Skip to content

fix(deploy): clear the image scan and the dependency audit - #1044

Merged
Eomdahyeon merged 2 commits into
mainfrom
fix/os-patch-date-2026-10-06
Oct 5, 2026
Merged

Eomdahyeon merged 2 commits into
mainfrom
fix/os-patch-date-2026-10-06

Conversation

@Eomdahyeon

@Eomdahyeon Eomdahyeon commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

PR 마다 실패하는 두 검사를 푼다. 둘 다 저장소의 코드가 아니라 바깥에서 새로 공개된 취약점 때문이다.

1. docker build and scan — OS 패치 레이어

#1043 의 잡에서 Trivy 가 Total: 7 (HIGH: 4, CRITICAL: 3) 을 보고했다. 그중 perl-base 의 CVE-2026-13221, CVE-2026-42496 은 수정 버전(5.36.0-7+deb12u4)이 나와 있다.

Dockerfile 의 OS_PATCH_DATE 를 2026-10-04 → 2026-10-06 으로 올렸다. #1006 이 만들어 둔 그 레이어의 캐시 키다 — 날짜를 올리면 apt-get upgrade 레이어가 다시 만들어진다.

이 PR 의 첫 커밋에서 그 잡은 통과했다(실패 목록에서 사라졌다).

2. Dependency audit (pip-audit) — fsspec

Found 1 known vulnerability in 1 package
Name   Version  ID              Fix Versions
fsspec 2026.3.0 CVE-2026-104851 2026.6.0

uv lock --no-sources --upgrade-package fsspec → 2026.3.0 → 2026.9.0. 잠금 파일에서 바뀐 것은 fsspec 항목의 버전·sdist·wheel 네 줄뿐이다(git diff 로 확인). uv lock --no-sources --check 통과.

처음에는 --no-sources 없이 돌려서 kpubdata 가 로컬 editable 소스로 잠기는 변경이 섞였다 — 버리고 다시 만들었다. CI 가 --no-sources 로 설치하므로 잠금도 그렇게 만들어야 한다.

검증

  • 로컬에서 이미지를 빌드하거나 스캔하지 않았다(디스크 여유가 없다). 판정은 이 PR 의 두 잡이다.
  • fsspec 2026.9.0 으로 테스트를 로컬에서 돌리지 않았다 — CI 에 맡긴다. fsspec 은 publish extra(Hugging Face 쪽)를 통해 들어온다.
  • Trivy 의 7건 중 이름을 확인한 것은 perl-base 의 둘이다.

🤖 Generated with Claude Code

Eomdahyeon and others added 2 commits October 6, 2026 08:07
The image scan fails on every pull request: perl-base has fixed versions for
CVE-2026-13221 and CVE-2026-42496 that the cached patch layer predates. Raise
OS_PATCH_DATE, the layer's cache key (#1006).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
pip-audit fails on every pull request: fsspec 2026.3.0, fixed in 2026.6.0.
Only the lock file's fsspec entry changes (uv lock --no-sources
--upgrade-package fsspec).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Eomdahyeon Eomdahyeon changed the title fix(deploy): rebuild the OS patch layer for the 2026-10-06 Debian fixes fix(deploy): clear the image scan and the dependency audit Oct 5, 2026
@Eomdahyeon
Eomdahyeon merged commit cabbda1 into main Oct 5, 2026
25 checks passed
@yeongseon
yeongseon deleted the fix/os-patch-date-2026-10-06 branch October 7, 2026 22:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant