Skip to content

fix(deps): close all 8 OSV advisories flagged by Scorecard (Vulnerabilities 8 → 10) - #372

Merged
Cre-eD merged 1 commit into
mainfrom
fix/sca-osv-scorecard
Aug 3, 2026
Merged

fix(deps): close all 8 OSV advisories flagged by Scorecard (Vulnerabilities 8 → 10)#372
Cre-eD merged 1 commit into
mainfrom
fix/sca-osv-scorecard

Conversation

@Cre-eD

@Cre-eD Cre-eD commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Summary

OpenSSF Scorecard's Vulnerabilities check is at 8/10 with 8 open advisories. This PR takes it to 10/10.

  • 7 fixed by version bump — 3 Go, 4 Python (all severities, nothing deferred).
  • 1 unfixable by designGO-2026-5932 has introduced: 0 and no fix event in OSV. Declared not_affected with reachability evidence.
  • 2 stale suppressions retiredGO-2022-0635 / GO-2022-0646 no longer apply; removed rather than carried forward.

osv-scanner scan source -r .No issues found (was 8). Scorecard runs the same scanner (osvscanner.DoScan via clients/osv.go) against the repo root, so the check flips on merge to main.

Fixed

Package Old → New Advisory Sev Where
github.com/klauspost/compress 1.18.4 → 1.18.7 GO-2026-5841 / GHSA-259r-337f-4rfw — OOB read in s2 HIGH go.mod (indirect)
google.golang.org/grpc 1.81.1 → 1.82.1 GO-2026-6061 / GHSA-hrxh-6v49-42gf — xDS RBAC + HTTP/2 server HIGH go.mod (indirect)
click 8.1.8 → 8.4.2 PYSEC-2026-2132 / CVE-2026-7246 MEDIUM docs/requirements.txt
pymdown-extensions 10.21.3 → 11.0.1 GHSA-9xwg-3r6f-jcx2 / CVE-2026-61632b64 path traversal MEDIUM docs/requirements.txt
setuptools 82.0.1 → 83.0.0 PYSEC-2026-3447 / CVE-2026-59890 MEDIUM docs/requirements.txt
soupsieve 2.8.3 → 2.9.1 PYSEC-2026-3071 / CVE-2026-49476 — memory exhaustion HIGH docs/requirements.txt
soupsieve 2.8.3 → 2.9.1 PYSEC-2026-3072 / CVE-2026-49477 — ReDoS in selector parser HIGH docs/requirements.txt

Side-effect bumps pulled in by the above: x/crypto 0.53.0 → 0.54.0, x/sys 0.46.0 → 0.47.0, x/term 0.44.0 → 0.45.0, opentelemetry-operations-go/detectors/gcp 1.31.0 → 1.32.0, contrib/detectors/gcp 1.42.0 → 1.43.0, plus the tools.go chain (see CI ordering below).

How the Python side was done

docs/requirements.in gains explicit patched floors for the four packages, following the pattern already established for requests / urllib3 after #264 — pinning the floor in the .in file is what stops a future pip-compile from silently resolving back to a vulnerable version. docs/requirements.txt was then regenerated with pip-compile --allow-unsafe --generate-hashes --upgrade.

mkdocs-material 9.7.7 declares pymdown-extensions>=10.2 with no upper bound, so the 11.x major is in range for the theme — no theme pin change needed, and the docs site builds clean (evidence below). The b64 extension that carries CVE-2026-61632 is not enabled in docs/mkdocs.yml at all; the bump closes the advisory rather than a live exposure.

Not fixable — GO-2026-5932 (golang.org/x/crypto/openpgp)

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues.

This is a permanent "this package should not be used" notice, not a patchable defect. In OSV it is introduced: 0 with no fix event, so no version of x/crypto clears it — bumping to 0.54.0 (done here anyway, for hygiene) changes nothing.

Reachability:

  1. Where in the treex/crypto is a direct dependency, required for chacha20poly1305 in pkg/api/secrets/ciphers. The advisory covers only openpgp and its six subpackages.
  2. Is it in the artifact — no. go list -deps ./... | grep x/crypto/openpgp returns nothing, and Go's linker does not emit packages no import path reaches. The vulnerable code is not present in any binary this repo produces.
  3. Is the vulnerable code called — no. govulncheck -mode=source ./... reports 0 reachable vulnerabilities; this advisory lands in its "modules you require, but your code doesn't appear to call" bucket.
  4. What OpenPGP work actually runsgithub.com/ProtonMail/go-crypto/openpgp, which is the maintained fork the advisory text itself recommends as the replacement.
  5. What would change the answer — any new import of x/crypto/openpgp/*. That would flip the VEX statement to affected and block the gate.

