Repository navigation
fix: [TOOL-1291] upgrade base-image packages so rebuilds clear trixie CVEs - #10
Merged
Merged
Conversation
… CVEs AWS Inspector (via Vanta) reports 3 CRITICALs on this image that Debian has already fixed in trixie point releases: CVE-2026-8376 and CVE-2026-42496 in perl (5.40.1 -> 0:5.40.1-6+deb13u1) and CVE-2026-5450 in glibc (2.41 -> 0:2.41-12+deb13u4), plus 15 more of lower severity (TOOL-1292). perl and glibc are base-image packages and are not in the runtime stage's install list, so `apt-get install` never upgrades them. Nothing in the Dockerfile pins a version or a base digest, so today a rebuild clears these CVEs only if Docker Hub has already refreshed python:3.12-slim-trixie with the point releases -- and if the base digest has not moved, the release workflow's `cache-from: type=gha` serves every layer from cache and the new tag is a byte-identical image with the same findings. `apt-get upgrade` makes it deterministic: the point releases land at build time regardless of the base image's cadence, and next month's rebuild is self-healing instead of a bet on upstream. The builder stage is deliberately left alone -- only /app is copied out of it, so its packages are not in the scanned artifact. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Rggiavt7EWATqozS3GUoCh
eculver
marked this pull request as ready for review
September 28, 2026 19:07
eculver
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Evan Culver · Slack thread
Context
TOOL-1291 — AWS Inspector (via Vanta) now reports fixed versions available for all 3 CRITICALs on this image:
0:5.40.1-6+deb13u10:5.40.1-6+deb13u10:2.41-12+deb13u4TOOL-1291 proposed a plain rebuild + retag. Reading the Dockerfile, a plain rebuild is not a reliable fix, which is what this PR corrects.
Why a rebuild alone isn't enough
perlandglibc(libc6/perl-base) come from thepython:3.12-slim-trixiebase image. The runtime stage installs onlylibpq-dev iputils-ping dnsutils net-tools, andapt-get installdoes not upgrade packages outside its argument list. There is noapt-get upgradeanywhere in the Dockerfile, and nothing pins a package version or a base-image digest.So today, a rebuild clears these CVEs only if Docker Hub has already refreshed
python:3.12-slim-trixiewith the point releases. Two ways that bites:release.yml'scache-from: type=ghaserves every layer from the GHA cache and the new tag is a byte-identical image with the same findings.For reference, the base image currently sits at digest
sha256:2f17fc044b579bab302c2e8054d3a686e2cb9a83de48e70534b94cd8ebbe06a9, last pushed2026-09-19T08:09:26Z, i.e. after the deployedv0.3.0-sfc.4(commitb308aa5, 2026-09-15). So in this particular instance the base has moved and a rebuild would likely have worked — but by luck, not by construction.The change
One
RUNin the runtime stage gainsDEBIAN_FRONTEND=noninteractive apt-get upgrade -ybetweenupdateandinstall. The point releases land at build time regardless of the base image's cadence, and next month's rebuild is self-healing.Same spirit as the existing
pip install --upgrade pipline directly below it (added in #2 for exactly this class of base-image CVE).The builder stage is deliberately left alone: only
/appis copied out of it, so its packages are not part of the scanned artifact, and upgrading there would just slow the build.Verification
I could not build this locally — this environment's egress proxy returns
403 Forbiddenon Docker Hub blob fetches (production.cloudfront.docker.com), sodocker pull python:3.12-slim-trixiefails before any build starts. Debian'ssecurity-tracker.debian.organddeb.debian.orgare blocked by the same policy, so I also could not confirm from package metadata that the 2026-09-19 base already carriesdeb13u1/deb13u4.build.ymldoes not build the Dockerfile (it runs ruff/pyright/pytest), so CI on this PR will not exercise the change either.Please dry-run before merging:
release.ymlhas aworkflow_dispatchwhosepushinput defaults tofalse, which builds both platforms without publishing anything. That is the check this PR needs:Left as a draft until that dry run is green.
What this unblocks
Tagging
v0.3.0-sfc.5off this commit and bumpingimage.tagindeployment/helm/postgres-mcp/values.yaml(monorepo) closes TOOL-1291 and TOOL-1292, clears the bind9 half of TOOL-1316, and retires TOOL-1202, TOOL-1135 and 3 of TOOL-1075's 4 CVEs. Known residual no-fix items are unaffected: libxml2 (TOOL-1205/1316), zlib, nghttp2.Related: #2 (the bookworm → trixie bump this generalizes), #3 (TOOL-838, the release workflow), #9 (TOOL-862, the staging shadow that will mirror the new tag automatically).
🤖 Generated with Claude Code
https://claude.ai/code/session_01Rggiavt7EWATqozS3GUoCh
Generated by Claude Code