fix: temporarily safelist unreleased Python tarfile fix - #1017
Merged
Merged
Conversation
benbrasso
pushed a commit
that referenced
this pull request
Oct 2, 2026
🤖 I have created a release *beep* *boop* --- ## [3.47.0](nofos-v3.46.0...nofos-v3.47.0) (2026-10-02) ### Features * add SAMHSA user group ([#1004](#1004)) ([0c74ff0](0c74ff0)) * add saved readability checkpoints and history ([#1014](#1014)) ([b714111](b714111)) * auto-size "Point value" columns in scoring tables ([#1008](#1008)) ([dd8c867](dd8c867)) ### Bug Fixes * protect production GrabzIt Word export ([#1002](#1002)) ([9391867](9391867)), closes [#1000](#1000) * temporarily safelist unreleased Python tarfile fix ([#1017](#1017)) ([a25cb05](a25cb05)) * update NOFO metadata field guidance ([#1001](#1001)) ([de47d52](de47d52)) * upgrade virtualenv and remove unused Login.gov sign-in ([#1011](#1011)) ([08cd880](08cd880)) ### Documentation * clarify PDF publishing scope ([#1015](#1015)) ([94721a5](94721a5)) * consolidate repository documentation ([#1016](#1016)) ([33b7e9a](33b7e9a)) * draft approved PDF retrieval proposal for Announcement Services ([#1010](#1010)) ([755ce2d](755ce2d)) ### Miscellaneous Chores * bump boto3 from 1.43.93 to 1.43.96 in the python-minor-and-patch group across 1 directory ([#1006](#1006)) ([de4bc0b](de4bc0b)) * bump pypdf from 6.16.1 to 6.19.0 ([#1012](#1012)) ([4ae72c0](4ae72c0)) * bump urllib3 from 2.7.0 to 2.8.0 ([95c4a85](95c4a85)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This was referenced Oct 2, 2026
benbrasso
added a commit
that referenced
this pull request
Oct 3, 2026
## Summary Anchore now fails every PR (first seen on #1021) on a single finding: `CVE-2026-12345` in CPython 3.14.8 from `python:3.14-slim`. Add a documented temporary safelist entry, following the existing policy for Python vulnerabilities whose fix is unavailable on the supported runtime line (same approach as #1017). This suppresses the finding; it does **not** patch the vulnerability. - **What it is:** a race condition in `tempfile.TemporaryDirectory` cleanup. An attacker who can modify the temporary tree during cleanup can swap a directory for a symlink, so files outside the temporary directory can be deleted or have permissions/flags reset. Medium severity (CVSS 4.0 score 5.9), local attack vector. Published 2026-09-29. - **Why safelist instead of upgrade:** 3.14.8 is the latest 3.14 release. The fix is merged for 3.15 (3.15.0rc3) and has not been backported to 3.14, so there is nothing to upgrade to. Grype lists the fix only in 3.15.0. - **When to remove:** once `python:3.14-slim` ships a 3.14 release with the backport and Grype recognizes it. Mirrored in simpler-grants-gov's `.grype.yml` so the deploy scan enforces the same rule. References: - Advisory: https://www.cve.org/CVERecord?id=CVE-2026-12345 - Upstream issue: python/cpython#157579 - Tracking: HHS/simpler-grants-gov#8109 ## Test plan - Anchore output on #1021 before this change: only `python 3.14.8 / CVE-2026-12345 / Medium / fixed in 3.15.0`. - Checked the CVE record (CVEProject/cvelistV5) and CPython's 3.14 branch: no 3.14 backport or release yet. - `.grype.yml` parses as valid YAML. The Anchore Scan check on this PR should pass. ## Checklist - [x] Tests pass locally (`make test`): no application code changed - [x] No import-rule changes, so `documentation/IMPORT_RULES.md` doesn't need updating 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_011q1hrRfsosZzADmnXZuLi2 Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PR #1014 fails Anchore on the sole remaining finding:
CVE-2026-87910in CPython 3.14.8 (/usr/local/lib/libpython3.14.so.1.0). Add a documented temporary safelist entry, following the existing policy for Python vulnerabilities whose fix is unavailable on the supported runtime line. This suppresses the finding; it does not patch the vulnerability.The 3.14 backport merged on October 1 after the 3.14.8 release. The PSF CVE record still marks the 3.14 series affected, and the release announcement lists this fix for 3.10–3.13 only. Remove the exception once
python:3.14-slimcontains the backport and Grype recognizes the fixed release.HHS/simpler-grants-gov#12615 updates urllib3, Amazon Linux packages and frontend dependencies; none addresses this CPython finding in the Debian-based NOFO image. No dependency or image changes are needed for this temporary scan-policy change.
After this PR merges, rebase #1014 onto main to pick up the exception. The deployment repository maintains a separate
.grype.yml; its NOFO deployment scan will need the same exception while the runtime fix remains unreleased. This PR changes only the PDF Builder repository.Test plan
.grype.ymland recognized the new ignore entry.git diff --checkpassed.