diff --git a/.trivyignore b/.trivyignore index 42d83ba4b..3ecd7d357 100644 --- a/.trivyignore +++ b/.trivyignore @@ -28,41 +28,3 @@ GHSA-r7wm-3cxj-wff9 exp:2026-09-27 # by Vert.x instrumentation, not Micrometer's vulnerable HTTP server binder # See: UID2-7662 CVE-2026-40984 exp:2026-11-11 - -# CVE-2026-14456 — libcrypto3/libssl3 (openssl, Alpine base image, transitive via -# eclipse-temurin:21-jre-alpine-3.23) (HIGH): DoS via unbounded memory growth in an OpenSSL -# QUIC server. Not exploitable: uid2-operator terminates TLS via JSSE over plain TCP and never -# runs an OpenSSL QUIC server. The bundled Amazon Corretto Crypto Provider (ACCP) only exposes -# JCA Cipher/Signature/MessageDigest/KeyAgreement via OpenSSL's EVP API — it never touches -# libssl's QUIC server implementation, so ACCP does not make this path reachable. Applies to the -# GCP OIDC and Azure CC private-operator images (scripts/gcp-oidc, scripts/azure-cc), which don't -# carry the apk upgrade applied to ./Dockerfile in #2708. -# See: UID2-7761 -CVE-2026-14456 exp:2026-09-28 - -# CVE-2026-66046 — libexpat (Alpine base-image OS library) (HIGH). -# Not exploitable here: Dockerfile FROM eclipse-temurin:21-jre-alpine-3.23 (adds gcompat + -# libcrypto3/libssl3 for Amazon Corretto Crypto Provider only). Pure-Java; no native XML -# binding to libexpat in src. -# See: UID2-7800 -CVE-2026-66046 exp:2026-12-02 - -# CVE-2026-76641 — libexpat (Alpine base-image native C library) (HIGH). -# Not exploitable here: Dockerfile FROM eclipse-temurin 21-jre-alpine-3.23; adds gcompat + -# libcrypto3/libssl3 for Amazon Corretto Crypto Provider only; no libexpat, no native XML -# binding; runs java -jar -# See: UID2-7801 -CVE-2026-76641 exp:2026-12-02 - -# libexpat is an Alpine OS package; this is a Java/Vert.x service that parses XML via JAXP/Xerces, not libexpat — no native/JNI path reaches it -# See: UID2-7849 -CVE-2026-76956 exp:2026-10-10 - -# libexpat is an Alpine OS package; this is a Java/Vert.x service that parses XML via JAXP/Xerces, not libexpat — no native/JNI path reaches it -# See: UID2-7849 -CVE-2026-76957 exp:2026-10-10 - -# CVE-2026-93990 — libexpat (Alpine base-image native C library) (HIGH). Not exploitable here. -# See the ticket below for the assessment. -# See: UID2-7962 -CVE-2026-93990 exp:2026-12-25 diff --git a/Dockerfile b/Dockerfile index 921a52d72..c70ec2b15 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,8 +1,8 @@ -# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d -FROM eclipse-temurin@sha256:319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d +# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84 +FROM eclipse-temurin@sha256:42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84 # For Amazon Corretto Crypto Provider -RUN apk add --no-cache gcompat && apk add --no-cache --upgrade libcrypto3 libssl3 +RUN apk add --no-cache gcompat WORKDIR /app EXPOSE 8080 diff --git a/scripts/azure-cc/Dockerfile b/scripts/azure-cc/Dockerfile index f6c147068..b6cafce93 100644 --- a/scripts/azure-cc/Dockerfile +++ b/scripts/azure-cc/Dockerfile @@ -1,5 +1,5 @@ -# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d -FROM eclipse-temurin@sha256:319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d +# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84 +FROM eclipse-temurin@sha256:42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84 # Install necessary packages and set up virtual environment RUN apk update && apk add --no-cache jq python3 py3-pip && \ diff --git a/scripts/gcp-oidc/Dockerfile b/scripts/gcp-oidc/Dockerfile index 3ae7869c7..98bb11cd6 100644 --- a/scripts/gcp-oidc/Dockerfile +++ b/scripts/gcp-oidc/Dockerfile @@ -1,5 +1,5 @@ -# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d -FROM eclipse-temurin@sha256:319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d +# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84 +FROM eclipse-temurin@sha256:42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84 LABEL "tee.launch_policy.allow_env_override"="API_TOKEN_SECRET_NAME,DEPLOYMENT_ENVIRONMENT,CORE_BASE_URL,OPTOUT_BASE_URL,DEBUG_MODE,SKIP_VALIDATIONS" LABEL "tee.launch_policy.log_redirect"="always"