Skip to content

Fix Trivy containerd and GLib CVEs in the BCI runtime - #292

Merged
rb3ckers merged 3 commits into
masterfrom
cve-pcre2-glibc-runtime
Oct 2, 2026
Merged

rb3ckers merged 3 commits into
masterfrom
cve-pcre2-glibc-runtime

Conversation

@ai-collaboration-app

@ai-collaboration-app ai-collaboration-app Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

The rebuilt process-agent images clear all six assigned Trivy rows on quay.io/stackstate/stackstate-k8s-process-agent:0294bfee: containerd CVE-2026-53493 and five GLib package rows for SUSE-SU-2026:4367-1. Source: dev scan 36983036771, attempt 1; verified aggregate digest sha256:600d791947fc21560ab206d820e80af13dab87d0de836377c73cda6046e96345. Tracking: cve-reporter #69, containerd #260.

  • Upgrade github.com/containerd/containerd v1.7.35 → v1.7.36, the compatible upstream patch for CVE-2026-53493. Upstream module requirements are byte-identical.
  • Require glib2-tools, libgio-2_0-0, libglib-2_0-0, libgmodule-2_0-0, and libgobject-2_0-0 at 2.78.6-150600.4.41.1 or newer for SUSE-SU-2026:4367-1. Supported BCI 15.7 supplies the fixes through the existing zypper path; no base migration or custom runtime updater is needed. Version floors make stale-repository builds fail.
  • Retain this PR's PCRE2/glibc floors and signed checkpoint c86d936d5833e97b6e6daccb3d1e7beec3e3b2c1. Current master and the reviewed PR Bump gRPC and containerd for September CVEs #278/Upgrade OpenTelemetry for CVE-2026-81870, preserving reviewed Go fixes #290 ancestry are incorporated without rewriting history. Product diff: three files.

Signed source head: a0a3d2f. Published branch image: quay.io/stackstate/stackstate-k8s-process-agent:a0a3d2fb, signed index sha256:ea384c3380fc56d809133e1b26680f29488137a58e9abab4efd1155be7464a0c.

Architecture Published runtime digest
amd64 sha256:fb6e9f8546674f06a165c7668d45b6d57b9bd62b4edeafd29934da081bcb76fd
arm64 sha256:9dc61c6e59fe8f97dc69b377fa74416920a7fd6623e1374de4917543450b1296

Validation:

  • CI 36991914873: all eight required jobs passed, including native prebuild/generated-code checks, build/unit tests, runtime smoke tests, both scanners and signed publication.
  • Dual-scanner published-image verification 36994560497: both native architecture jobs passed against the exact published digests. The index signature verifies, extracted binaries match tested CI artifacts byte-for-byte, source metadata matches the signed head, and each complete inventory contains 433 components/125 RPMs. Containerd is v1.7.36 and all five targeted GLib packages are exactly 2.78.6-150600.4.41.1. Published VEX-aware Trivy reports contain zero vulnerabilities at all severities and zero secrets. Grype scanning remains enabled and reports 78 matches per architecture (2 Critical, 24 High, 48 Medium, 4 Low); these remain in the reports without new suppressions. Both jobs pass under the unchanged existing inform-mode gates.
  • go mod verify, containerd's upstream TestWalk*/TestDispatch* regression tests, and BCI floor resolution passed. Verified baseline reports and a fresh Trivy scan positively detect all six target rows on the delivered image. Existing PR #292 floor-control evidence verifies rejection of unavailable requirements.
  • Signed durable evidence retains byte-identical candidate/publication report archives, artifact digests, identities, inventories, checksums and the isolated one-off workflow. Reports and validation output remain outside the product diff.

Scope follows the operator's exact scanners == ["Trivy"] filter and Remco's October 2 direction: remediate Trivy findings, retain Grype scanning and existing gates. Product CI is byte-identical to master, including with-grype: true and its existing inform mode. No ignore rule, suppression, VEX statement or exception was added. The supplemental publication workflow has also been corrected to retain Grype; dual-scanner publication run 36994560497 passed on the same published digests with Grype findings retained. This supersedes the earlier Trivy-only supplemental run for scanner coverage; its signed historical checkpoint is preserved. Locally built CI candidates retain the known UNKNOWN GO-2026-5932 and unchanged September 10-expired bridge exception (#27); actual published-image reports clear it through the existing VEX configuration. The maintained OpenPGP-absence control passed on both architectures. No VEX or exception was changed. Inform-mode workflow success alone is not merge authorization.

Outstanding: independent review of this new source/publication checkpoint, human merge/release/promotion approval, and later chart adoption/delivery verification. The supervisor owns ticket/Project updates.

Base automatically changed from cve-otel-81870-candidate to master September 20, 2026 07:08
@ai-collaboration-app ai-collaboration-app Bot changed the title Require patched PCRE2 and glibc in the BCI runtime Fix Trivy containerd and GLib CVEs in the BCI runtime Oct 2, 2026
@rb3ckers
rb3ckers merged commit 00f5597 into master Oct 2, 2026
9 checks passed
@rb3ckers
rb3ckers deleted the cve-pcre2-glibc-runtime branch October 2, 2026 11:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants