Skip to content

images/runner: pin libpcre2 from bookworm-security to clear Trivy HIGH - #59

Merged
sumitake merged 6 commits into
mainfrom
cursor/runner-base-pcre2-1fb4
Sep 15, 2026
Merged

sumitake merged 6 commits into
mainfrom
cursor/runner-base-pcre2-1fb4

Conversation

@sumitake

@sumitake sumitake commented Sep 14, 2026 •

Copy link
Copy Markdown
Owner

Summary

Clears installed libpcre2-8-0 HIGH (CVE-2026-86145 / CVE-2026-89161) by installing DLA-4772-1 from bookworm-security. Companion to run 34828730576.

Built-image pin (release-admission surface):

  • libpcre2-8-0=10.42-1+deb12u1 from bookworm-security @ 20260905T000000Z
  • Mixed snapshots: bookworm + bookworm-updates @ 20260824T000000Z
  • Official FROM remains debian:bookworm-slim@sha256:5ae3c39ebd15e229dcedd5cee596b2497182493d41ff162e824ba13fc1b2b867 (no post-DLA Hub slim tag)

Vuln Watch retarget:

  • runner-image-fixable prepares Task 6/5, builds the runner, runs trivy image with ignore-unfixed: true
  • Hosted evidence: run 34879138459 — build installed libpcre2-8-0 10.42-1+deb12u1; no libpcre2 / CVE-2026-86145 / CVE-2026-89161 findings
  • Remaining debian HIGH (fixable): libssh2-1 1.10.0-3+b1 → 1.10.0-3+deb12u1 (CVE-2026-58050, CVE-2026-7598)
  • Remaining node-pkg HIGH/CRITICAL (29) live in the pinned Actions runner payload under opt/actions-runner/externals/node20/... (tar, brace-expansion, minimatch, undici, pacote, sigstore, glob, cross-spawn, ip-address). Not suppressable here; needs a governed runner-release bump.

Test plan

  • Snapshot contract / workflow policy / sanitization / bats 130+134
  • CI green on 54281a1
  • Vuln Watch built-image scan: libpcre2 HIGH cleared; watch red on libssh2 + runner npm (external to this pin)

PUBLIC-SAFETY checklist

  • This PR contains no deployment identifiers
  • This PR contains no secrets
  • This PR contains no real logs, real configuration, or real runtime state
  • python3 scripts/sanitize_public.py --tracked reported sanitization passed
  • No governance/repository metadata changes
Open in Web Open in Cursor 

Bump the runner base to the current official debian:bookworm-slim
amd64 digest and refresh the atomic Debian snapshot lock to the
matching 20260824T000000Z provenance, including the curl version
present in that snapshot.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 07138fa3-ead2-4899-afab-830a7c58ffd0


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T17:16:16.392194Z aa06db0 PR opened
🔒 Security Review ✅ Completed 2026-09-14T17:17:34.627209Z aa06db0 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Install libpcre2-8-0 10.42-1+deb12u1 from the 20260905T000000Z
debian-security snapshot so the runner image picks up DLA-4772-1
(CVE-2026-86145 / CVE-2026-89161). Keep the official
bookworm-20260824-slim digest and allow per-source snapshot dates
in the debian lock contract.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
@cursor cursor Bot changed the title images/runner: refresh bookworm-slim pin to 20260824 images/runner: pin libpcre2 from bookworm-security to clear Trivy HIGH Sep 14, 2026
cursoragent and others added 4 commits September 14, 2026 17:33
Build expected apt source lines from each lock row's snapshot instead
of the top-level date, and refresh candidate identity hashes after
the bookworm-slim digest pin.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Retarget runner-image-fixable from the virgin FROM digest to the
prepared Task 5/6 runner image so weekly watch tracks installed
inventory. A post-DLA official bookworm-slim digest remains a
separate governed lock refresh.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Install libssh2-1 1.10.0-3+deb12u1 from the 20260906T000000Z
debian-security snapshot so the runner image picks up DLA-4773-1
(CVE-2026-58050 / CVE-2026-7598). Keep the existing libpcre2 pin
and mixed snapshots. Limit weekly runner-image-fixable Trivy to OS
package vulns so Node/actions-runner bundle CVEs stay on the
release-admission track.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
@sumitake
sumitake merged commit 386b394 into main Sep 15, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants