Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 4 additions & 43 deletions .trivyignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,26 +2,10 @@
# See https://aquasecurity.github.io/trivy/v0.35/docs/vulnerability/examples/filter/
# for more details

# libpng OOB read in png_image_read_composite - uid2-operator is a pure Java service
# that never calls into libpng's simplified PNG processing API; the JVM does not use
# libpng for image handling. Fix is available in Alpine 3.23 >= 1.6.53-r0 but the
# pinned eclipse-temurin image has not yet been rebuilt with it (tracked alongside
# sibling CVE-2026-25646 which shares the same base-image lag). See: UID2-6385
CVE-2025-66293 exp:2026-09-15

# jackson-core async parser DoS - not exploitable, services only use synchronous ObjectMapper API
# See: UID2-6670
GHSA-72hv-8253-57qq exp:2026-09-01

# libpng heap buffer overflow in Alpine base image - fixed version not yet available in Alpine 3.23
# See: UID2-6677
CVE-2026-25646 exp:2026-09-02

# zlib contrib/untgz demo utility buffer overflow - not exploitable, Alpine does not ship the untgz binary
# and the core libz library used by the JRE is unaffected. The zlib maintainer disputes this CVE.
# See: UID2-6704
CVE-2026-22184 exp:2026-09-09

# CVE-2026-42577 — netty-transport-native-epoll DoS via RST on half-closed TCP connection.
# Advisory: https://github.com/netty/netty/security/advisories/GHSA-rwm7-x88c-3g2p
# Server-side bug; netty maintainers backported the fix only to 4.2.13.Final and we run on
Expand All @@ -31,35 +15,11 @@ CVE-2026-22184 exp:2026-09-09
# Availability only (C:N/I:N/A:H). Tracking via UID2-7035; revisit on vert.x 5 migration.
CVE-2026-42577 exp:2026-09-11

# CVE-2026-2100 — p11-kit NULL dereference via C_DeriveKey in the Alpine base image.
# uid2-operator is a pure Java service; the JVM uses JSSE for TLS and the bundled Java cacerts keystore for trust — it does
# not load the native p11-kit PKCS#11 module loader and never calls C_DeriveKey, so the
# vulnerable code path is not reachable. Fixed in Alpine v3.23 >= 0.26.2-r0 but the pinned
# eclipse-temurin base image has not yet been rebuilt with it.
# See: UID2-7376
CVE-2026-2100 exp:2026-09-01

# CVE-2026-56131 / CVE-2026-56407 / CVE-2026-56408 — libexpat stack exhaustion / integer overflows
# in the Alpine base image. uid2-operator is a pure Java service; the JVM parses XML via the built-in
# JAXP/Xerces implementation, not the native libexpat C library, and there are no JNI bindings or
# native deps that call into libexpat, so the crafted-XML attack path is not reachable. Fixed in
# Alpine v3.23 libexpat >= 2.8.2-r0; the pinned eclipse-temurin base image has not yet been rebuilt with it.
# See: UID2-7456
CVE-2026-56131 exp:2026-08-09
CVE-2026-56407 exp:2026-08-09
# CVE-2026-56408 — libexpat (Alpine base image, transitive via eclipse-temurin:21-jre-
# alpine-3.23) (HIGH).
# Not exploitable here: Same alpine base (adds only gcompat for Corretto crypto). No native
# libexpat path; pure-Java XML via JAXP. Nitro builder is a separate ubuntu:22.04 build stage,
# not the scanned runtime image.
# See: UID2-7656
CVE-2026-56408 exp:2026-11-11

# jackson-core async parser maxNumberLength bypass (GHSA-r7wm-3cxj-wff9) - incomplete fix for
# GHSA-72hv-8253-57qq. Not exploitable: services only use the synchronous ObjectMapper API, not
# jackson-core's non-blocking/async parser. A jackson bump is also in flight via uid2-shared
# (PR #631) and will flow on the next release. See: UID2-7557 (predecessor UID2-6670)
GHSA-r7wm-3cxj-wff9 exp:2026-08-23
# jackson-core's non-blocking/async parser. Note: uid2-shared PR #631 (previously cited here as
# "in flight") was reverted in #633 — not a fix for this GHSA. See: UID2-7557 (predecessor UID2-6670)
GHSA-r7wm-3cxj-wff9 exp:2026-09-27

# CVE-2026-40984 — io.micrometer:micrometer-core (transitive via micrometer-registry-
# prometheus/-jmx); micrometer-jetty11/12 not present (HIGH).
Expand All @@ -68,3 +28,4 @@ GHSA-r7wm-3cxj-wff9 exp:2026-08-23
# by Vert.x instrumentation, not Micrometer's vulnerable HTTP server binder
# See: UID2-7662
CVE-2026-40984 exp:2026-11-11

6 changes: 3 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-3f08b13888f595cc49edabea7250ba69499ba25602b267da591720769400e08c
FROM eclipse-temurin@sha256:3f08b13888f595cc49edabea7250ba69499ba25602b267da591720769400e08c
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d
FROM eclipse-temurin@sha256:319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d

# For Amazon Corretto Crypto Provider
RUN apk add --no-cache gcompat
RUN apk add --no-cache gcompat && apk add --no-cache --upgrade libcrypto3 libssl3

WORKDIR /app
EXPOSE 8080
Expand Down
4 changes: 2 additions & 2 deletions scripts/azure-cc/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-3f08b13888f595cc49edabea7250ba69499ba25602b267da591720769400e08c
FROM eclipse-temurin@sha256:3f08b13888f595cc49edabea7250ba69499ba25602b267da591720769400e08c
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d
FROM eclipse-temurin@sha256:319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d

# Install necessary packages and set up virtual environment
RUN apk update && apk add --no-cache jq python3 py3-pip && \
Expand Down
4 changes: 2 additions & 2 deletions scripts/gcp-oidc/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-3f08b13888f595cc49edabea7250ba69499ba25602b267da591720769400e08c
FROM eclipse-temurin@sha256:3f08b13888f595cc49edabea7250ba69499ba25602b267da591720769400e08c
# sha from https://hub.docker.com/layers/library/eclipse-temurin/21-jre-alpine-3.23/images/sha256-319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d
FROM eclipse-temurin@sha256:319339a7fc9c7b59478cbed0340b6ba4944b45384a6eba3b0086856f4af08d8d

LABEL "tee.launch_policy.allow_env_override"="API_TOKEN_SECRET_NAME,DEPLOYMENT_ENVIRONMENT,CORE_BASE_URL,OPTOUT_BASE_URL,DEBUG_MODE,SKIP_VALIDATIONS"
LABEL "tee.launch_policy.log_redirect"="always"
Expand Down