diff --git a/products/relay-v2/security/advisory-baseline.json b/products/relay-v2/security/advisory-baseline.json index b33618396..8e4b408c8 100644 --- a/products/relay-v2/security/advisory-baseline.json +++ b/products/relay-v2/security/advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:753b9fb0d92961dfac809c9338af4da0cae9360e7f75fd918ff42845d362f4a3", + "sha256:09f15108ffc6e06dc7b3d8087ae30c15cd59ef95df063358ea7f9eca45735652", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -52,7 +52,7 @@ "exposed_ports": ["8080/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:5d4778c28a757951aa132bae444460348318d49cfe42474d0226a40084a8d67b" + "definition_digest": "sha256:4691a407b98e5ebcf560c2b488bd79d5e09bd3ec2ab3393ed9b4eb2e8354e39d" }, "policies": [ { @@ -75,9 +75,9 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.0 Linux AMD64 Relay candidate had exactly two __isoc23_sscanf call sites using fixed-format %lu and %lx conversions and no allocating-character scanf conversion in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.1 Linux AMD64 Relay candidate had exactly two __isoc23_sscanf call sites using fixed-format %lu and %lx conversions and no allocating-character scanf conversion in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -93,14 +93,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:5d4778c28a757951aa132bae444460348318d49cfe42474d0226a40084a8d67b", + "runtime_definition_digest": "sha256:4691a407b98e5ebcf560c2b488bd79d5e09bd3ec2ab3393ed9b4eb2e8354e39d", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:64052a8a9aa86f7e68559f4343dfa22ac7d4b19c244fc2989ae3f0d967ec99a4", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:ff8e8d84143d3af01930d0ddc65c8b894f367b31b66f0b5d163854cd7d28dea8", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:5d4778c28a757951aa132bae444460348318d49cfe42474d0226a40084a8d67b", + "runtime_definition_digest": "sha256:4691a407b98e5ebcf560c2b488bd79d5e09bd3ec2ab3393ed9b4eb2e8354e39d", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -120,10 +120,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:9b11cedbd6157818f8c69748b06cfe72e7d1d550d44867cd979a0a8a8f991b01" + "sha256": "sha256:81417e719f4fb66d32b9b642d8077b37a02c37312db0de92f8da615a26b06124" } ], - "definition_digest": "sha256:31bd2c31158006c1f8b30d07414fb9af596e34014d19acf71fd1342c555d125a" + "definition_digest": "sha256:178e530b0214a1567de96f775578584214bf3be5af617271659b2d950d2ea8ae" } }, { @@ -133,9 +133,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.0 Linux AMD64 Relay candidate imported no ungetwc, getwc, fgetwc, wscanf, fwscanf, or swscanf symbol and had no effective wide-character input path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.1 Linux AMD64 Relay candidate imported no ungetwc, getwc, fgetwc, wscanf, fwscanf, or swscanf symbol and had no effective wide-character input path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -151,14 +151,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:5d4778c28a757951aa132bae444460348318d49cfe42474d0226a40084a8d67b", + "runtime_definition_digest": "sha256:4691a407b98e5ebcf560c2b488bd79d5e09bd3ec2ab3393ed9b4eb2e8354e39d", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:64052a8a9aa86f7e68559f4343dfa22ac7d4b19c244fc2989ae3f0d967ec99a4", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:ff8e8d84143d3af01930d0ddc65c8b894f367b31b66f0b5d163854cd7d28dea8", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:5d4778c28a757951aa132bae444460348318d49cfe42474d0226a40084a8d67b", + "runtime_definition_digest": "sha256:4691a407b98e5ebcf560c2b488bd79d5e09bd3ec2ab3393ed9b4eb2e8354e39d", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -178,10 +178,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:9b11cedbd6157818f8c69748b06cfe72e7d1d550d44867cd979a0a8a8f991b01" + "sha256": "sha256:81417e719f4fb66d32b9b642d8077b37a02c37312db0de92f8da615a26b06124" } ], - "definition_digest": "sha256:31bd2c31158006c1f8b30d07414fb9af596e34014d19acf71fd1342c555d125a" + "definition_digest": "sha256:178e530b0214a1567de96f775578584214bf3be5af617271659b2d950d2ea8ae" } }, { @@ -191,9 +191,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.26.0 Linux AMD64 Relay candidate imported __res_init and none of the deprecated resolver-printing helpers fp_nquery, fp_query, p_query, ns_sprintrr, or ns_sprintrrf. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.26.1 Linux AMD64 Relay candidate imported __res_init and none of the deprecated resolver-printing helpers fp_nquery, fp_query, p_query, ns_sprintrr, or ns_sprintrrf. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -209,14 +209,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:5d4778c28a757951aa132bae444460348318d49cfe42474d0226a40084a8d67b", + "runtime_definition_digest": "sha256:4691a407b98e5ebcf560c2b488bd79d5e09bd3ec2ab3393ed9b4eb2e8354e39d", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:64052a8a9aa86f7e68559f4343dfa22ac7d4b19c244fc2989ae3f0d967ec99a4", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:ff8e8d84143d3af01930d0ddc65c8b894f367b31b66f0b5d163854cd7d28dea8", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:5d4778c28a757951aa132bae444460348318d49cfe42474d0226a40084a8d67b", + "runtime_definition_digest": "sha256:4691a407b98e5ebcf560c2b488bd79d5e09bd3ec2ab3393ed9b4eb2e8354e39d", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -236,10 +236,68 