Skip to content

fix: temporarily safelist unreleased Python tarfile fix - #1017

Merged
benbrasso merged 1 commit into
HHS:mainfrom
benbrasso:codex/anchore-python-tarfile
Oct 2, 2026
Merged

benbrasso merged 1 commit into
HHS:mainfrom
benbrasso:codex/anchore-python-tarfile

Conversation

@benbrasso

Copy link
Copy Markdown
Collaborator

Summary

PR #1014 fails Anchore on the sole remaining finding: CVE-2026-87910 in CPython 3.14.8 (/usr/local/lib/libpython3.14.so.1.0). Add a documented temporary safelist entry, following the existing policy for Python vulnerabilities whose fix is unavailable on the supported runtime line. This suppresses the finding; it does not patch the vulnerability.

The 3.14 backport merged on October 1 after the 3.14.8 release. The PSF CVE record still marks the 3.14 series affected, and the release announcement lists this fix for 3.10–3.13 only. Remove the exception once python:3.14-slim contains the backport and Grype recognizes the fixed release.

HHS/simpler-grants-gov#12615 updates urllib3, Amazon Linux packages and frontend dependencies; none addresses this CPython finding in the Debian-based NOFO image. No dependency or image changes are needed for this temporary scan-policy change.

After this PR merges, rebase #1014 onto main to pick up the exception. The deployment repository maintains a separate .grype.yml; its NOFO deployment scan will need the same exception while the runtime fix remains unreleased. This PR changes only the PDF Builder repository.

Test plan

  • Reviewed the failed Anchore job on feat: add saved readability checkpoints and history #1014; confirmed this is its only reported match.
  • Grype 0.119.0 successfully loaded .grype.yml and recognized the new ignore entry.
  • Pre-commit checks passed, including YAML validation; git diff --check passed.
  • Application tests are unchanged and were not run locally for this scan-configuration-only change. GitHub CI will build and scan the actual image; no local Docker runtime is available.

@benbrasso
benbrasso merged commit a25cb05 into HHS:main Oct 2, 2026
6 checks passed
@benbrasso
benbrasso deleted the codex/anchore-python-tarfile branch October 2, 2026 13:57
benbrasso pushed a commit that referenced this pull request Oct 2, 2026
🤖 I have created a release *beep* *boop*
---


##
[3.47.0](nofos-v3.46.0...nofos-v3.47.0)
(2026-10-02)


### Features

* add SAMHSA user group
([#1004](#1004))
([0c74ff0](0c74ff0))
* add saved readability checkpoints and history
([#1014](#1014))
([b714111](b714111))
* auto-size "Point value" columns in scoring tables
([#1008](#1008))
([dd8c867](dd8c867))


### Bug Fixes

* protect production GrabzIt Word export
([#1002](#1002))
([9391867](9391867)),
closes
[#1000](#1000)
* temporarily safelist unreleased Python tarfile fix
([#1017](#1017))
([a25cb05](a25cb05))
* update NOFO metadata field guidance
([#1001](#1001))
([de47d52](de47d52))
* upgrade virtualenv and remove unused Login.gov sign-in
([#1011](#1011))
([08cd880](08cd880))


### Documentation

* clarify PDF publishing scope
([#1015](#1015))
([94721a5](94721a5))
* consolidate repository documentation
([#1016](#1016))
([33b7e9a](33b7e9a))
* draft approved PDF retrieval proposal for Announcement Services
([#1010](#1010))
([755ce2d](755ce2d))


### Miscellaneous Chores

* bump boto3 from 1.43.93 to 1.43.96 in the python-minor-and-patch group
across 1 directory
([#1006](#1006))
([de4bc0b](de4bc0b))
* bump pypdf from 6.16.1 to 6.19.0
([#1012](#1012))
([4ae72c0](4ae72c0))
* bump urllib3 from 2.7.0 to 2.8.0
([95c4a85](95c4a85))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
benbrasso added a commit that referenced this pull request Oct 3, 2026
## Summary

Anchore now fails every PR (first seen on #1021) on a single finding:
`CVE-2026-12345` in CPython 3.14.8 from `python:3.14-slim`. Add a
documented temporary safelist entry, following the existing policy for
Python vulnerabilities whose fix is unavailable on the supported runtime
line (same approach as #1017). This suppresses the finding; it does
**not** patch the vulnerability.

- **What it is:** a race condition in `tempfile.TemporaryDirectory`
cleanup. An attacker who can modify the temporary tree during cleanup
can swap a directory for a symlink, so files outside the temporary
directory can be deleted or have permissions/flags reset. Medium
severity (CVSS 4.0 score 5.9), local attack vector. Published
2026-09-29.
- **Why safelist instead of upgrade:** 3.14.8 is the latest 3.14
release. The fix is merged for 3.15 (3.15.0rc3) and has not been
backported to 3.14, so there is nothing to upgrade to. Grype lists the
fix only in 3.15.0.
- **When to remove:** once `python:3.14-slim` ships a 3.14 release with
the backport and Grype recognizes it.

Mirrored in simpler-grants-gov's `.grype.yml` so the deploy scan
enforces the same rule.

References:
- Advisory: https://www.cve.org/CVERecord?id=CVE-2026-12345
- Upstream issue: python/cpython#157579
- Tracking: HHS/simpler-grants-gov#8109

## Test plan

- Anchore output on #1021 before this change: only `python 3.14.8 /
CVE-2026-12345 / Medium / fixed in 3.15.0`.
- Checked the CVE record (CVEProject/cvelistV5) and CPython's 3.14
branch: no 3.14 backport or release yet.
- `.grype.yml` parses as valid YAML. The Anchore Scan check on this PR
should pass.

## Checklist

- [x] Tests pass locally (`make test`): no application code changed
- [x] No import-rule changes, so `documentation/IMPORT_RULES.md` doesn't
need updating

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_011q1hrRfsosZzADmnXZuLi2

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant