Skip to content

CVE scan 2026-09-21: clear 2 rebuild-clearable CVEs (docs-only, no code fix) - #2029

Merged
henrychv merged 1 commit into
masterfrom
CVE-fixes_2026-09-21
Sep 21, 2026
Merged

henrychv merged 1 commit into
masterfrom
CVE-fixes_2026-09-21

Conversation

@jenkins-cicd-bot

Copy link
Copy Markdown
Contributor

Fixable in taurus, this run: 13 detected → 0 fixed

Rebuild-clearable: 2 — no code change needed; merging this PR is what clears them.

This is a docs-only / R-only PR. The scan turned up no finding that a change to this repo's
Dockerfile / requirements.txt could fix, but it did turn up two findings that clear on a plain
rebuild. Merging this PR runs taurus-community-master, which rebuilds --no-cache and republishes
blazemeter/taurus:unstable — that republish is the fix. Y = 0 is an honest result here, not a failure.

Baseline: prisma-cloud-ondemand-scan #257 on blazemeter/taurus:unstable
(Image ID sha256:b10f3a36…, built by taurus-community-master #14908, build start 2026-09-17 08:42:06Z).

Rebuild-clearable (R) — expected to clear on merge

CVE Sev CVSS Package Installed → Fixed Fix published (UTC)
CVE-2026-18649 medium 7.5 gst-plugins-good1.0 1.24.2-1ubuntu1.5 → 1.24.2-1ubuntu1.6 2026-09-17 11:43:55 (Security)
CVE-2026-1801 medium 5.3 libsoup3 3.4.4-5ubuntu0.7 → 3.4.4-5ubuntu0.8 2026-09-17 16:22:39 (Security)

Evidence for the R classification (all four category-4 conditions):

  • fixed in now, needed four days ago. Both flipped needed → fixed in between scan Update Taurus Windows installation guide #244 (09-17) and Refactor Selenium executor to make subclassing easier #257 (09-21) on identical image content — same Image ID b10f3a36…. Nothing about the image changed; the Ubuntu pocket moved.
  • Already covered by an unpinned line. Both are installed unpinned by the Playwright/GStreamer apt-get install: gstreamer1.0-plugins-good is named explicitly on its command line; libgstreamer-plugins-good1.0-0 and libsoup-3.0-0 arrive as automatic deps. Proven from the image's own /var/log/apt/history.log, not from reading the Dockerfile.
  • Fix exists upstream and the unpinned line picks it up on the next --no-cache build.
  • Published after build start. 11:43Z / 16:22Z vs a build that started 08:42Z and was pushed 09:28Z — the patches did not exist while the image was being built.

Per the skill's category-4 rule, the correct action is zero code changes; adding a version pin here
would be brittle and would churn a layer for something already covered.

git tag --points-at origin/master is empty, so isRelease=false and this merge does rebuild unstable.
(On a release commit unstable is not rebuilt and R would not clear.)

No branch-build verification — and why that's correct here

There is no code change to verify, so taurus-branch-builder was deliberately not run and the
step-15 decision gate does not apply; that gate guards fix claims, and this PR makes none. The two
findings above are expected to clear on merge — they are not being reported as already cleared.

⚠️ A --no-cache rebuild re-resolves every unpinned dependency, so it is not monotonic: it can also
pick up newly-disclosed CVEs. Please treat −2 as the expectation, not a guarantee, and confirm with a
fresh prisma-cloud-ondemand-scan on unstable after merge rather than assuming the delta.

The other 11 in-scope findings — all deferred/monitor for documented cause

CVE(s) Package Why not fixed
CVE-2026-73231 (high 7.8) @faker-js/faker 5.5.3 postman-collection pins it exactly; faker 10 is ESM-only and drops APIs Newman uses. Not overridable.
CVE-2026-80212 (high 7.5), CVE-2026-80213 resolv 0.7.1 Stale default gemspec. The loaded code is patched (0.7.2). Deleting the gemspec would silence Prisma while reverting the runtime to vulnerable code — the appeasement bug this repo already fixed.
CVE-2026-54696 json 2.9.1 Same stale-default-gemspec case; loaded code is 2.19.9.
CVE-2026-85063 csv-parse 4.16.3 Vulnerable path unreachable as Newman calls it, and the only fix is a 4→7 major that changes the CommonJS export shape.
CVE-2022-36313 file-type 3.9.0 Fix is a 3→16 major (ESM rewrite); exact pin upstream, no range to widen.
CVE-2026-24001 diff 7.0.0 (Mocha) No 7.x fix line; clearing it needs a mocha 11→12 major. CVSS 2.7.
CVE-2026-85024, CVE-2026-19534, CVE-2026-18540 undici 6.28.0 (npm-internal) Needs 6.28.1; npm 11.19.1 (newest 11.x) still bundles 6.28.0, and npm 12.0.2 bundles an older 6.27.0. No reachable fix → monitor.
CVE-2026-59890 setuptools 80.10.2 Fix is 83.0.0, past the 82.0.0 removal of pkg_resources, which setup.py still imports. Blocked until that import is rewritten.

