From caa4ca6cd1e10a3002b3ed31b756f61b21200b3b Mon Sep 17 00:00:00 2001 From: Chingis S Date: Sun, 4 Oct 2026 23:00:51 +0700 Subject: [PATCH] Drop Python 3.10 and accept the scanner false positive for 3.11.17 Python 3.10 reaches end of life this month and its builds fail the vulnerability scan, so it is no longer built. Published 3.10 tags stay available. The scan exceptions were pinned to the previous Python versions and stopped matching after the version update. 3.12.15 and 3.13.16 now pass without an exception. 3.11.17 contains the upstream tarfile fix, but the vulnerability data does not list a fixed 3.11 release yet, so CVE-2026-82049 is ignored for exactly that version. --- .github/workflows/workflow.yml | 4 +--- .grype.yaml | 31 ++++--------------------------- .image-revision-aliases.json | 25 ------------------------- README.md | 3 --- base-images.mk | 1 - 5 files changed, 5 insertions(+), 59 deletions(-) diff --git a/.github/workflows/workflow.yml b/.github/workflows/workflow.yml index 0ac0c68..5b6c379 100644 --- a/.github/workflows/workflow.yml +++ b/.github/workflows/workflow.yml @@ -16,7 +16,6 @@ env: PYTHON313: '3.13.16' PYTHON312: '3.12.15' PYTHON311: '3.11.17' - PYTHON310: '3.10.22' jobs: setup: @@ -31,8 +30,7 @@ jobs: {"key": "python314", "version": "${{ env.PYTHON314 }}", "latest": "latest", "latest_major": "3"}, {"key": "python313", "version": "${{ env.PYTHON313 }}", "latest": "", "latest_major": ""}, {"key": "python312", "version": "${{ env.PYTHON312 }}", "latest": "", "latest_major": ""}, - {"key": "python311", "version": "${{ env.PYTHON311 }}", "latest": "", "latest_major": ""}, - {"key": "python310", "version": "${{ env.PYTHON310 }}", "latest": "", "latest_major": ""} + {"key": "python311", "version": "${{ env.PYTHON311 }}", "latest": "", "latest_major": ""} ] EOF echo "python-versions=$(cat versions.json | jq -c .)" >> $GITHUB_OUTPUT diff --git a/.grype.yaml b/.grype.yaml index d3cb027..558b527 100644 --- a/.grype.yaml +++ b/.grype.yaml @@ -1,32 +1,9 @@ -# Temporary acceptance of CVE-2026-7210 in the unpatched upstream Python 3.10.21. -# Remove after adopting an official Python 3.10 image containing the XML hash-salt fix. -# Tracked in https://github.com/wodby/python/issues/10 +# Python 3.11.17 contains the upstream tarfile fix, but the vulnerability data does not list a +# fixed 3.11 release yet: https://github.com/python/cpython/pull/158455 +# Remove once the scan passes without it: https://github.com/wodby/python/issues/21 ignore: - - vulnerability: CVE-2026-7210 - package: - name: python - version: 3.10.21 - type: binary - # Temporary acceptance until the official Python 3.10–3.13 images include the tarfile fix. - # https://github.com/python/cpython/pull/157192 - # Remove after upgrading: https://github.com/wodby/python/issues/12 - - vulnerability: CVE-2026-82049 - package: - name: python - version: 3.13.15 - type: binary - - vulnerability: CVE-2026-82049 - package: - name: python - version: 3.12.14 - type: binary - - vulnerability: CVE-2026-82049 - package: - name: python - version: 3.11.16 - type: binary - vulnerability: CVE-2026-82049 package: name: python - version: 3.10.21 + version: 3.11.17 type: binary diff --git a/.image-revision-aliases.json b/.image-revision-aliases.json index 7b826b0..70685cc 100644 --- a/.image-revision-aliases.json +++ b/.image-revision-aliases.json @@ -104,31 +104,6 @@ "full": "{version}-dev-macos" } ] - }, - { - "version": { - "env": "PYTHON310" - }, - "variants": [ - { - "short": [ - "{minor}" - ], - "full": "{version}" - }, - { - "short": [ - "{minor}-dev" - ], - "full": "{version}-dev" - }, - { - "short": [ - "{minor}-dev-macos" - ], - "full": "{version}-dev-macos" - } - ] } ] } diff --git a/README.md b/README.md index cdd89dd..6dd8f6a 100644 --- a/README.md +++ b/README.md @@ -43,17 +43,14 @@ Supported tags and respective `Dockerfile` links: - `3.13` [_(Dockerfile)_] - `3.12` [_(Dockerfile)_] - `3.11` [_(Dockerfile)_] -- `3.10` [_(Dockerfile)_] - `3.14-dev`, `3-dev` [_(Dockerfile)_] - `3.13-dev` [_(Dockerfile)_] - `3.12-dev` [_(Dockerfile)_] - `3.11-dev` [_(Dockerfile)_] -- `3.10-dev` [_(Dockerfile)_] - `3.14-dev-macos`, `3-dev-macos` [_(Dockerfile)_] - `3.13-dev-macos` [_(Dockerfile)_] - `3.12-dev-macos` [_(Dockerfile)_] - `3.11-dev-macos` [_(Dockerfile)_] -- `3.10-dev-macos` [_(Dockerfile)_] [_(Dockerfile)_]: https://github.com/wodby/python/tree/master/Dockerfile diff --git a/base-images.mk b/base-images.mk index 04300e8..6686a8a 100644 --- a/base-images.mk +++ b/base-images.mk @@ -3,7 +3,6 @@ BASE_IMAGE_REPOSITORY := python BASE_IMAGE_VERSION_SUFFIX := -alpine -BASE_IMAGE_DIGEST_3.10.22-alpine := sha256:c3a48015ed1daf66afcafa7a02b7a24af8a51b8037964c03de578032556ec5b3 BASE_IMAGE_DIGEST_3.11.17-alpine := sha256:faa35f7f7a56c17c2796719f9903b42cb17d59e671a6a74bf85549432e38770e BASE_IMAGE_DIGEST_3.12.15-alpine := sha256:8a001d79e5a57ae4de7faa57af12f3d589058ea06ac42ec850c1cb0ac325bd21 BASE_IMAGE_DIGEST_3.13.16-alpine := sha256:1ac543fc677b1e24cfb220f2e9f2c73d6d9f1d5e718c2bbe5801cae34732f899