Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 0 additions & 38 deletions .trivyignore
Original file line number Diff line number Diff line change
Expand Up @@ -28,41 +28,3 @@ GHSA-r7wm-3cxj-wff9 exp:2026-09-27
# by Vert.x instrumentation, not Micrometer's vulnerable HTTP server binder
# See: UID2-7662
CVE-2026-40984 exp:2026-11-11

# CVE-2026-14456 — libcrypto3/libssl3 (openssl, Alpine base image, transitive via
# eclipse-temurin:21-jre-alpine-3.23) (HIGH): DoS via unbounded memory growth in an OpenSSL
# QUIC server. Not exploitable: uid2-operator terminates TLS via JSSE over plain TCP and never
# runs an OpenSSL QUIC server. The bundled Amazon Corretto Crypto Provider (ACCP) only exposes
# JCA Cipher/Signature/MessageDigest/KeyAgreement via OpenSSL's EVP API — it never touches
# libssl's QUIC server implementation, so ACCP does not make this path reachable. Applies to the
# GCP OIDC and Azure CC private-operator images (scripts/gcp-oidc, scripts/azure-cc), which don't
# carry the apk upgrade applied to ./Dockerfile in #2708.
# See: UID2-7761
CVE-2026-14456 exp:2026-09-28

# CVE-2026-66046 — libexpat (Alpine base-image OS library) (HIGH).
# Not exploitable here: Dockerfile FROM eclipse-temurin:21-jre-alpine-3.23 (adds gcompat +
# libcrypto3/libssl3 for Amazon Corretto Crypto Provider only). Pure-Java; no native XML
# binding to libexpat in src.
# See: UID2-7800
CVE-2026-66046 exp:2026-12-02

# CVE-2026-76641 — libexpat (Alpine base-image native C library) (HIGH).
# Not exploitable here: Dockerfile FROM eclipse-temurin 21-jre-alpine-3.23; adds gcompat +
# libcrypto3/libssl3 for Amazon Corretto Crypto Provider only; no libexpat, no native XML
# binding; runs java -jar
# See: UID2-7801
CVE-2026-76641 exp:2026-12-02

# libexpat is an Alpine OS package; this is a Java/Vert.x service that parses XML via JAXP/Xerces, not libexpat — no native/JNI path reaches it
# See: UID2-7849
CVE-2026-76956 exp:2026-10-10

# libexpat is an Alpine OS package; this is a Java/Vert.x service that parses XML via JAXP/Xerces, not libexpat — no native/JNI path reaches it
# See: UID2-7849
CVE-2026-76957 exp:2026-10-10

# CVE-2026-93990 — libexpat (Alpine base-image native C library) (HIGH). Not exploitable here.
# See the ticket below for the assessment.
# See: UID2-7962
CVE-2026-93990 exp:2026-12-25
6 changes: 3 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d
FROM eclipse-temurin@sha256:319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84
FROM eclipse-temurin@sha256:42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84

# For Amazon Corretto Crypto Provider
RUN apk add --no-cache gcompat && apk add --no-cache --upgrade libcrypto3 libssl3
RUN apk add --no-cache gcompat

WORKDIR /app
EXPOSE 8080
Expand Down
4 changes: 2 additions & 2 deletions scripts/azure-cc/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d
FROM eclipse-temurin@sha256:319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84
FROM eclipse-temurin@sha256:42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84

# Install necessary packages and set up virtual environment
RUN apk update && apk add --no-cache jq python3 py3-pip && \
Expand Down
4 changes: 2 additions & 2 deletions scripts/gcp-oidc/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d
FROM eclipse-temurin@sha256:319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84
FROM eclipse-temurin@sha256:42b42237d59d901504348d97b8bc304e6b5f4e12f5cf8f45c4f76fef2427aa84

LABEL "tee.launch_policy.allow_env_override"="API_TOKEN_SECRET_NAME,DEPLOYMENT_ENVIRONMENT,CORE_BASE_URL,OPTOUT_BASE_URL,DEBUG_MODE,SKIP_VALIDATIONS"
LABEL "tee.launch_policy.log_redirect"="always"
Expand Down
Loading