Skip to content

fix: temporarily safelist unreleased Python tarfile fix - #12677

Merged
benbrasso merged 1 commit into
mainfrom
codex/nofo-python-tarfile-exception
Oct 2, 2026
Merged

benbrasso merged 1 commit into
mainfrom
codex/nofo-python-tarfile-exception

Conversation

@benbrasso

Copy link
Copy Markdown
Collaborator

Summary

Work for #8109. Unblock the NOFO dev deployment scan failing on CVE-2026-87910 in CPython 3.14.8 by syncing the documented temporary exception already merged in HHS/simpler-grants-pdf-builder#1017.

Changes proposed

Add one CVE safelist entry to the root .grype.yml, with advisory and backport references, the date checked, and removal criteria. This follows the existing policy for fixes unavailable on our Python runtime line. It suppresses this finding; it does not patch the runtime vulnerability.

Context for reviewers

The failed dev deployment job reports Python 3.14.8 as affected and lists fixes in 3.12.15, 3.13.16 and pre-release 3.15.0. The 3.14 backport merged after the 3.14.8 release; the release announcement lists this fix for 3.10–3.13 only. Remove the exception once python:3.14-slim contains the backport and Grype recognizes the fixed version.

The deployment workflow checks out this repository's scan configuration, so the PDF Builder change alone did not update the deployment scan. After merge, start a new dev deployment run from the updated main branch; rerunning the old workflow run may retain its old configuration.

Validation steps

@prasnava prasnava left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@benbrasso
benbrasso merged commit ff2b60a into main Oct 2, 2026
21 checks passed
@benbrasso
benbrasso deleted the codex/nofo-python-tarfile-exception branch October 2, 2026 14:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants