Repository navigation
fix(deploy): clear the image scan and the dependency audit - #1044
Merged
Merged
Conversation
The image scan fails on every pull request: perl-base has fixed versions for CVE-2026-13221 and CVE-2026-42496 that the cached patch layer predates. Raise OS_PATCH_DATE, the layer's cache key (#1006). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
pip-audit fails on every pull request: fsspec 2026.3.0, fixed in 2026.6.0. Only the lock file's fsspec entry changes (uv lock --no-sources --upgrade-package fsspec). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR 마다 실패하는 두 검사를 푼다. 둘 다 저장소의 코드가 아니라 바깥에서 새로 공개된 취약점 때문이다.
1.
docker build and scan— OS 패치 레이어#1043 의 잡에서 Trivy 가
Total: 7 (HIGH: 4, CRITICAL: 3)을 보고했다. 그중perl-base의 CVE-2026-13221, CVE-2026-42496 은 수정 버전(5.36.0-7+deb12u4)이 나와 있다.Dockerfile의OS_PATCH_DATE를2026-10-04→2026-10-06으로 올렸다. #1006 이 만들어 둔 그 레이어의 캐시 키다 — 날짜를 올리면apt-get upgrade레이어가 다시 만들어진다.이 PR 의 첫 커밋에서 그 잡은 통과했다(실패 목록에서 사라졌다).
2.
Dependency audit (pip-audit)— fsspecuv lock --no-sources --upgrade-package fsspec→2026.3.0 → 2026.9.0. 잠금 파일에서 바뀐 것은 fsspec 항목의 버전·sdist·wheel 네 줄뿐이다(git diff로 확인).uv lock --no-sources --check통과.처음에는
--no-sources없이 돌려서 kpubdata 가 로컬 editable 소스로 잠기는 변경이 섞였다 — 버리고 다시 만들었다. CI 가--no-sources로 설치하므로 잠금도 그렇게 만들어야 한다.검증
perl-base의 둘이다.🤖 Generated with Claude Code