findings to be triaged here
  • Verifier HIGH — residual findings to be triaged here
  • Verifier MEDIUM — residual findings to be triaged here
  • Verifier LOW — residual findings to be triaged here

Rules of engagement

Acceptance criteria

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions