Skip to content

Fix Trivy findings in embedded Python packages and containerd - #542

Open
ai-collaboration-app[bot] wants to merge 4 commits into
stackstate-7.78.2from
cve/trivy-dependencies-20261002
Open

ai-collaboration-app[bot] wants to merge 4 commits into
stackstate-7.78.2from
cve/trivy-dependencies-20261002

Conversation

@ai-collaboration-app

@ai-collaboration-app ai-collaboration-app Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Tracking and detailed evidence: https://github.com/StackVista/cve-reporter/issues/29

Upgrade PyJWT to 2.15.0, urllib3 to 2.8.0, oauthlib to 4.0.0 and containerd to 1.7.36 for the 19 assigned Trivy findings; retain the PyJWT regression.

MERGE HOLD — merge-ready handoff withdrawn. Integrations #382 is merged, but this PR pins its unreleased commit. A verified released integrations version is required. No release is approved.

Proposed only: 7.78.2-7 (tag/release absent; latest tag 7.78.2-6), targeting merged source 9489042512f704ce00b82461207343ec7402d709, tree c1c2030398c048a42b31e8f12165c36e166bcc87, identical to reviewed integrations source. Merged-source CI is green. An approved signed tag push triggers checks-tests.yml: all 20 suites, validation, Zizmor and CI-success gate; no separate release/publisher workflow.

Preserved green evidence at signed agent head 1a18c978 (zero assigned findings in AMD64/ARM64 packages/images): binary builds, lint/unit tests, DEB/images/security/scans.

After explicit release approval, verify the tag/signature/source/tree and green tag CI, then adopt the released version with a signed commit and renew exact-head CI, packaged scans and independent review. Human merge, production release/promotion/deployment and existing VEX/interpreter holds remain.

Residuals: Trivy UNKNOWN GO-2026-5932, Grype-only findings and baseline local logExtractionError lint failure. Grype scans/gates are unchanged; no VEX, ignores, suppressions or exceptions added.

dependabot Bot and others added 4 commits September 25, 2026 20:21
Bumps [github.com/containerd/containerd](https://github.com/containerd/containerd) from 1.7.35 to 1.7.36.
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v1.7.35...v1.7.36)

---
updated-dependencies:
- dependency-name: github.com/containerd/containerd
  dependency-version: 1.7.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant