From 183d00cfc551a43c0a6f59786e58e73afdd5afd0 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 21 Sep 2026 15:46:40 +0000 Subject: [PATCH] fix: [TOOL-1291] upgrade base-image packages so rebuilds clear trixie CVEs AWS Inspector (via Vanta) reports 3 CRITICALs on this image that Debian has already fixed in trixie point releases: CVE-2026-8376 and CVE-2026-42496 in perl (5.40.1 -> 0:5.40.1-6+deb13u1) and CVE-2026-5450 in glibc (2.41 -> 0:2.41-12+deb13u4), plus 15 more of lower severity (TOOL-1292). perl and glibc are base-image packages and are not in the runtime stage's install list, so `apt-get install` never upgrades them. Nothing in the Dockerfile pins a version or a base digest, so today a rebuild clears these CVEs only if Docker Hub has already refreshed python:3.12-slim-trixie with the point releases -- and if the base digest has not moved, the release workflow's `cache-from: type=gha` serves every layer from cache and the new tag is a byte-identical image with the same findings. `apt-get upgrade` makes it deterministic: the point releases land at build time regardless of the base image's cadence, and next month's rebuild is self-healing instead of a bet on upstream. The builder stage is deliberately left alone -- only /app is copied out of it, so its packages are not in the scanned artifact. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01Rggiavt7EWATqozS3GUoCh --- Dockerfile | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 97d061d6..509d23db 100644 --- a/Dockerfile +++ b/Dockerfile @@ -41,8 +41,14 @@ LABEL org.opencontainers.image.licenses="Apache-2.0" LABEL org.opencontainers.image.vendor="Crystal DBA" LABEL org.opencontainers.image.url="https://www.crystaldba.ai" -# Install runtime system dependencies -RUN apt-get update && apt-get install -y \ +# Install runtime system dependencies. The `upgrade` is what pulls Debian's +# security point releases (perl, glibc) in: those packages come from the base +# image and are not in the install list, so `install` alone never touches them +# and a rebuild only clears their CVEs if Docker Hub happens to have refreshed +# python:3.12-slim-trixie first. +RUN apt-get update \ + && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y \ + && apt-get install -y \ libpq-dev \ iputils-ping \ dnsutils \