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:9b11cedbd6157818f8c69748b06cfe72e7d1d550d44867cd979a0a8a8f991b01" + "sha256": "sha256:81417e719f4fb66d32b9b642d8077b37a02c37312db0de92f8da615a26b06124" } ], - "definition_digest": "sha256:31bd2c31158006c1f8b30d07414fb9af596e34014d19acf71fd1342c555d125a" + "definition_digest": "sha256:178e530b0214a1567de96f775578584214bf3be5af617271659b2d950d2ea8ae" + } + }, + { + "vulnerability_id": "CVE-2026-85091", + "package": "zlib1g", + "installed_version": "1:1.3.dfsg+really1.3.1-1+b1", + "severity": "High", + "status": "accepted_risk", + "owner": "@jeremi", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The official v0.26.1 Linux AMD64 Relay candidate from run 33873930773 attempt 1 neither links libz nor contains libz.so, gz_vacate, gzwrite, gzprintf, or gzvprintf in the reviewed executable bytes, so the vulnerable stalled non-blocking gzwrite followed by gzprintf/gzvprintf path is absent. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", + "invalidation_triggers": [ + "candidate_image_identity_mismatch", + "candidate_rootfs_changed", + "component_layer_changed", + "expired", + "exposure_assertion_changed", + "exposure_assertion_false", + "exposure_assertion_unevaluable", + "fix_available", + "material_finding_changed", + "package_version_changed", + "rootfs_evidence_mismatch", + "runtime_config_changed", + "runtime_base_changed" + ], + "runtime_definition_digest": "sha256:4691a407b98e5ebcf560c2b488bd79d5e09bd3ec2ab3393ed9b4eb2e8354e39d", + "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", + "exposure_assertion": { + "kind": "whole_image_fingerprint_equals", + "reference_image_digest": "sha256:ff8e8d84143d3af01930d0ddc65c8b894f367b31b66f0b5d163854cd7d28dea8", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:4691a407b98e5ebcf560c2b488bd79d5e09bd3ec2ab3393ed9b4eb2e8354e39d", + "files": [ + { + "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "sha256": "sha256:438c546d8e8cc48496bf3a95f753051afd9db66a629a74e31a9ded71586b56e0" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libc.so.6", + "sha256": "sha256:fa430b8f298f817a266046af84a77533185ad6fc4406c7d3787b5a0a0c207826" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "sha256": "sha256:30c61ab012a4241bed033725a09b61f5fdd3bb7df95ee852d0b096520524c7af" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libm.so.6", + "sha256": "sha256:6d567d53e895273ca14a1f9dc164fc6c8d39aed2f60aa46a733c2784228915f3" + }, + { + "path": "/usr/local/bin/relay", + "sha256": "sha256:81417e719f4fb66d32b9b642d8077b37a02c37312db0de92f8da615a26b06124" + } + ], + "definition_digest": "sha256:178e530b0214a1567de96f775578584214bf3be5af617271659b2d950d2ea8ae" } } ] diff --git a/release/scripts/test_check_advisory_baselines.py b/release/scripts/test_check_advisory_baselines.py index d9f81288f..7c74dd6e4 100644 --- a/release/scripts/test_check_advisory_baselines.py +++ b/release/scripts/test_check_advisory_baselines.py @@ -26,18 +26,18 @@ ROOT / "release/security/mint-advisory-baseline.json", ) LIVE_REFERENCE_IMAGE_DIGESTS = { - "relay": "sha256:64052a8a9aa86f7e68559f4343dfa22ac7d4b19c244fc2989ae3f0d967ec99a4", - "breg": "sha256:4bde5e4116a51c664385e62f47564a844a3e700f3e36066f6c91f0555b99907a", - "discovery": "sha256:0e2e21ccc1fec3fa40efa7855ee3ee745cfe588c4601dcd7a8a38661798bc589", - "evidence": "sha256:9b186ad6026466a1baab26d98cfd69759289325a4e094b9433abe1fc667833ce", - "mint": "sha256:a8c23cd64bc1d31c9413d283eaf5a8388ba0be0a2d011077a3bfe4e9380c3e57", + "relay": "sha256:ff8e8d84143d3af01930d0ddc65c8b894f367b31b66f0b5d163854cd7d28dea8", + "breg": "sha256:ff6faa69c81b62029578f50d47499165e3942a01cd2987b70984a920d5619239", + "discovery": "sha256:68b298259c0871c161a4f3f7c1ef4f0bb0a78e42051f833aa1d64a922ad75587", + "evidence": "sha256:3b2acf91f2095d565d06529175fc231414c0dd508844c2d09ad4522d7be03908", + "mint": "sha256:532598e7581716ce679cb83e10aa7d6c1ff9c134f0fcfc7ec9578818644db800", } -LIVE_REFERENCE_SOURCE_REVISION = "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4" +LIVE_REFERENCE_SOURCE_REVISION = "3e655214558e4479a72a2049ebf72bf5721a303e" # The date the live exceptions below were reviewed against, stated here rather # than derived from the baselines: deriving it from their own reviewed_at values # would make the checker's future-dated guard unreachable for the newest # exception. Move it forward by hand when the baselines are renewed. -LIVE_REVIEW_EVALUATION_DATE = "2026-09-03" +LIVE_REVIEW_EVALUATION_DATE = "2026-09-04" LIVE_REFERENCE_PROVENANCE = { "relay": "official_candidate", "breg": "official_candidate", diff --git a/release/security/breg-advisory-baseline.json b/release/security/breg-advisory-baseline.json index db3b73f9e..b6e4cecfd 100644 --- a/release/security/breg-advisory-baseline.json +++ b/release/security/breg-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:abe1242b6b576e55376437aed32cfc69b9095091d98dd45aac20c403844a9d5d", + "sha256:86409bcb66a9569af0418cfcba8000ea0ac642792de739b00edcfc5609959483", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -51,7 +51,7 @@ ], "stop_signal": "" }, - "definition_digest": "sha256:6b10251e32515b928487c58d587c78b48e4cad49f839159552b612bb86730887" + "definition_digest": "sha256:f2861235e2e554979f8415512c6f58144bdcb8fc9728131159f429cc6c6af793" }, "policies": [ { @@ -74,9 +74,9 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.0 Linux AMD64 BReg candidate