CVE scan 2026-09-21: clear 2 rebuild-clearable CVEs (docs-only, no code fix) - #2029
Merged
Merged
Conversation
Baseline: prisma-cloud-ondemand-scan #257 on blazemeter/taurus:unstable (Image ID sha256:b10f3a36..., built by taurus-community-master #14908). Fixable in taurus: 13 detected -> 0 fixed by code change. Rebuild-clearable (R): 2 -- merging this PR rebuilds and republishes unstable, which is expected to clear them: CVE-2026-18649 gst-plugins-good1.0 1.24.2-1ubuntu1.5 -> 1ubuntu1.6 CVE-2026-1801 libsoup3 3.4.4-5ubuntu0.7 -> 5ubuntu0.8 Both are installed unpinned (automatic deps of the Playwright/GStreamer apt-get install, proven from the image's apt history) and both fixes were published after the image's build start, so no Dockerfile change applies. The other 11 are documented deferrals/monitors (faker, csv-parse, file-type, diff, setuptools, resolv/json stale default gemspecs, and a new npm-internal undici trio no npm release bundles a fix for yet). Records three durable lessons in the prisma-taurus history: - step 2's scan-validity rule can pass on a STALE baseline (#243 did), and that drives wrong Dockerfile edits, not just wrong counts - a monitor verdict expires after one run: both R findings flipped needed -> fixed in on identical image content - undici is back to monitor; npm@11 and npm@12 both bundle a vulnerable one Auto-fixed by prisma-taurus skill.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixable in taurus, this run: 13 detected → 0 fixed
Rebuild-clearable: 2 — no code change needed; merging this PR is what clears them.
This is a docs-only / R-only PR. The scan turned up no finding that a change to this repo's
Dockerfile/requirements.txtcould fix, but it did turn up two findings that clear on a plainrebuild. Merging this PR runs
taurus-community-master, which rebuilds--no-cacheand republishesblazemeter/taurus:unstable— that republish is the fix.Y = 0is an honest result here, not a failure.Baseline:
prisma-cloud-ondemand-scan#257 onblazemeter/taurus:unstable(
Image ID sha256:b10f3a36…, built bytaurus-community-master#14908, build start 2026-09-17 08:42:06Z).Rebuild-clearable (R) — expected to clear on merge
1.24.2-1ubuntu1.5→1.24.2-1ubuntu1.63.4.4-5ubuntu0.7→3.4.4-5ubuntu0.8Evidence for the R classification (all four category-4 conditions):
fixed innow,neededfour days ago. Both flippedneeded→fixed inbetween scan Update Taurus Windows installation guide #244 (09-17) and Refactor Selenium executor to make subclassing easier #257 (09-21) on identical image content — sameImage ID b10f3a36…. Nothing about the image changed; the Ubuntu pocket moved.apt-get install:gstreamer1.0-plugins-goodis named explicitly on its command line;libgstreamer-plugins-good1.0-0andlibsoup-3.0-0arrive asautomaticdeps. Proven from the image's own/var/log/apt/history.log, not from reading the Dockerfile.--no-cachebuild.Per the skill's category-4 rule, the correct action is zero code changes; adding a version pin here
would be brittle and would churn a layer for something already covered.
git tag --points-at origin/masteris empty, soisRelease=falseand this merge does rebuildunstable.(On a release commit
unstableis not rebuilt and R would not clear.)No branch-build verification — and why that's correct here
There is no code change to verify, so
taurus-branch-builderwas deliberately not run and thestep-15 decision gate does not apply; that gate guards fix claims, and this PR makes none. The two
findings above are expected to clear on merge — they are not being reported as already cleared.
--no-cacherebuild re-resolves every unpinned dependency, so it is not monotonic: it can alsopick up newly-disclosed CVEs. Please treat
−2as the expectation, not a guarantee, and confirm with afresh
prisma-cloud-ondemand-scanonunstableafter merge rather than assuming the delta.The other 11 in-scope findings — all deferred/monitor for documented cause
@faker-js/faker5.5.3postman-collectionpins it exactly; faker 10 is ESM-only and drops APIs Newman uses. Not overridable.resolv0.7.1json2.9.1csv-parse4.16.3file-type3.9.0diff7.0.0 (Mocha)undici6.28.0 (npm-internal)setuptools80.10.2pkg_resources, whichsetup.pystill imports. Blocked until that import is rewritten.Not actionable in this repo
325 distinct CVEs — monitor-only JMeter/Gatling bundled jars, k6 binary internals, Ubuntu Pro ESM,
distro pip, and findings with no released patch (
needed/deferred).All 3 distinct criticals are monitor-only JMeter/Gatling bundled jars (computed, not assumed):
CVE-2025-54988 and CVE-2025-66516 (Tika 1.28.3, bundled in JMeter) and CVE-2026-75595
(netty-handler 4.1.77/4.1.92, bundled in JMeter and Gatling).
(Raw scan, reconciliation only — baseline #257: 369 rows / 338 distinct CVEs
[crit 6 rows / 3 distinct, high 58, medium 236, low 54, negligible 7, unassigned 8]. No branch scan exists
for this PR. Raw rows count per-occurrence and do not sum arithmetically with X/Y.)
What actually changed in this PR
Only
.claude/skills/prisma-taurus/vulnerability_history.md— three in-place recipe updates:push and still returned the pre-republish image. Classifying from it would have added three
--only-upgradeentries (aom,libinput,perl) for CVEs absent from the real image — andneither the build nor a branch re-scan can catch an inert entry. Guard: compare the live config digest
to the CSV's
Image IDbefore classifying.needed→fixed inflip above.undiciis back to monitor, with the re-check condition recorded.Local code review (step 12)
superpowers:requesting-code-reviewwas not available in this environment, so/code-reviewran instead.It raised 2 findings, both accepted and amended into the commit before pushing:
npm@12contradicted the adjacent note, which already givesthat same regression reason — reworded as a re-confirmation.
gstreamer1.0-plugins-good, which is named explicitly on theapt command line — corrected, since this section's whole point is provenance precision.
No unit tests were run: the diff touches only a Markdown file, no
bzt/**/*.py, so the suite cannot beaffected and the
codecov/projectgate is inapplicable (CI measures--source=bzt).No Jira ticket — no code fix to track.
🤖 Generated with Claude Code