Not actionable in this repo

325 distinct CVEs — monitor-only JMeter/Gatling bundled jars, k6 binary internals, Ubuntu Pro ESM,
distro pip, and findings with no released patch (needed/deferred).

All 3 distinct criticals are monitor-only JMeter/Gatling bundled jars (computed, not assumed):
CVE-2025-54988 and CVE-2025-66516 (Tika 1.28.3, bundled in JMeter) and CVE-2026-75595
(netty-handler 4.1.77/4.1.92, bundled in JMeter and Gatling).

(Raw scan, reconciliation only — baseline #257: 369 rows / 338 distinct CVEs
[crit 6 rows / 3 distinct, high 58, medium 236, low 54, negligible 7, unassigned 8]. No branch scan exists
for this PR. Raw rows count per-occurrence and do not sum arithmetically with X/Y.)

What actually changed in this PR

Only .claude/skills/prisma-taurus/vulnerability_history.md — three in-place recipe updates:

  1. Step 2's scan-validity rule can pass on a STALE baseline. Scan Support JMeter 3.0 #243 ran 27 min after the image
    push and still returned the pre-republish image. Classifying from it would have added three
    --only-upgrade entries (aom, libinput, perl) for CVEs absent from the real image — and
    neither the build nor a branch re-scan can catch an inert entry. Guard: compare the live config digest
    to the CSV's Image ID before classifying.
  2. A monitor verdict expires after one run — documented via the needed → fixed in flip above.
  3. undici is back to monitor, with the re-check condition recorded.

Local code review (step 12)

superpowers:requesting-code-review was not available in this environment, so /code-review ran instead.
It raised 2 findings, both accepted and amended into the commit before pushing:

  • "a third independent reason" for avoiding npm@12 contradicted the adjacent note, which already gives
    that same regression reason — reworded as a re-confirmation.
  • "as automatic deps" was inaccurate for gstreamer1.0-plugins-good, which is named explicitly on the
    apt command line — corrected, since this section's whole point is provenance precision.

No unit tests were run: the diff touches only a Markdown file, no bzt/**/*.py, so the suite cannot be
affected and the codecov/project gate is inapplicable (CI measures --source=bzt).

No Jira ticket — no code fix to track.

🤖 Generated with Claude Code

Baseline: prisma-cloud-ondemand-scan #257 on blazemeter/taurus:unstable
(Image ID sha256:b10f3a36..., built by taurus-community-master #14908).

Fixable in taurus: 13 detected -> 0 fixed by code change.
Rebuild-clearable (R): 2 -- merging this PR rebuilds and republishes
unstable, which is expected to clear them:
  CVE-2026-18649  gst-plugins-good1.0  1.24.2-1ubuntu1.5 -> 1ubuntu1.6
  CVE-2026-1801   libsoup3             3.4.4-5ubuntu0.7  -> 5ubuntu0.8
Both are installed unpinned (automatic deps of the Playwright/GStreamer
apt-get install, proven from the image's apt history) and both fixes were
published after the image's build start, so no Dockerfile change applies.

The other 11 are documented deferrals/monitors (faker, csv-parse,
file-type, diff, setuptools, resolv/json stale default gemspecs, and a new
npm-internal undici trio no npm release bundles a fix for yet).

Records three durable lessons in the prisma-taurus history:
- step 2's scan-validity rule can pass on a STALE baseline (#243 did), and
  that drives wrong Dockerfile edits, not just wrong counts
- a monitor verdict expires after one run: both R findings flipped
  needed -> fixed in on identical image content
- undici is back to monitor; npm@11 and npm@12 both bundle a vulnerable one

Auto-fixed by prisma-taurus skill.
@henrychv
henrychv merged commit 44c6886 into master Sep 21, 2026
1 check passed
@henrychv
henrychv deleted the CVE-fixes_2026-09-21 branch September 21, 2026 08:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant