chore(security): ignore unfixed CVEs in Trivy, override deepmerge-ts (#1085)
Stable twin of #1083, scoped to what exists on this branch. docker-build.yml — set ignore-unfixed on both Trivy steps. Stable has the backend and frontend legs only (no aio, no ml), so two steps here against four on main. Base-image CVEs with no released fix are not actionable: the Dockerfiles already run `apt-get upgrade -y` behind a CACHEBUST, so a fix lands in the next build automatically. Reporting them buries anything someone can actually act on. backend — deepmerge-ts <8.0.0 has a stack-exhaustion advisory (CVE-2026-40345, high) reached via mailparser -> html-to-text, which pins ^7.1.5 so npm cannot get there alone. Stable carries the same mailparser ^3.9.9 and the same 3-high exposure as main. Not reachable in our code: html-to-text only feeds deepmerge-ts its options object, never parsed email content. npm audit on this branch goes 3 high -> 0. The ml/Dockerfile half of #1083 has no counterpart here — the face sidecar does not exist on stable, so there is nothing to drift. Verified on stable itself rather than assuming main's results carry: npm audit 3 high -> 0, html-to-text exercised end-to-end through simpleParser, and jest at 1577 passed. The 5 failing suites (20 tests) fail identically on clean origin/stable with these changes stashed. Co-authored-by: Paul Nothaft <[email protected]>
This commit is contained in:
co-authored by
Paul Nothaft
parent
6df42ab22c
commit
83290a0f1a
@@ -203,6 +203,14 @@ jobs:
|
|||||||
format: 'sarif'
|
format: 'sarif'
|
||||||
output: 'trivy-backend-${{ env.PLATFORM_PAIR }}.sarif'
|
output: 'trivy-backend-${{ env.PLATFORM_PAIR }}.sarif'
|
||||||
severity: 'CRITICAL,HIGH'
|
severity: 'CRITICAL,HIGH'
|
||||||
|
# Base-image CVEs with no released fix are not actionable: the
|
||||||
|
# Dockerfiles already run `apt-get upgrade -y` behind a CACHEBUST,
|
||||||
|
# so a fix lands in the next build automatically. Reporting them
|
||||||
|
# buries the findings someone can actually do something about.
|
||||||
|
# Dropping them is also the precondition for ever setting
|
||||||
|
# exit-code: 1, which build-backend's comment flags as a
|
||||||
|
# deliberate follow-up.
|
||||||
|
ignore-unfixed: true
|
||||||
timeout: '10m'
|
timeout: '10m'
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
@@ -425,6 +433,14 @@ jobs:
|
|||||||
format: 'sarif'
|
format: 'sarif'
|
||||||
output: 'trivy-frontend-${{ env.PLATFORM_PAIR }}.sarif'
|
output: 'trivy-frontend-${{ env.PLATFORM_PAIR }}.sarif'
|
||||||
severity: 'CRITICAL,HIGH'
|
severity: 'CRITICAL,HIGH'
|
||||||
|
# Base-image CVEs with no released fix are not actionable: the
|
||||||
|
# Dockerfiles already run `apt-get upgrade -y` behind a CACHEBUST,
|
||||||
|
# so a fix lands in the next build automatically. Reporting them
|
||||||
|
# buries the findings someone can actually do something about.
|
||||||
|
# Dropping them is also the precondition for ever setting
|
||||||
|
# exit-code: 1, which build-backend's comment flags as a
|
||||||
|
# deliberate follow-up.
|
||||||
|
ignore-unfixed: true
|
||||||
timeout: '10m'
|
timeout: '10m'
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
|
|||||||
Generated
+15
-5
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "picpeak-backend",
|
"name": "picpeak-backend",
|
||||||
"version": "3.45.14",
|
"version": "3.46.0",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "picpeak-backend",
|
"name": "picpeak-backend",
|
||||||
"version": "3.45.14",
|
"version": "3.46.0",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@aws-sdk/client-s3": "^3.850.0",
|
"@aws-sdk/client-s3": "^3.850.0",
|
||||||
"@aws-sdk/lib-storage": "^3.850.0",
|
"@aws-sdk/lib-storage": "^3.850.0",
|
||||||
@@ -5315,9 +5315,19 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/deepmerge-ts": {
|
"node_modules/deepmerge-ts": {
|
||||||
"version": "7.1.5",
|
"version": "8.0.1",
|
||||||
"resolved": "https://registry.npmjs.org/deepmerge-ts/-/deepmerge-ts-7.1.5.tgz",
|
"resolved": "https://registry.npmjs.org/deepmerge-ts/-/deepmerge-ts-8.0.1.tgz",
|
||||||
"integrity": "sha512-HOJkrhaYsweh+W+e74Yn7YStZOilkoPb6fycpwNLKzSPtruFs48nYis0zy5yJz1+ktUhHxoRDJ27RQAWLIJVJw==",
|
"integrity": "sha512-szCXE7YLCvLKR9bFPJcvsezOShdalctSvrgN/LM/QGUEPZQajwjmsMObZ6/DuANT5lxzM/wtO8Feubwdkz8myA==",
|
||||||
|
"funding": [
|
||||||
|
{
|
||||||
|
"type": "ko-fi",
|
||||||
|
"url": "https://ko-fi.com/rebeccastevens"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"type": "tidelift",
|
||||||
|
"url": "https://tidelift.com/funding/github/npm/deepmerge-ts"
|
||||||
|
}
|
||||||
|
],
|
||||||
"license": "BSD-3-Clause",
|
"license": "BSD-3-Clause",
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=16.0.0"
|
"node": ">=16.0.0"
|
||||||
|
|||||||
@@ -93,6 +93,7 @@
|
|||||||
"@tootallnate/once": ">=3.0.1",
|
"@tootallnate/once": ">=3.0.1",
|
||||||
"ip-address": ">=10.3.1",
|
"ip-address": ">=10.3.1",
|
||||||
"uuid": "^11.1.1",
|
"uuid": "^11.1.1",
|
||||||
"nodemailer": "^9.0.1"
|
"nodemailer": "^9.0.1",
|
||||||
|
"deepmerge-ts": ">=8.0.1"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user