Skip to content

Security (Hub): remediate MEDIUM container image vulnerabilities #1752

Description

@ajile-in

Part of: #1730 — Security: Remediate 3,147 vulnerabilities across 26 container images (Hub + Verifier)

Scope

  • Deployment: Hub
  • Severity: MEDIUM
  • Findings: 858 (across 20 images)

Current progress: 0% (test-based)

  • Basis: pnpm security:progress — all 5 targets (perl, glibc, xz-utils, node, pnpm) are container-level; not verifiable in this repo. Requires image re-scan.
  • Regression: no regressions (CI green).

Affected Hub images

Image Platform Findings (medium subset)
NestJS services v2.2.0 (x16, identical profile) Alpine 3.23 43 packages (subset)
seed-v2.1.4-alpha.11 Alpine 3.21 69 packages (subset)
nats-2.12.4-alpine / 2.12.3 / 2.12.4 Alpine 3.22 / Scratch subset
Total 858

Attribution (Upstream vs CREDEBL-owned)

Source Findings (approx) How fixed
Upstream (OS packages, transitive Node/Go deps) ~70% P0 rebuilds + P1/P2 bumps — largely resolved as a side-effect of the CRITICAL/HIGH work.
CREDEBL-owned (major migrations / deprecated deps) ~30% P3 major migrations (protobufjs 8, nodemailer, multer, @opentelemetry/exporter-prometheus, ajv, glob, basic-ftp, tough-cookie, fast-xml-parser) + dependency removals.

NOTE: exact per-finding upstream/owned counts to be finalised on the next container re-scan; package-level attribution is from #1730's P0–P4 tables.

Package checklist (from #1730 plan)

  • P0 – Base image rebuilds: openssl → 3.5.7 LTS, musl → 1.2.6, zlib → 1.3.2, xz-utils → 5.8.3, perl → 5.42.2, glibc → 2.44, go/stdlib → 1.26.5
  • P1 – Shared Node.js bumps: remaining MEDIUM findings across axios, lodash, ws, qs, tar-fs, brace-expansion, fast-uri, ip-address, follow-redirects, cross-spawn, engine.io, socket.io-parser, @grpc/grpc-js, form-data, websocket-driver, @opentelemetry/propagator-jaeger, @protobufjs/utf8, validator, @nestjs/microservices
  • P3 – Major bumps: Node 22 → 26, pnpm 9 → 11, protobufjs → 8.7.x, @opentelemetry/exporter-prometheus → 0.221.0, ajv → 8.20.0, glob → 9.x, fast-xml-parser → 5.x, basic-ftp → 6.x, tough-cookie → 6.x, nodemailer → 9.x, multer → 2.x
  • Re-scan all 20 Hub images
  • Post re-scan result + update progress matrix on Security: Remediate 3,147 vulnerabilities across 26 container images (Hub + Verifier) #1730

Acceptance criteria

Execution order reference

Follow #1730's execution order: P0 → P1 → P2 → P3 → re-scan. This issue is mostly "mop-up" after CRITICAL/HIGH are closed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions