From 0a68349ba332062eb4f05ba6be9507009a97f801 Mon Sep 17 00:00:00 2001 From: Jeremi Joslin Date: Thu, 20 Aug 2026 08:41:06 +0200 Subject: [PATCH 1/2] fix(release): renew image advisories for v0.23.0 The v0.23.0 candidate run stopped in the advisory gate. Two causes: the reviewed whole-image fingerprints still named the v0.22.0 candidate images, and Grype now reports CVE-2026-14456 in libssl3t64, a High finding with no exception. Renew all three baselines against the v0.23.0 candidate images built from 5c4e28578cf3c632faca77bf9d81cd18e95c635f, and record the reviewed CVE-2026-14456 acceptance. Security review notes: - Only application_layer_ids[0] moved in each image. The pinned 21-layer distroless base prefix is unchanged, so runtime_base_changed is not triggered; the OCI process config is unchanged and was re-reviewed against the production contract. - Every digest here was recomputed from the candidate images themselves: the images were pulled by digest from ghcr.io, scanned with the versions release-candidate.yml pins (syft v1.45.1, grype v0.114.0, crane v0.21.2), and the reviewed file digests were taken from the exported rootfs. No digest was carried over or invented. - The three libc6 acceptances keep their reasoning; their claims were re-verified against the v0.23.0 bytes before the rationale text moved from v0.22.0 to v0.23.0. __isoc23_sscanf is still reached only from fixed-format call sites, the binaries still export no wide-character input path, and no deprecated resolver-printing function is present. - CVE-2026-14456 is an unbounded pending-connection queue in the OpenSSL QUIC server path. Debian marks it postponed for Trixie with no fixed version and Grype reports it wont-fix, so a base bump cannot clear it. No workspace crate links OpenSSL: TLS is rustls with aws-lc-rs, the only OpenSSL-adjacent dependency is openssl-probe (a pure-Rust CA-path finder), and each binary declares only libgcc_s.so.1, libm.so.6, libc.so.6 and the loader as NEEDED with no libssl.so.3 or libcrypto.so.3 name to load dynamically. libssl3t64 ships in the pinned base and no image process opens it. - The acceptances use whole_image_fingerprint_equals rather than a closure assertion. All three binaries import dlsym (evidence and relay also dlopen), so executable_closure() reports an open closure and any closure-based assertion would evaluate as unevaluable. - All four exceptions in a baseline share one reviewed fingerprint. Layer equality already pins every rootfs byte, including the unused libssl3t64 bytes, so a per-advisory file list would add no evidence and would split the reviewed image identity. - The review window keeps the established 14-day cadence: reviewed_at 2026-08-20, expires_at 2026-09-03. The checker's live-baseline test grew a second package, so its synthetic Syft model now derives one artifact per exception from the baseline instead of hard-coding libc6, and it evaluates on the baselines' own review date instead of a pinned literal. Signed-off-by: Jeremi Joslin --- .../relay-v2/security/advisory-baseline.json | 116 +++++++++++++----- .../scripts/test_check_advisory_baselines.py | 51 +++++--- .../security/evidence-advisory-baseline.json | 116 +++++++++++++----- release/security/mint-advisory-baseline.json | 116 +++++++++++++----- 4 files changed, 293 insertions(+), 106 deletions(-) diff --git a/products/relay-v2/security/advisory-baseline.json b/products/relay-v2/security/advisory-baseline.json index 61d8dc167..6ce8b23f6 100644 --- a/products/relay-v2/security/advisory-baseline.json +++ b/products/relay-v2/security/advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:dd3c98586309126e1a7daf7864a2fd4f39706f5d571d830b4ea1590cbb35e964", + "sha256:6b6ac9bdb2dd2fb70ee79206378fe74ae84b1b056ccf2c165fba4e2bd0402144", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -52,7 +52,7 @@ "exposed_ports": ["8080/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8" + "definition_digest": "sha256:1b53d7b56025114b448e6a8d613108897641ca9de1299c81e237fa037ed2cce1" }, "policies": [ { @@ -75,9 +75,9 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Relay candidate had no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-14", - "expires_at": "2026-08-28", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.23.0 Linux AMD64 Relay candidate had no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -93,14 +93,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", + "runtime_definition_digest": "sha256:1b53d7b56025114b448e6a8d613108897641ca9de1299c81e237fa037ed2cce1", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0249df2c016c38bd1fd4ab89f69f819471eab84a733a9ed0b996b354ef00d887", - "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_image_digest": "sha256:bba41cf6d867b319b05282e2e94746cebf6f0bd1dbf7dcc3c1666813f7241847", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", + "runtime_definition_digest": "sha256:1b53d7b56025114b448e6a8d613108897641ca9de1299c81e237fa037ed2cce1", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -120,10 +120,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:944481f0421914ac0cde105db0a09676cf84f10dd1ce97c9e781d070f0802ed5" + "sha256": "sha256:5195ece8083b3641203133e85a78f51728c679cebda50fec24e830df743a4d87" } ], - "definition_digest": "sha256:d4749980452f087d8fb78339616c8e86d312f4653dc6d224c8e5668529dc5cb2" + "definition_digest": "sha256:ec054e4a5d653ee76f29d9a14ec0d3319a3885025ed932e1e8dda10cda907aeb" } }, { @@ -133,9 +133,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Relay candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-14", - "expires_at": "2026-08-28", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.23.0 Linux AMD64 Relay candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -151,14 +151,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", + "runtime_definition_digest": "sha256:1b53d7b56025114b448e6a8d613108897641ca9de1299c81e237fa037ed2cce1", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0249df2c016c38bd1fd4ab89f69f819471eab84a733a9ed0b996b354ef00d887", - "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_image_digest": "sha256:bba41cf6d867b319b05282e2e94746cebf6f0bd1dbf7dcc3c1666813f7241847", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", + "runtime_definition_digest": "sha256:1b53d7b56025114b448e6a8d613108897641ca9de1299c81e237fa037ed2cce1", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -178,10 +178,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:944481f0421914ac0cde105db0a09676cf84f10dd1ce97c9e781d070f0802ed5" + "sha256": "sha256:5195ece8083b3641203133e85a78f51728c679cebda50fec24e830df743a4d87" } ], - "definition_digest": "sha256:d4749980452f087d8fb78339616c8e86d312f4653dc6d224c8e5668529dc5cb2" + "definition_digest": "sha256:ec054e4a5d653ee76f29d9a14ec0d3319a3885025ed932e1e8dda10cda907aeb" } }, { @@ -191,9 +191,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Relay candidate had no effective vulnerable DNS-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-14", - "expires_at": "2026-08-28", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.23.0 Linux AMD64 Relay candidate had no effective vulnerable DNS-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -209,14 +209,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", + "runtime_definition_digest": "sha256:1b53d7b56025114b448e6a8d613108897641ca9de1299c81e237fa037ed2cce1", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0249df2c016c38bd1fd4ab89f69f819471eab84a733a9ed0b996b354ef00d887", - "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_image_digest": "sha256:bba41cf6d867b319b05282e2e94746cebf6f0bd1dbf7dcc3c1666813f7241847", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", + "runtime_definition_digest": "sha256:1b53d7b56025114b448e6a8d613108897641ca9de1299c81e237fa037ed2cce1", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -236,10 +236,68 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:944481f0421914ac0cde105db0a09676cf84f10dd1ce97c9e781d070f0802ed5" + "sha256": "sha256:5195ece8083b3641203133e85a78f51728c679cebda50fec24e830df743a4d87" } ], - "definition_digest": "sha256:d4749980452f087d8fb78339616c8e86d312f4653dc6d224c8e5668529dc5cb2" + "definition_digest": "sha256:ec054e4a5d653ee76f29d9a14ec0d3319a3885025ed932e1e8dda10cda907aeb" + } + }, + { + "vulnerability_id": "CVE-2026-14456", + "package": "libssl3t64", + "installed_version": "3.5.6-1~deb13u2", + "severity": "High", + "status": "accepted_risk", + "owner": "@jeremi", + "rationale": "Debian marks the Trixie issue postponed with no fixed Trixie version, and Grype reports it wont-fix. The advisory is an unbounded pending-connection queue in the OpenSSL QUIC server path. The official v0.23.0 Linux AMD64 Relay candidate links no OpenSSL library: the reviewed binary declares only libgcc_s.so.1, libm.so.6, libc.so.6, and the program interpreter as NEEDED, contains no libssl.so.3 or libcrypto.so.3 name to load dynamically, and terminates TLS with rustls and aws-lc-rs rather than OpenSSL. libssl3t64 ships in the pinned distroless base and no image process opens it. A candidate must retain the complete ordered reference rootfs layers, which pin every libssl3t64 byte, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", + "invalidation_triggers": [ + "candidate_image_identity_mismatch", + "candidate_rootfs_changed", + "component_layer_changed", + "expired", + "exposure_assertion_changed", + "exposure_assertion_false", + "exposure_assertion_unevaluable", + "fix_available", + "material_finding_changed", + "package_version_changed", + "rootfs_evidence_mismatch", + "runtime_config_changed", + "runtime_base_changed" + ], + "runtime_definition_digest": "sha256:1b53d7b56025114b448e6a8d613108897641ca9de1299c81e237fa037ed2cce1", + "component_layer_id": "sha256:80bb2aedf42cbf9911cb9073be23406c0e7f799f8083bf13a1cd2d460a25e383", + "exposure_assertion": { + "kind": "whole_image_fingerprint_equals", + "reference_image_digest": "sha256:bba41cf6d867b319b05282e2e94746cebf6f0bd1dbf7dcc3c1666813f7241847", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:1b53d7b56025114b448e6a8d613108897641ca9de1299c81e237fa037ed2cce1", + "files": [ + { + "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "sha256": "sha256:438c546d8e8cc48496bf3a95f753051afd9db66a629a74e31a9ded71586b56e0" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libc.so.6", + "sha256": "sha256:fa430b8f298f817a266046af84a77533185ad6fc4406c7d3787b5a0a0c207826" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "sha256": "sha256:30c61ab012a4241bed033725a09b61f5fdd3bb7df95ee852d0b096520524c7af" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libm.so.6", + "sha256": "sha256:6d567d53e895273ca14a1f9dc164fc6c8d39aed2f60aa46a733c2784228915f3" + }, + { + "path": "/usr/local/bin/relay", + "sha256": "sha256:5195ece8083b3641203133e85a78f51728c679cebda50fec24e830df743a4d87" + } + ], + "definition_digest": "sha256:ec054e4a5d653ee76f29d9a14ec0d3319a3885025ed932e1e8dda10cda907aeb" } } ] diff --git a/release/scripts/test_check_advisory_baselines.py b/release/scripts/test_check_advisory_baselines.py index 516fa6ce8..af1cef44e 100644 --- a/release/scripts/test_check_advisory_baselines.py +++ b/release/scripts/test_check_advisory_baselines.py @@ -24,11 +24,11 @@ ROOT / "release/security/mint-advisory-baseline.json", ) LIVE_REFERENCE_IMAGE_DIGESTS = { - "relay": "sha256:0249df2c016c38bd1fd4ab89f69f819471eab84a733a9ed0b996b354ef00d887", - "evidence": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3", - "mint": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12", + "relay": "sha256:bba41cf6d867b319b05282e2e94746cebf6f0bd1dbf7dcc3c1666813f7241847", + "evidence": "sha256:8896bc15dd9e16e6c9fff73c1b42f1b953c27f2bc4e3609f6ff567ee60e41979", + "mint": "sha256:94dafa4e93a1864efc1c62ca5e593a5b9f12eddfee71d29aaf4ea68b1f4b5cb5", } -LIVE_REFERENCE_SOURCE_REVISION = "0ddd1fa6481ef0154d9f11a13815ba35ab942053" +LIVE_REFERENCE_SOURCE_REVISION = "5c4e28578cf3c632faca77bf9d81cd18e95c635f" LIVE_REFERENCE_PROVENANCE = { "relay": "official_candidate", "evidence": "official_candidate", @@ -1324,19 +1324,24 @@ def test_all_live_baselines_use_evaluable_whole_image_fingerprints(self): runtime_layers + application_layers, live_assertion["reference_image_digest"], ) - component_layer = baseline["exceptions"][0]["component_layer_id"] - artifact = { - "id": "libc6-artifact", - "name": "libc6", - "version": "2.41-12+deb13u3", - "type": "deb", - "locations": [ + artifacts = {} + for exception in baseline["exceptions"]: + package = exception["package"] + artifacts.setdefault( + package, { - "path": "/var/lib/dpkg/status.d/libc6", - "layerID": component_layer, - } - ], - } + "id": f"{package}-artifact", + "name": package, + "version": exception["installed_version"], + "type": "deb", + "locations": [ + { + "path": f"/var/lib/dpkg/status.d/{package}", + "layerID": exception["component_layer_id"], + } + ], + }, + ) grype = { "descriptor": {"name": "grype", "version": "0.104.0"}, "source": {"type": "image", "target": copy.deepcopy(target)}, @@ -1347,7 +1352,7 @@ def test_all_live_baselines_use_evaluable_whole_image_fingerprints(self): "severity": exception["severity"], "fix": {"versions": [], "state": "not-fixed"}, }, - "artifact": copy.deepcopy(artifact), + "artifact": copy.deepcopy(artifacts[exception["package"]]), } for exception in baseline["exceptions"] ], @@ -1356,7 +1361,9 @@ def test_all_live_baselines_use_evaluable_whole_image_fingerprints(self): "descriptor": {"name": "syft", "version": "1.45.1"}, "schema": {"version": "16.1.3"}, "source": {"type": "image", "metadata": copy.deepcopy(target)}, - "artifacts": [copy.deepcopy(artifact)], + "artifacts": [ + copy.deepcopy(artifact) for artifact in artifacts.values() + ], "files": [self.file_entry(image_path) for image_path in sorted(paths)], } normalized = self.module.normalize_grype( @@ -1368,7 +1375,13 @@ def test_all_live_baselines_use_evaluable_whole_image_fingerprints(self): list(normalized.findings), normalized.image, synthetic_baseline, - self.module.parse_date("2026-08-14", "today"), + self.module.parse_date( + max( + exception["reviewed_at"] + for exception in baseline["exceptions"] + ), + "today", + ), self.rootfs, live_assertion["reference_image_digest"], copy.deepcopy(baseline["runtime"]["config"]), diff --git a/release/security/evidence-advisory-baseline.json b/release/security/evidence-advisory-baseline.json index 8727e696b..7daa82980 100644 --- a/release/security/evidence-advisory-baseline.json +++ b/release/security/evidence-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:9c9226dd6fa9be3fb68e2702d21430ee4a7a5bd9121df7cfbfaaa1b221fa8b34", + "sha256:47baa51099a97968c6231fc8683726d0f97535dad203a8a6333f73a12f55e1c2", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -45,7 +45,7 @@ "exposed_ports": ["8080/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7" + "definition_digest": "sha256:759e6b9454f28584fc7ac6d506ec56fd3dabd7daf5065080a2007a81feadf3bd" }, "policies": [ { @@ -68,9 +68,9 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Evidence candidate had only fixed-format %lu and %lx sscanf call sites and no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-14", - "expires_at": "2026-08-28", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.23.0 Linux AMD64 Evidence candidate had only fixed-format %lu and %lx sscanf call sites and no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -86,14 +86,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", + "runtime_definition_digest": "sha256:759e6b9454f28584fc7ac6d506ec56fd3dabd7daf5065080a2007a81feadf3bd", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3", - "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_image_digest": "sha256:8896bc15dd9e16e6c9fff73c1b42f1b953c27f2bc4e3609f6ff567ee60e41979", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", + "runtime_definition_digest": "sha256:759e6b9454f28584fc7ac6d506ec56fd3dabd7daf5065080a2007a81feadf3bd", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -113,10 +113,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:f10c16ad811f63289c2eb36582db7bcb79308ff9012c86addbfbef11bbf70439" + "sha256": "sha256:47c9933ccc406d1d873fe9437ca60e00a1ef78c78e7a3bb571b86a72a273ba9b" } ], - "definition_digest": "sha256:2dcf75b57667b0bd40d53920c27f2a4a4be9cd236497fd2b2e174cd86b2e77e9" + "definition_digest": "sha256:c6ddf609f7ddcdceab1a778779bb32a323d74fc3e1fe8b357f5053df84fe0b4a" } }, { @@ -126,9 +126,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Evidence candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-14", - "expires_at": "2026-08-28", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.23.0 Linux AMD64 Evidence candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -144,14 +144,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", + "runtime_definition_digest": "sha256:759e6b9454f28584fc7ac6d506ec56fd3dabd7daf5065080a2007a81feadf3bd", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3", - "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_image_digest": "sha256:8896bc15dd9e16e6c9fff73c1b42f1b953c27f2bc4e3609f6ff567ee60e41979", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", + "runtime_definition_digest": "sha256:759e6b9454f28584fc7ac6d506ec56fd3dabd7daf5065080a2007a81feadf3bd", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -171,10 +171,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:f10c16ad811f63289c2eb36582db7bcb79308ff9012c86addbfbef11bbf70439" + "sha256": "sha256:47c9933ccc406d1d873fe9437ca60e00a1ef78c78e7a3bb571b86a72a273ba9b" } ], - "definition_digest": "sha256:2dcf75b57667b0bd40d53920c27f2a4a4be9cd236497fd2b2e174cd86b2e77e9" + "definition_digest": "sha256:c6ddf609f7ddcdceab1a778779bb32a323d74fc3e1fe8b357f5053df84fe0b4a" } }, { @@ -184,9 +184,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.22.0 Linux AMD64 Evidence candidate had no effective deprecated resolver-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-14", - "expires_at": "2026-08-28", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.23.0 Linux AMD64 Evidence candidate had no effective deprecated resolver-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -202,14 +202,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", + "runtime_definition_digest": "sha256:759e6b9454f28584fc7ac6d506ec56fd3dabd7daf5065080a2007a81feadf3bd", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3", - "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_image_digest": "sha256:8896bc15dd9e16e6c9fff73c1b42f1b953c27f2bc4e3609f6ff567ee60e41979", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", + "runtime_definition_digest": "sha256:759e6b9454f28584fc7ac6d506ec56fd3dabd7daf5065080a2007a81feadf3bd", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -229,10 +229,68 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:f10c16ad811f63289c2eb36582db7bcb79308ff9012c86addbfbef11bbf70439" + "sha256": "sha256:47c9933ccc406d1d873fe9437ca60e00a1ef78c78e7a3bb571b86a72a273ba9b" } ], - "definition_digest": "sha256:2dcf75b57667b0bd40d53920c27f2a4a4be9cd236497fd2b2e174cd86b2e77e9" + "definition_digest": "sha256:c6ddf609f7ddcdceab1a778779bb32a323d74fc3e1fe8b357f5053df84fe0b4a" + } + }, + { + "vulnerability_id": "CVE-2026-14456", + "package": "libssl3t64", + "installed_version": "3.5.6-1~deb13u2", + "severity": "High", + "status": "accepted_risk", + "owner": "@jeremi", + "rationale": "Debian marks the Trixie issue postponed with no fixed Trixie version, and Grype reports it wont-fix. The advisory is an unbounded pending-connection queue in the OpenSSL QUIC server path. The official v0.23.0 Linux AMD64 Evidence candidate links no OpenSSL library: the reviewed binary declares only libgcc_s.so.1, libm.so.6, libc.so.6, and the program interpreter as NEEDED, contains no libssl.so.3 or libcrypto.so.3 name to load dynamically, and terminates TLS with rustls and aws-lc-rs rather than OpenSSL. libssl3t64 ships in the pinned distroless base and no image process opens it. A candidate must retain the complete ordered reference rootfs layers, which pin every libssl3t64 byte, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", + "invalidation_triggers": [ + "candidate_image_identity_mismatch", + "candidate_rootfs_changed", + "component_layer_changed", + "expired", + "exposure_assertion_changed", + "exposure_assertion_false", + "exposure_assertion_unevaluable", + "fix_available", + "material_finding_changed", + "package_version_changed", + "rootfs_evidence_mismatch", + "runtime_config_changed", + "runtime_base_changed" + ], + "runtime_definition_digest": "sha256:759e6b9454f28584fc7ac6d506ec56fd3dabd7daf5065080a2007a81feadf3bd", + "component_layer_id": "sha256:80bb2aedf42cbf9911cb9073be23406c0e7f799f8083bf13a1cd2d460a25e383", + "exposure_assertion": { + "kind": "whole_image_fingerprint_equals", + "reference_image_digest": "sha256:8896bc15dd9e16e6c9fff73c1b42f1b953c27f2bc4e3609f6ff567ee60e41979", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:759e6b9454f28584fc7ac6d506ec56fd3dabd7daf5065080a2007a81feadf3bd", + "files": [ + { + "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "sha256": "sha256:438c546d8e8cc48496bf3a95f753051afd9db66a629a74e31a9ded71586b56e0" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libc.so.6", + "sha256": "sha256:fa430b8f298f817a266046af84a77533185ad6fc4406c7d3787b5a0a0c207826" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "sha256": "sha256:30c61ab012a4241bed033725a09b61f5fdd3bb7df95ee852d0b096520524c7af" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libm.so.6", + "sha256": "sha256:6d567d53e895273ca14a1f9dc164fc6c8d39aed2f60aa46a733c2784228915f3" + }, + { + "path": "/usr/local/bin/evidence", + "sha256": "sha256:47c9933ccc406d1d873fe9437ca60e00a1ef78c78e7a3bb571b86a72a273ba9b" + } + ], + "definition_digest": "sha256:c6ddf609f7ddcdceab1a778779bb32a323d74fc3e1fe8b357f5053df84fe0b4a" } } ] diff --git a/release/security/mint-advisory-baseline.json b/release/security/mint-advisory-baseline.json index 48f7271b5..8f5cb8bbc 100644 --- a/release/security/mint-advisory-baseline.json +++ b/release/security/mint-advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:be33545edd3caceb5201ba9bcc736856d8fb4ee87442920e8bc6383db8df7384", + "sha256:3a58a738ee6e4801e9a00cedd52e516b3c525684569264bf3b1c973cf3217a62", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -45,7 +45,7 @@ "exposed_ports": ["8081/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2" + "definition_digest": "sha256:9c8c18a72538becb28dab46d8a66259187ceb982272cbd1e6ecc46eae89eb337" }, "policies": [ { @@ -68,9 +68,9 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Mint candidate had only fixed-format %lu and %lx sscanf call sites and no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-14", - "expires_at": "2026-08-28", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.23.0 Linux AMD64 Mint candidate had only fixed-format %lu and %lx sscanf call sites and no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -86,14 +86,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", + "runtime_definition_digest": "sha256:9c8c18a72538becb28dab46d8a66259187ceb982272cbd1e6ecc46eae89eb337", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12", - "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_image_digest": "sha256:94dafa4e93a1864efc1c62ca5e593a5b9f12eddfee71d29aaf4ea68b1f4b5cb5", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", + "runtime_definition_digest": "sha256:9c8c18a72538becb28dab46d8a66259187ceb982272cbd1e6ecc46eae89eb337", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -113,10 +113,10 @@ }, { "path": "/usr/local/bin/mint", - "sha256": "sha256:620321d21759a69e7a09cc133c60d0f1fad2804593c79d12332590de7aa05a89" + "sha256": "sha256:7ff5d48e0c35337501a4680165e90a6e9ea4f6f25c9106cc88094f62d0a7262d" } ], - "definition_digest": "sha256:39945c382e5d58182d36aba32fca48d0dc42eef58373d8ead4eab246e14ecc6d" + "definition_digest": "sha256:3eaccd4fe9d0dfc43f4ae0756748f32052e68bb8ac7c27599c45280daac0de85" } }, { @@ -126,9 +126,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Mint candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-14", - "expires_at": "2026-08-28", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.23.0 Linux AMD64 Mint candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -144,14 +144,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", + "runtime_definition_digest": "sha256:9c8c18a72538becb28dab46d8a66259187ceb982272cbd1e6ecc46eae89eb337", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12", - "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_image_digest": "sha256:94dafa4e93a1864efc1c62ca5e593a5b9f12eddfee71d29aaf4ea68b1f4b5cb5", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", + "runtime_definition_digest": "sha256:9c8c18a72538becb28dab46d8a66259187ceb982272cbd1e6ecc46eae89eb337", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -171,10 +171,10 @@ }, { "path": "/usr/local/bin/mint", - "sha256": "sha256:620321d21759a69e7a09cc133c60d0f1fad2804593c79d12332590de7aa05a89" + "sha256": "sha256:7ff5d48e0c35337501a4680165e90a6e9ea4f6f25c9106cc88094f62d0a7262d" } ], - "definition_digest": "sha256:39945c382e5d58182d36aba32fca48d0dc42eef58373d8ead4eab246e14ecc6d" + "definition_digest": "sha256:3eaccd4fe9d0dfc43f4ae0756748f32052e68bb8ac7c27599c45280daac0de85" } }, { @@ -184,9 +184,9 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.22.0 Linux AMD64 Mint candidate had no effective deprecated resolver-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-14", - "expires_at": "2026-08-28", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.23.0 Linux AMD64 Mint candidate had no effective deprecated resolver-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", "invalidation_triggers": [ "candidate_image_identity_mismatch", "candidate_rootfs_changed", @@ -202,14 +202,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", + "runtime_definition_digest": "sha256:9c8c18a72538becb28dab46d8a66259187ceb982272cbd1e6ecc46eae89eb337", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12", - "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_image_digest": "sha256:94dafa4e93a1864efc1c62ca5e593a5b9f12eddfee71d29aaf4ea68b1f4b5cb5", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", + "runtime_definition_digest": "sha256:9c8c18a72538becb28dab46d8a66259187ceb982272cbd1e6ecc46eae89eb337", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -229,10 +229,68 @@ }, { "path": "/usr/local/bin/mint", - "sha256": "sha256:620321d21759a69e7a09cc133c60d0f1fad2804593c79d12332590de7aa05a89" + "sha256": "sha256:7ff5d48e0c35337501a4680165e90a6e9ea4f6f25c9106cc88094f62d0a7262d" } ], - "definition_digest": "sha256:39945c382e5d58182d36aba32fca48d0dc42eef58373d8ead4eab246e14ecc6d" + "definition_digest": "sha256:3eaccd4fe9d0dfc43f4ae0756748f32052e68bb8ac7c27599c45280daac0de85" + } + }, + { + "vulnerability_id": "CVE-2026-14456", + "package": "libssl3t64", + "installed_version": "3.5.6-1~deb13u2", + "severity": "High", + "status": "accepted_risk", + "owner": "@jeremi", + "rationale": "Debian marks the Trixie issue postponed with no fixed Trixie version, and Grype reports it wont-fix. The advisory is an unbounded pending-connection queue in the OpenSSL QUIC server path. The official v0.23.0 Linux AMD64 Mint candidate links no OpenSSL library: the reviewed binary declares only libgcc_s.so.1, libm.so.6, libc.so.6, and the program interpreter as NEEDED, contains no libssl.so.3 or libcrypto.so.3 name to load dynamically, and terminates TLS with rustls and aws-lc-rs rather than OpenSSL. libssl3t64 ships in the pinned distroless base and no image process opens it. A candidate must retain the complete ordered reference rootfs layers, which pin every libssl3t64 byte, the production OCI process contract, and the Syft-bound reviewed file digests.", + "reviewed_at": "2026-08-20", + "expires_at": "2026-09-03", + "invalidation_triggers": [ + "candidate_image_identity_mismatch", + "candidate_rootfs_changed", + "component_layer_changed", + "expired", + "exposure_assertion_changed", + "exposure_assertion_false", + "exposure_assertion_unevaluable", + "fix_available", + "material_finding_changed", + "package_version_changed", + "rootfs_evidence_mismatch", + "runtime_config_changed", + "runtime_base_changed" + ], + "runtime_definition_digest": "sha256:9c8c18a72538becb28dab46d8a66259187ceb982272cbd1e6ecc46eae89eb337", + "component_layer_id": "sha256:80bb2aedf42cbf9911cb9073be23406c0e7f799f8083bf13a1cd2d460a25e383", + "exposure_assertion": { + "kind": "whole_image_fingerprint_equals", + "reference_image_digest": "sha256:94dafa4e93a1864efc1c62ca5e593a5b9f12eddfee71d29aaf4ea68b1f4b5cb5", + "reference_source_revision": "5c4e28578cf3c632faca77bf9d81cd18e95c635f", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:9c8c18a72538becb28dab46d8a66259187ceb982272cbd1e6ecc46eae89eb337", + "files": [ + { + "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "sha256": "sha256:438c546d8e8cc48496bf3a95f753051afd9db66a629a74e31a9ded71586b56e0" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libc.so.6", + "sha256": "sha256:fa430b8f298f817a266046af84a77533185ad6fc4406c7d3787b5a0a0c207826" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "sha256": "sha256:30c61ab012a4241bed033725a09b61f5fdd3bb7df95ee852d0b096520524c7af" + }, + { + "path": "/usr/lib/x86_64-linux-gnu/libm.so.6", + "sha256": "sha256:6d567d53e895273ca14a1f9dc164fc6c8d39aed2f60aa46a733c2784228915f3" + }, + { + "path": "/usr/local/bin/mint", + "sha256": "sha256:7ff5d48e0c35337501a4680165e90a6e9ea4f6f25c9106cc88094f62d0a7262d" + } + ], + "definition_digest": "sha256:3eaccd4fe9d0dfc43f4ae0756748f32052e68bb8ac7c27599c45280daac0de85" } } ] From e6249b1657ed7e65146fa4afe2de6be0b6984248 Mon Sep 17 00:00:00 2001 From: Jeremi Joslin Date: Thu, 20 Aug 2026 08:55:42 +0200 Subject: [PATCH 2/2] test(release): pin live baseline review date independently The live-baseline evaluability test derived its evaluation date from the maximum reviewed_at across the baseline's own exceptions. That made the checker's future-dated guard unreachable for the newest exception: a baseline committed with a future reviewed_at defined the very "today" it was compared against, so ordinary CI accepted it and only a later release-candidate run against the real clock would have stopped it. State the date independently instead, and cover the guard directly. Security review notes: this restores a release-provenance gate rather than relaxing one. LIVE_REVIEW_EVALUATION_DATE is now a stated constant a reviewer moves by hand at each renewal, so a future-dated reviewed_at fails in ordinary CI. Verified by mutating a live exception's reviewed_at to 2026-08-25, which now fails the live test with "future-dated exception: CVE-2026-14456 libssl3t64 3.5.6-1~deb13u2" and passed silently before. The new test_future_dated_exception_is_invalid covers the checker path itself. No baseline content, digest, or exception changes in this commit. Signed-off-by: Jeremi Joslin --- .../scripts/test_check_advisory_baselines.py | 21 ++++++++++++++----- 1 file changed, 16 insertions(+), 5 deletions(-) diff --git a/release/scripts/test_check_advisory_baselines.py b/release/scripts/test_check_advisory_baselines.py index af1cef44e..f923df5af 100644 --- a/release/scripts/test_check_advisory_baselines.py +++ b/release/scripts/test_check_advisory_baselines.py @@ -29,6 +29,11 @@ "mint": "sha256:94dafa4e93a1864efc1c62ca5e593a5b9f12eddfee71d29aaf4ea68b1f4b5cb5", } LIVE_REFERENCE_SOURCE_REVISION = "5c4e28578cf3c632faca77bf9d81cd18e95c635f" +# The date the live exceptions below were reviewed against, stated here rather +# than derived from the baselines: deriving it from their own reviewed_at values +# would make the checker's future-dated guard unreachable for the newest +# exception. Move it forward by hand when the baselines are renewed. +LIVE_REVIEW_EVALUATION_DATE = "2026-08-20" LIVE_REFERENCE_PROVENANCE = { "relay": "official_candidate", "evidence": "official_candidate", @@ -587,6 +592,16 @@ def test_whole_image_fingerprint_blocks_new_forbidden_symbol(self): self.assertIn("runtime.layer_ids/application_layer_ids", output) self.assertNotIn("reviewed runtime change", output) + def test_future_dated_exception_is_invalid(self): + reviewed = self.finding() + data = self.baseline(reviewed) + data["exceptions"][0]["reviewed_at"] = "2026-08-14" + baseline = self.load_baseline(data) + stderr = io.StringIO() + with contextlib.redirect_stderr(stderr): + self.assertEqual(1, self.check(reviewed, baseline)) + self.assertIn("future-dated exception:", stderr.getvalue()) + def test_dynamic_lookup_makes_symbol_absence_unevaluable(self): for api in ("dlopen", "dlmopen", "dlsym", "dlvsym"): with self.subTest(api=api): @@ -1376,11 +1391,7 @@ def test_all_live_baselines_use_evaluable_whole_image_fingerprints(self): normalized.image, synthetic_baseline, self.module.parse_date( - max( - exception["reviewed_at"] - for exception in baseline["exceptions"] - ), - "today", + LIVE_REVIEW_EVALUATION_DATE, "today" ), self.rootfs, live_assertion["reference_image_digest"],