has exactly two __isoc23_sscanf call sites; disassembly binds them to fixed %lu and %lx format strings, with no allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.1 Linux AMD64 BReg candidate has exactly two __isoc23_sscanf call sites; disassembly binds them to fixed %lu and %lx format strings, with no allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -92,14 +92,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:6b10251e32515b928487c58d587c78b48e4cad49f839159552b612bb86730887", + "runtime_definition_digest": "sha256:f2861235e2e554979f8415512c6f58144bdcb8fc9728131159f429cc6c6af793", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:4bde5e4116a51c664385e62f47564a844a3e700f3e36066f6c91f0555b99907a", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:ff6faa69c81b62029578f50d47499165e3942a01cd2987b70984a920d5619239", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:6b10251e32515b928487c58d587c78b48e4cad49f839159552b612bb86730887", + "runtime_definition_digest": "sha256:f2861235e2e554979f8415512c6f58144bdcb8fc9728131159f429cc6c6af793", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -119,10 +119,10 @@ }, { "path": "/usr/local/bin/breg", - "sha256": "sha256:7527a4fd147dbd2ea931737c08ceb14161015b5ed993902c8ada87211215b777" + "sha256": "sha256:26a02335b10b4fbdf2dd622dd7e37025e512c4ea6a85d7d969925bca20cce1cb" } ], - "definition_digest": "sha256:5bb391a2dcc186dfc2b66928453c3d9ff68aa2f3e99bcccfbf0cbc615a227c2f" + "definition_digest": "sha256:701d5410c8c0fdeeeeffd5cda585ae3c0c5f53c655b5a8f36fed5233820435fb" } }, { @@ -132,9 +132,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.0 Linux AMD64 BReg candidate imports no wide-character input function and contains no ungetwc or other wide-character input function name for dynamic resolution, so it has no effective vulnerable input path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.1 Linux AMD64 BReg candidate imports no wide-character input function and contains no ungetwc or other wide-character input function name for dynamic resolution, so it has no effective vulnerable input path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -150,14 +150,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:6b10251e32515b928487c58d587c78b48e4cad49f839159552b612bb86730887", + "runtime_definition_digest": "sha256:f2861235e2e554979f8415512c6f58144bdcb8fc9728131159f429cc6c6af793", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:4bde5e4116a51c664385e62f47564a844a3e700f3e36066f6c91f0555b99907a", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:ff6faa69c81b62029578f50d47499165e3942a01cd2987b70984a920d5619239", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:6b10251e32515b928487c58d587c78b48e4cad49f839159552b612bb86730887", + "runtime_definition_digest": "sha256:f2861235e2e554979f8415512c6f58144bdcb8fc9728131159f429cc6c6af793", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -177,10 +177,10 @@ }, { "path": "/usr/local/bin/breg", - "sha256": "sha256:7527a4fd147dbd2ea931737c08ceb14161015b5ed993902c8ada87211215b777" + "sha256": "sha256:26a02335b10b4fbdf2dd622dd7e37025e512c4ea6a85d7d969925bca20cce1cb" } ], - "definition_digest": "sha256:5bb391a2dcc186dfc2b66928453c3d9ff68aa2f3e99bcccfbf0cbc615a227c2f" + "definition_digest": "sha256:701d5410c8c0fdeeeeffd5cda585ae3c0c5f53c655b5a8f36fed5233820435fb" } }, { @@ -190,9 +190,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.26.0 Linux AMD64 BReg candidate imports __res_init but none of the deprecated ns_sprintrrf, ns_sprintrr, or fp_nquery functions and contains none of those function names for dynamic resolution. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.26.1 Linux AMD64 BReg candidate imports __res_init but none of the deprecated ns_sprintrrf, ns_sprintrr, or fp_nquery functions and contains none of those function names for dynamic resolution. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -208,14 +208,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:6b10251e32515b928487c58d587c78b48e4cad49f839159552b612bb86730887", + "runtime_definition_digest": "sha256:f2861235e2e554979f8415512c6f58144bdcb8fc9728131159f429cc6c6af793", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:4bde5e4116a51c664385e62f47564a844a3e700f3e36066f6c91f0555b99907a", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:ff6faa69c81b62029578f50d47499165e3942a01cd2987b70984a920d5619239", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:6b10251e32515b928487c58d587c78b48e4cad49f839159552b612bb86730887", + "runtime_definition_digest": "sha256:f2861235e2e554979f8415512c6f58144bdcb8fc9728131159f429cc6c6af793", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -235,10 +235,68 @@ }, { "path": "/usr/local/bin/breg", - "sha256": "sha256:7527a4fd147dbd2ea931737c08ceb14161015b5ed993902c8ada87211215b777" + "sha256": "sha256:26a02335b10b4fbdf2dd622dd7e37025e512c4ea6a85d7d969925bca20cce1cb" } ], - "definition_digest": "sha256:5bb391a2dcc186dfc2b66928453c3d9ff68aa2f3e99bcccfbf0cbc615a227c2f" + "definition_digest": "sha256:701d5410c8c0fdeeeeffd5cda585ae3c0c5f53c655b5a8f36fed5233820435fb" + } + }, + { + "vulnerability_id": "CVE-2026-85091", + "package": "zlib1g", + "installed_version": "1:1.3.dfsg+really1.3.1-1+b1", + "severity": "High", + "status": "accepted_risk", + "owner": "@jeremi", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The official v0.26.1 Linux AMD64 BReg candidate from run 33873930773 attempt 1 neither links libz nor contains libz.so, gz_vacate, gzwrite, gzprintf, or gzvprintf in the reviewed executable bytes, so the vulnerable stalled non-blocking gzwrite followed by gzprintf/gzvprintf path is absent. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", + "invalidation_triggers": [ + "candidate_image_identity_mismatch", + "candidate_rootfs_changed", + "component_layer_changed", + "expired", + "exposure_assertion_changed", + "exposure_assertion_false", + "exposure_assertion_unevaluable", + "fix_available", + "material_finding_changed", + "package_version_changed", + "rootfs_evidence_mismatch", + "runtime_config_changed", + "runtime_base_changed" + ], + "runtime_definition_digest": "sha256:f2861235e2e554979f8415512c6f58144bdcb8fc9728131159f429cc6c6af793", + "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", + "exposure_assertion": { + "kind": "whole_image_fingerprint_equals", + "reference_image_digest": "sha256:ff6faa69c81b62029578f50d47499165e3942a01cd2987b70984a920d5619239", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:f2861235e2e554979f8415512c6f58144bdcb8fc9728131159f429cc6c6af793", + "files": [ + { + "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "sha256": "sha256:438c546d8e8cc48496bf3a95f753051afd9db66a629a74e31a9ded71586b56e0" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libc.so.6", + "sha256": "sha256:fa430b8f298f817a266046af84a77533185ad6fc4406c7d3787b5a0a0c207826" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "sha256": "sha256:30c61ab012a4241bed033725a09b61f5fdd3bb7df95ee852d0b096520524c7af" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libm.so.6", + "sha256": "sha256:6d567d53e895273ca14a1f9dc164fc6c8d39aed2f60aa46a733c2784228915f3" + }, + { + "path": "/usr/local/bin/breg", + "sha256": "sha256:26a02335b10b4fbdf2dd622dd7e37025e512c4ea6a85d7d969925bca20cce1cb" + } + ], + "definition_digest": "sha256:701d5410c8c0fdeeeeffd5cda585ae3c0c5f53c655b5a8f36fed5233820435fb" } } ] diff --git a/release/security/discovery-advisory-baseline.json b/release/security/discovery-advisory-baseline.json index 48eec61b9..5837bb32f 100644 --- a/release/security/discovery-advisory-baseline.json +++ b/release/security/discovery-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:bd9b46c222970650762faefb4d0bf1524c3082658527a765133546c39b8f1e47" + "sha256:fe5ac30aa3a09070a61c279f59c9eb3d7915515aab4ee237eed5c1618f506e6e" ], "config": { "user": "65532", @@ -43,7 +43,7 @@ "exposed_ports": ["8080/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:91d2bac3f45cdc2eb4d6ddbd3dd1d5618af0ce9a2790c2875abe05817863cd97" + "definition_digest": "sha256:931adb354de49dd2ab85ea32e5e1fed47adc610444f5e7e3c4777fd1660b80bb" }, "policies": [ { @@ -66,9 +66,9 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.0 Linux AMD64 Discovery candidate reaches no scanf-family function: the reviewed binary imports none of the glibc scanf entry points, including the __isoc23_ aliases, and embeds no scanf symbol name to resolve dynamically, so no vulnerable allocating-character scanf path exists in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.1 Linux AMD64 Discovery candidate reaches no scanf-family function: the reviewed binary imports none of the glibc scanf entry points, including the __isoc23_ aliases, and embeds no scanf symbol name to resolve dynamically, so no vulnerable allocating-character scanf path exists in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -84,14 +84,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:91d2bac3f45cdc2eb4d6ddbd3dd1d5618af0ce9a2790c2875abe05817863cd97", + "runtime_definition_digest": "sha256:931adb354de49dd2ab85ea32e5e1fed47adc610444f5e7e3c4777fd1660b80bb", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0e2e21ccc1fec3fa40efa7855ee3ee745cfe588c4601dcd7a8a38661798bc589", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:68b298259c0871c161a4f3f7c1ef4f0bb0a78e42051f833aa1d64a922ad75587", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:91d2bac3f45cdc2eb4d6ddbd3dd1d5618af0ce9a2790c2875abe05817863cd97", + "runtime_definition_digest": "sha256:931adb354de49dd2ab85ea32e5e1fed47adc610444f5e7e3c4777fd1660b80bb", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -111,10 +111,10 @@ }, { "path": "/usr/local/bin/discovery", - "sha256": "sha256:1401e0a66b6dd9b9c8c609aa718ea487fd6fb731d4a8f90d7edc2a3e754d68d4" + "sha256": "sha256:b13aeda4420d9d7bff514d38a3aef80f8e445141f18b4d266dd16e8229f64ad7" } ], - "definition_digest": "sha256:b458dd0df3c488a43db8c8fb8ab6de3a4d8bccca33dba4d589e44bef023fd202" + "definition_digest": "sha256:4e36b1712f547620139bb63c701207f8c4fa101e6100e3a344cd1bed776a4a46" } }, { @@ -124,9 +124,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.0 Linux AMD64 Discovery candidate imports no wide-character or ungetwc function and embeds no ungetwc symbol name, so no vulnerable wide-character pushback path exists in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.1 Linux AMD64 Discovery candidate imports no wide-character or ungetwc function and embeds no ungetwc symbol name, so no vulnerable wide-character pushback path exists in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -142,14 +142,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:91d2bac3f45cdc2eb4d6ddbd3dd1d5618af0ce9a2790c2875abe05817863cd97", + "runtime_definition_digest": "sha256:931adb354de49dd2ab85ea32e5e1fed47adc610444f5e7e3c4777fd1660b80bb", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0e2e21ccc1fec3fa40efa7855ee3ee745cfe588c4601dcd7a8a38661798bc589", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:68b298259c0871c161a4f3f7c1ef4f0bb0a78e42051f833aa1d64a922ad75587", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:91d2bac3f45cdc2eb4d6ddbd3dd1d5618af0ce9a2790c2875abe05817863cd97", + "runtime_definition_digest": "sha256:931adb354de49dd2ab85ea32e5e1fed47adc610444f5e7e3c4777fd1660b80bb", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -169,10 +169,10 @@ }, { "path": "/usr/local/bin/discovery", - "sha256": "sha256:1401e0a66b6dd9b9c8c609aa718ea487fd6fb731d4a8f90d7edc2a3e754d68d4" + "sha256": "sha256:b13aeda4420d9d7bff514d38a3aef80f8e445141f18b4d266dd16e8229f64ad7" } ], - "definition_digest": "sha256:b458dd0df3c488a43db8c8fb8ab6de3a4d8bccca33dba4d589e44bef023fd202" + "definition_digest": "sha256:4e36b1712f547620139bb63c701207f8c4fa101e6100e3a344cd1bed776a4a46" } }, { @@ -182,9 +182,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.0 Linux AMD64 Discovery candidate imports none of the deprecated resolver-printing functions ns_sprintrrf, ns_sprintrr, or fp_nquery and embeds none of those names, so no vulnerable TSIG record printing path exists in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.1 Linux AMD64 Discovery candidate imports none of the deprecated resolver-printing functions ns_sprintrrf, ns_sprintrr, or fp_nquery and embeds none of those names, so no vulnerable TSIG record printing path exists in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -200,14 +200,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:91d2bac3f45cdc2eb4d6ddbd3dd1d5618af0ce9a2790c2875abe05817863cd97", + "runtime_definition_digest": "sha256:931adb354de49dd2ab85ea32e5e1fed47adc610444f5e7e3c4777fd1660b80bb", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0e2e21ccc1fec3fa40efa7855ee3ee745cfe588c4601dcd7a8a38661798bc589", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:68b298259c0871c161a4f3f7c1ef4f0bb0a78e42051f833aa1d64a922ad75587", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:91d2bac3f45cdc2eb4d6ddbd3dd1d5618af0ce9a2790c2875abe05817863cd97", + "runtime_definition_digest": "sha256:931adb354de49dd2ab85ea32e5e1fed47adc610444f5e7e3c4777fd1660b80bb", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -227,10 +227,68 @@ }, { "path": "/usr/local/bin/discovery", - "sha256": "sha256:1401e0a66b6dd9b9c8c609aa718ea487fd6fb731d4a8f90d7edc2a3e754d68d4" + "sha256": "sha256:b13aeda4420d9d7bff514d38a3aef80f8e445141f18b4d266dd16e8229f64ad7" } ], - "definition_digest": "sha256:b458dd0df3c488a43db8c8fb8ab6de3a4d8bccca33dba4d589e44bef023fd202" + "definition_digest": "sha256:4e36b1712f547620139bb63c701207f8c4fa101e6100e3a344cd1bed776a4a46" + } + }, + { + "vulnerability_id": "CVE-2026-85091", + "package": "zlib1g", + "installed_version": "1:1.3.dfsg+really1.3.1-1+b1", + "severity": "High", + "status": "accepted_risk", + "owner": "@jeremi", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The official v0.26.1 Linux AMD64 Discovery candidate from run 33873930773 attempt 1 neither links libz nor contains libz.so, gz_vacate, gzwrite, gzprintf, or gzvprintf in the reviewed executable bytes, so the vulnerable stalled non-blocking gzwrite followed by gzprintf/gzvprintf path is absent. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", + "invalidation_triggers": [ + "candidate_image_identity_mismatch", + "candidate_rootfs_changed", + "component_layer_changed", + "expired", + "exposure_assertion_changed", + "exposure_assertion_false", + "exposure_assertion_unevaluable", + "fix_available", + "material_finding_changed", + "package_version_changed", + "rootfs_evidence_mismatch", + "runtime_config_changed", + "runtime_base_changed" + ], + "runtime_definition_digest": "sha256:931adb354de49dd2ab85ea32e5e1fed47adc610444f5e7e3c4777fd1660b80bb", + "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", + "exposure_assertion": { + "kind": "whole_image_fingerprint_equals", + "reference_image_digest": "sha256:68b298259c0871c161a4f3f7c1ef4f0bb0a78e42051f833aa1d64a922ad75587", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:931adb354de49dd2ab85ea32e5e1fed47adc610444f5e7e3c4777fd1660b80bb", + "files": [ + { + "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "sha256": "sha256:438c546d8e8cc48496bf3a95f753051afd9db66a629a74e31a9ded71586b56e0" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libc.so.6", + "sha256": "sha256:fa430b8f298f817a266046af84a77533185ad6fc4406c7d3787b5a0a0c207826" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "sha256": "sha256:30c61ab012a4241bed033725a09b61f5fdd3bb7df95ee852d0b096520524c7af" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libm.so.6", + "sha256": "sha256:6d567d53e895273ca14a1f9dc164fc6c8d39aed2f60aa46a733c2784228915f3" + }, + { + "path": "/usr/local/bin/discovery", + "sha256": "sha256:b13aeda4420d9d7bff514d38a3aef80f8e445141f18b4d266dd16e8229f64ad7" + } + ], + "definition_digest": "sha256:4e36b1712f547620139bb63c701207f8c4fa101e6100e3a344cd1bed776a4a46" } } ] diff --git a/release/security/evidence-advisory-baseline.json b/release/security/evidence-advisory-baseline.json index 5d68a2b19..9c3d360c1 100644 --- a/release/security/evidence-advisory-baseline.json +++ b/release/security/evidence-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:ec168be2cb5e4a28a188c17e52b2cf5fbd457312770f2df75f7a63661a9c4b03", + "sha256:2e242cbc17151e40876b6a41b1f8b640095c9720cca0607334a2c2d62fd50098", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -45,7 +45,7 @@ "exposed_ports": ["8080/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:dc673d2a4ed65c37399a052133723498e0e2ce981241420c1b4170302b918a00" + "definition_digest": "sha256:fcfa4afaf77d079d8164194283708c986a2f7cd0862362a8e540f734f129ea9e" }, "policies": [ { @@ -68,9 +68,9 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and Grype reports no fix. The official v0.26.0 Linux AMD64 Evidence candidate from run 33811606748 attempt 1 imports __isoc23_sscanf at exactly two call sites, whose immutable format strings are %lu and %lx, and has no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and Grype reports no fix. The official v0.26.1 Linux AMD64 Evidence candidate from run 33873930773 attempt 1 imports __isoc23_sscanf at exactly two call sites, whose immutable format strings are %lu and %lx, and has no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -86,14 +86,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:dc673d2a4ed65c37399a052133723498e0e2ce981241420c1b4170302b918a00", + "runtime_definition_digest": "sha256:fcfa4afaf77d079d8164194283708c986a2f7cd0862362a8e540f734f129ea9e", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:9b186ad6026466a1baab26d98cfd69759289325a4e094b9433abe1fc667833ce", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:3b2acf91f2095d565d06529175fc231414c0dd508844c2d09ad4522d7be03908", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:dc673d2a4ed65c37399a052133723498e0e2ce981241420c1b4170302b918a00", + "runtime_definition_digest": "sha256:fcfa4afaf77d079d8164194283708c986a2f7cd0862362a8e540f734f129ea9e", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -113,10 +113,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:700d8f2e9aeccfc1ea8763851e027c361dab6b56aeb1c70ceeb8d7d3d3ca7334" + "sha256": "sha256:c5e67539d25006e49670f6f0b720a255d0aae5ad624bf8095c37855c67ee9f49" } ], - "definition_digest": "sha256:5db2c138225c22151a2d2476442d57b820366709ee5b3dab767c6927a3d426be" + "definition_digest": "sha256:0c394155178d62b0829878e34c090815a938fadfe0495442c8d0de1f297fe8a9" } }, { @@ -126,9 +126,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and Grype reports no fix. The official v0.26.0 Linux AMD64 Evidence candidate from run 33811606748 attempt 1 imports no ungetwc, wide-character input, or wide-character scanning function in the reviewed dynamic symbol table. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and Grype reports no fix. The official v0.26.1 Linux AMD64 Evidence candidate from run 33873930773 attempt 1 imports no ungetwc, wide-character input, or wide-character scanning function in the reviewed dynamic symbol table. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -144,14 +144,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:dc673d2a4ed65c37399a052133723498e0e2ce981241420c1b4170302b918a00", + "runtime_definition_digest": "sha256:fcfa4afaf77d079d8164194283708c986a2f7cd0862362a8e540f734f129ea9e", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:9b186ad6026466a1baab26d98cfd69759289325a4e094b9433abe1fc667833ce", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:3b2acf91f2095d565d06529175fc231414c0dd508844c2d09ad4522d7be03908", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:dc673d2a4ed65c37399a052133723498e0e2ce981241420c1b4170302b918a00", + "runtime_definition_digest": "sha256:fcfa4afaf77d079d8164194283708c986a2f7cd0862362a8e540f734f129ea9e", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -171,10 +171,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:700d8f2e9aeccfc1ea8763851e027c361dab6b56aeb1c70ceeb8d7d3d3ca7334" + "sha256": "sha256:c5e67539d25006e49670f6f0b720a255d0aae5ad624bf8095c37855c67ee9f49" } ], - "definition_digest": "sha256:5db2c138225c22151a2d2476442d57b820366709ee5b3dab767c6927a3d426be" + "definition_digest": "sha256:0c394155178d62b0829878e34c090815a938fadfe0495442c8d0de1f297fe8a9" } }, { @@ -184,9 +184,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and Grype reports no fix. The official v0.26.0 Linux AMD64 Evidence candidate from run 33811606748 attempt 1 imports __res_init and none of the deprecated resolver-printing helpers in the reviewed dynamic symbol table. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and Grype reports no fix. The official v0.26.1 Linux AMD64 Evidence candidate from run 33873930773 attempt 1 imports __res_init and none of the deprecated resolver-printing helpers in the reviewed dynamic symbol table. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -202,14 +202,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:dc673d2a4ed65c37399a052133723498e0e2ce981241420c1b4170302b918a00", + "runtime_definition_digest": "sha256:fcfa4afaf77d079d8164194283708c986a2f7cd0862362a8e540f734f129ea9e", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:9b186ad6026466a1baab26d98cfd69759289325a4e094b9433abe1fc667833ce", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:3b2acf91f2095d565d06529175fc231414c0dd508844c2d09ad4522d7be03908", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:dc673d2a4ed65c37399a052133723498e0e2ce981241420c1b4170302b918a00", + "runtime_definition_digest": "sha256:fcfa4afaf77d079d8164194283708c986a2f7cd0862362a8e540f734f129ea9e", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -229,10 +229,68 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:700d8f2e9aeccfc1ea8763851e027c361dab6b56aeb1c70ceeb8d7d3d3ca7334" + "sha256": "sha256:c5e67539d25006e49670f6f0b720a255d0aae5ad624bf8095c37855c67ee9f49" } ], - "definition_digest": "sha256:5db2c138225c22151a2d2476442d57b820366709ee5b3dab767c6927a3d426be" + "definition_digest": "sha256:0c394155178d62b0829878e34c090815a938fadfe0495442c8d0de1f297fe8a9" + } + }, + { + "vulnerability_id": "CVE-2026-85091", + "package": "zlib1g", + "installed_version": "1:1.3.dfsg+really1.3.1-1+b1", + "severity": "High", + "status": "accepted_risk", + "owner": "@jeremi", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The official v0.26.1 Linux AMD64 Evidence candidate from run 33873930773 attempt 1 neither links libz nor contains libz.so, gz_vacate, gzwrite, gzprintf, or gzvprintf in the reviewed executable bytes, so the vulnerable stalled non-blocking gzwrite followed by gzprintf/gzvprintf path is absent. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", + "invalidation_triggers": [ + "candidate_image_identity_mismatch", + "candidate_rootfs_changed", + "component_layer_changed", + "expired", + "exposure_assertion_changed", + "exposure_assertion_false", + "exposure_assertion_unevaluable", + "fix_available", + "material_finding_changed", + "package_version_changed", + "rootfs_evidence_mismatch", + "runtime_config_changed", + "runtime_base_changed" + ], + "runtime_definition_digest": "sha256:fcfa4afaf77d079d8164194283708c986a2f7cd0862362a8e540f734f129ea9e", + "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", + "exposure_assertion": { + "kind": "whole_image_fingerprint_equals", + "reference_image_digest": "sha256:3b2acf91f2095d565d06529175fc231414c0dd508844c2d09ad4522d7be03908", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:fcfa4afaf77d079d8164194283708c986a2f7cd0862362a8e540f734f129ea9e", + "files": [ + { + "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "sha256": "sha256:438c546d8e8cc48496bf3a95f753051afd9db66a629a74e31a9ded71586b56e0" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libc.so.6", + "sha256": "sha256:fa430b8f298f817a266046af84a77533185ad6fc4406c7d3787b5a0a0c207826" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "sha256": "sha256:30c61ab012a4241bed033725a09b61f5fdd3bb7df95ee852d0b096520524c7af" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libm.so.6", + "sha256": "sha256:6d567d53e895273ca14a1f9dc164fc6c8d39aed2f60aa46a733c2784228915f3" + }, + { + "path": "/usr/local/bin/evidence", + "sha256": "sha256:c5e67539d25006e49670f6f0b720a255d0aae5ad624bf8095c37855c67ee9f49" + } + ], + "definition_digest": "sha256:0c394155178d62b0829878e34c090815a938fadfe0495442c8d0de1f297fe8a9" } } ] diff --git a/release/security/mint-advisory-baseline.json b/release/security/mint-advisory-baseline.json index 875e1b682..74eadbdb1 100644 --- a/release/security/mint-advisory-baseline.json +++ b/release/security/mint-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:c39120ec5f6417c09a3065d4415a5f7df6adc91e7cea5e0b12abf4871c2c16b4", + "sha256:f933e1719674201f5dcd9d61ce63f5965627d273a8a6006e95e2f1dca1c80aba", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -45,7 +45,7 @@ "exposed_ports": ["8081/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:884f428a6dace38300e8b520b4948a529d8eb243ea1ded951d1696f7f0fb47ec" + "definition_digest": "sha256:2614e32b9aef34a54a7f8ef26d00dd90cb40698d25266349fb58127d2baf3608" }, "policies": [ { @@ -68,9 +68,9 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.0 Linux AMD64 Mint candidate had only fixed-format %lu and %lx sscanf call sites and no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.1 Linux AMD64 Mint candidate had only fixed-format %lu and %lx sscanf call sites and no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -86,14 +86,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:884f428a6dace38300e8b520b4948a529d8eb243ea1ded951d1696f7f0fb47ec", + "runtime_definition_digest": "sha256:2614e32b9aef34a54a7f8ef26d00dd90cb40698d25266349fb58127d2baf3608", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:a8c23cd64bc1d31c9413d283eaf5a8388ba0be0a2d011077a3bfe4e9380c3e57", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:532598e7581716ce679cb83e10aa7d6c1ff9c134f0fcfc7ec9578818644db800", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:884f428a6dace38300e8b520b4948a529d8eb243ea1ded951d1696f7f0fb47ec", + "runtime_definition_digest": "sha256:2614e32b9aef34a54a7f8ef26d00dd90cb40698d25266349fb58127d2baf3608", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -113,10 +113,10 @@ }, { "path": "/usr/local/bin/mint", - "sha256": "sha256:e13b254e65fad2f08d1333328bcb57f040a0d28c3a3e02eec69681fedca3b9c7" + "sha256": "sha256:21b166c605452f1539d978ac6207030501496cf07a7b3275b3ecaf1bc09cf664" } ], - "definition_digest": "sha256:d769392954bc6029662e2a630e7510672fdfc95ebc5a41a8cc304731845f086a" + "definition_digest": "sha256:53aa0d9a1937d5f941a31ddd646da269cd87f4d5dd5b88ff7b57873ae2bfd5a3" } }, { @@ -126,9 +126,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.0 Linux AMD64 Mint candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.26.1 Linux AMD64 Mint candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -144,14 +144,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:884f428a6dace38300e8b520b4948a529d8eb243ea1ded951d1696f7f0fb47ec", + "runtime_definition_digest": "sha256:2614e32b9aef34a54a7f8ef26d00dd90cb40698d25266349fb58127d2baf3608", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:a8c23cd64bc1d31c9413d283eaf5a8388ba0be0a2d011077a3bfe4e9380c3e57", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:532598e7581716ce679cb83e10aa7d6c1ff9c134f0fcfc7ec9578818644db800", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:884f428a6dace38300e8b520b4948a529d8eb243ea1ded951d1696f7f0fb47ec", + "runtime_definition_digest": "sha256:2614e32b9aef34a54a7f8ef26d00dd90cb40698d25266349fb58127d2baf3608", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -171,10 +171,10 @@ }, { "path": "/usr/local/bin/mint", - "sha256": "sha256:e13b254e65fad2f08d1333328bcb57f040a0d28c3a3e02eec69681fedca3b9c7" + "sha256": "sha256:21b166c605452f1539d978ac6207030501496cf07a7b3275b3ecaf1bc09cf664" } ], - "definition_digest": "sha256:d769392954bc6029662e2a630e7510672fdfc95ebc5a41a8cc304731845f086a" + "definition_digest": "sha256:53aa0d9a1937d5f941a31ddd646da269cd87f4d5dd5b88ff7b57873ae2bfd5a3" } }, { @@ -184,9 +184,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.26.0 Linux AMD64 Mint candidate had no effective deprecated resolver-printing path in the reviewed bytes: the reviewed binary imports __res_init and none of the deprecated resolver-printing helpers. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-09-03", - "expires_at": "2026-09-17", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.26.1 Linux AMD64 Mint candidate had no effective deprecated resolver-printing path in the reviewed bytes: the reviewed binary imports __res_init and none of the deprecated resolver-printing helpers. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -202,14 +202,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:884f428a6dace38300e8b520b4948a529d8eb243ea1ded951d1696f7f0fb47ec", + "runtime_definition_digest": "sha256:2614e32b9aef34a54a7f8ef26d00dd90cb40698d25266349fb58127d2baf3608", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:a8c23cd64bc1d31c9413d283eaf5a8388ba0be0a2d011077a3bfe4e9380c3e57", - "reference_source_revision": "e7bd7aa3c7ab72d240f60a5fffa93d39265bc0e4", + "reference_image_digest": "sha256:532598e7581716ce679cb83e10aa7d6c1ff9c134f0fcfc7ec9578818644db800", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:884f428a6dace38300e8b520b4948a529d8eb243ea1ded951d1696f7f0fb47ec", + "runtime_definition_digest": "sha256:2614e32b9aef34a54a7f8ef26d00dd90cb40698d25266349fb58127d2baf3608", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -229,10 +229,68 @@ }, { "path": "/usr/local/bin/mint", - "sha256": "sha256:e13b254e65fad2f08d1333328bcb57f040a0d28c3a3e02eec69681fedca3b9c7" + "sha256": "sha256:21b166c605452f1539d978ac6207030501496cf07a7b3275b3ecaf1bc09cf664" } ], - "definition_digest": "sha256:d769392954bc6029662e2a630e7510672fdfc95ebc5a41a8cc304731845f086a" + "definition_digest": "sha256:53aa0d9a1937d5f941a31ddd646da269cd87f4d5dd5b88ff7b57873ae2bfd5a3" + } + }, + { + "vulnerability_id": "CVE-2026-85091", + "package": "zlib1g", + "installed_version": "1:1.3.dfsg+really1.3.1-1+b1", + "severity": "High", + "status": "accepted_risk", + "owner": "@jeremi", + "rationale": "Debian Trixie has no fixed package and Grype reports no fix. The official v0.26.1 Linux AMD64 Mint candidate from run 33873930773 attempt 1 neither links libz nor contains libz.so, gz_vacate, gzwrite, gzprintf, or gzvprintf in the reviewed executable bytes, so the vulnerable stalled non-blocking gzwrite followed by gzprintf/gzvprintf path is absent. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-09-04", + "expires_at": "2026-09-18", + "invalidation_triggers": [ + "candidate_image_identity_mismatch", + "candidate_rootfs_changed", + "component_layer_changed", + "expired", + "exposure_assertion_changed", + "exposure_assertion_false", + "exposure_assertion_unevaluable", + "fix_available", + "material_finding_changed", + "package_version_changed", + "rootfs_evidence_mismatch", + "runtime_config_changed", + "runtime_base_changed" + ], + "runtime_definition_digest": "sha256:2614e32b9aef34a54a7f8ef26d00dd90cb40698d25266349fb58127d2baf3608", + "component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0", + "exposure_assertion": { + "kind": "whole_image_fingerprint_equals", + "reference_image_digest": "sha256:532598e7581716ce679cb83e10aa7d6c1ff9c134f0fcfc7ec9578818644db800", + "reference_source_revision": "3e655214558e4479a72a2049ebf72bf5721a303e", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:2614e32b9aef34a54a7f8ef26d00dd90cb40698d25266349fb58127d2baf3608", + "files": [ + { + "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "sha256": "sha256:438c546d8e8cc48496bf3a95f753051afd9db66a629a74e31a9ded71586b56e0" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libc.so.6", + "sha256": "sha256:fa430b8f298f817a266046af84a77533185ad6fc4406c7d3787b5a0a0c207826" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "sha256": "sha256:30c61ab012a4241bed033725a09b61f5fdd3bb7df95ee852d0b096520524c7af" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libm.so.6", + "sha256": "sha256:6d567d53e895273ca14a1f9dc164fc6c8d39aed2f60aa46a733c2784228915f3" + }, + { + "path": "/usr/local/bin/mint", + "sha256": "sha256:21b166c605452f1539d978ac6207030501496cf07a7b3275b3ecaf1bc09cf664" + } + ], + "definition_digest": "sha256:53aa0d9a1937d5f941a31ddd646da269cd87f4d5dd5b88ff7b57873ae2bfd5a3" } } ]