images/runner: pin libpcre2 from bookworm-security to clear Trivy HIGH - #59
Merged
Merged
Conversation
Bump the runner base to the current official debian:bookworm-slim amd64 digest and refresh the atomic Debian snapshot lock to the matching 20260824T000000Z provenance, including the curl version present in that snapshot. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Install libpcre2-8-0 10.42-1+deb12u1 from the 20260905T000000Z debian-security snapshot so the runner image picks up DLA-4772-1 (CVE-2026-86145 / CVE-2026-89161). Keep the official bookworm-20260824-slim digest and allow per-source snapshot dates in the debian lock contract. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Build expected apt source lines from each lock row's snapshot instead of the top-level date, and refresh candidate identity hashes after the bookworm-slim digest pin. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Retarget runner-image-fixable from the virgin FROM digest to the prepared Task 5/6 runner image so weekly watch tracks installed inventory. A post-DLA official bookworm-slim digest remains a separate governed lock refresh. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Install libssh2-1 1.10.0-3+deb12u1 from the 20260906T000000Z debian-security snapshot so the runner image picks up DLA-4773-1 (CVE-2026-58050 / CVE-2026-7598). Keep the existing libpcre2 pin and mixed snapshots. Limit weekly runner-image-fixable Trivy to OS package vulns so Node/actions-runner bundle CVEs stay on the release-admission track. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Clears installed
libpcre2-8-0HIGH (CVE-2026-86145 / CVE-2026-89161) by installing DLA-4772-1 frombookworm-security. Companion to run 34828730576.Built-image pin (release-admission surface):
libpcre2-8-0=10.42-1+deb12u1frombookworm-security@20260905T000000Zbookworm+bookworm-updates@20260824T000000ZFROMremainsdebian:bookworm-slim@sha256:5ae3c39ebd15e229dcedd5cee596b2497182493d41ff162e824ba13fc1b2b867(no post-DLA Hub slim tag)Vuln Watch retarget:
runner-image-fixableprepares Task 6/5, builds the runner, runstrivy imagewithignore-unfixed: truelibpcre2-8-010.42-1+deb12u1; no libpcre2 / CVE-2026-86145 / CVE-2026-89161 findingslibssh2-11.10.0-3+b1→1.10.0-3+deb12u1(CVE-2026-58050,CVE-2026-7598)opt/actions-runner/externals/node20/...(tar,brace-expansion,minimatch,undici,pacote,sigstore,glob,cross-spawn,ip-address). Not suppressable here; needs a governed runner-release bump.Test plan
54281a1PUBLIC-SAFETY checklist
python3 scripts/sanitize_public.py --trackedreportedsanitization passed