Skip to content

Drop Python 3.10 and fix scan exceptions after the version update - #22

Merged
csandanov merged 1 commit into
masterfrom
chore/drop-python310
Oct 4, 2026
Merged

csandanov merged 1 commit into
masterfrom
chore/drop-python310

Conversation

@csandanov

Copy link
Copy Markdown
Member

Builds for Python 3.10–3.13 have failed the vulnerability scan since the version update on 2026-10-02, so revision r3 was never published. The scan exceptions were pinned to the previous Python versions and stopped matching once the versions changed.

This change makes the builds pass again:

Details

  • .grype.yaml: a single rule, CVE-2026-82049 for the python binary at exactly 3.11.17.
  • Removed PYTHON310 from the workflow matrix, the revision alias map, the base image pins, and the README tag list.

Validation

  • The pull request build runs the full matrix including the scan.

Follow-up

  • Tag a new image revision after merging; r3 points at a commit that cannot pass the scan.

Closes #10
Closes #12

Python 3.10 reaches end of life this month and its builds fail the vulnerability scan, so it is no longer built. Published 3.10 tags stay available.

The scan exceptions were pinned to the previous Python versions and stopped matching after the version update. 3.12.15 and 3.13.16 now pass without an exception. 3.11.17 contains the upstream tarfile fix, but the vulnerability data does not list a fixed 3.11 release yet, so CVE-2026-82049 is ignored for exactly that version.
@csandanov
csandanov merged commit f3f3447 into master Oct 4, 2026
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remove CVE-2026-82049 exception after fixed Python 3.13 release Remove temporary CVE-2026-7210 exception after fixed Python 3.10 release

1 participant