Recorded as status: not_affected, justification: vulnerable_code_not_present in vex/openvex.json, mirrored into osv-scanner.toml — Scorecard's check has no VEX input, so the mirror is the only channel that reaches it. No .trivyignore, no # nosec, nothing hidden.

Re-triage of existing suppressions

Both entries that predate this PR were re-checked rather than carried forward:

Advisory Was Now Why
GO-2022-0635 (aws-sdk-go v1 s3crypto) not_affected + ignore fixed, ignore removed github.com/aws/aws-sdk-go (v1) is no longer in go.mod — the Pulumi upgrades dropped the last build-graph edge and Go module pruning removed it. osv-scanner reported the entry as an unused ignore.
GO-2022-0646 (same subpackage) not_affected + ignore fixed, ignore removed Same.

VEX statements are kept one release as an audit trail; the osv-scanner.toml entries are gone.

Governance changes

  • CODEOWNERS/vex/ and /osv-scanner.toml are now named explicitly. A not_affected statement hides a real advisory from both the scanners and the Scorecard badge; that is the same class of change as touching a workflow, and it should not merge on a generic * match.
  • docs/DEPENDENCIES.md — documents (a) that osv-scanner.toml is a derivative mirror which may only carry an ID that already exists in VEX, and (b) that every SCA pass re-triages both files, with unused ignores as the removal signal. Previously the policy said suppressions live "never in a scanner-suppression file" while osv-scanner.toml existed; policy and practice now agree.
  • osv-scanner.toml — added a note that reason must stay a single-line TOML basic string. A newline in it makes osv-scanner discard the entire config (strings cannot contain newlines) and silently re-report every ignored advisory. Hit while writing this PR.

CI ordering (tools.go pre-bake)

build-setup runs go get $(tools.go imports)go mod downloadgo generate -tags toolsgo mod tidy. Because go get resolves tools to latest and tidy only runs afterwards, a tool minor landing between runs breaks go generate with missing go.sum entry. The post-go get state is pre-baked into this commit so CI's go get is a no-op: go-jsonschema 0.23.1 → 0.24.1, go-internal 1.14.1 → 1.15.0, gofumpt 0.10.0 → 0.11.0, x/mod 0.37.0 → 0.38.0, x/net 0.56.0 → 0.57.0, x/tools 0.47.0 → 0.48.0, x/telemetry bumped.

Dependabot reconciliation

Open alerts before this PR: 5 — pymdown-extensions, setuptools, soupsieve ×2, grpc. All 5 are closed by the bumps above; they auto-resolve once this lands on main. click (PYSEC-2026-2132) and klauspost/compress (GO-2026-5841) were not alerted by Dependabot but are flagged by OSV — fixed here too.

Open Dependabot PRs:

PR Disposition
#361 soupsieve 2.8.3 → 2.8.4 Superseded — this PR goes to 2.9.1. Dependabot closes it automatically when the manifest lands.
#371, #352, #351, #334, #333, #326 Untouched — github-actions / docker streams, unrelated to this PR.

No config change needed: .github/dependabot.yml already covers gomod (/), pip (/docs), docker, and github-actions.

Evidence

osv-scanner scan source -r . — before
click              8.1.8    [PyPI] -> PYSEC-2026-2132
pymdown-extensions 10.21.3  [PyPI] -> GHSA-9xwg-3r6f-jcx2
setuptools         82.0.1   [PyPI] -> PYSEC-2026-3447, GHSA-h35f-9h28-mq5c
soupsieve          2.8.3    [PyPI] -> PYSEC-2026-3071, PYSEC-2026-3072,
                                      GHSA-2wc2-fm75-p42x, GHSA-836r-79rf-4m37
klauspost/compress 1.18.4   [Go]   -> GO-2026-5841
golang.org/x/crypto 0.53.0  [Go]   -> GO-2026-5932
google.golang.org/grpc 1.81.1 [Go] -> GO-2026-6061, GHSA-hrxh-6v49-42gf

osv-scanner.toml has unused ignores:
 - GO-2022-0635
 - GO-2022-0646
osv-scanner scan source -r . — after
Scanned docs/requirements.txt file and found 36 packages
Scanned go.mod file and found 486 packages
Loaded filter from: osv-scanner.toml
GO-2026-5932 has been filtered out because: VEX not_affected
  (vulnerable_code_not_present) ...
Filtered 1 vulnerability from output

No issues found
govulncheck -mode=source ./... — after
=== Symbol Results ===

No vulnerabilities found.

Your code is affected by 0 vulnerabilities.
This scan also found 0 vulnerabilities in packages you import and 1
vulnerability in modules you require, but your code doesn't appear to call
these vulnerabilities.

The 1 module-level finding is GO-2026-5932, covered above.

Test plan

  • go build ./...
  • go generate -tags tools (post-pre-bake, matches CI's build-setup order)
  • go test ./pkg/api/secrets/... ./pkg/security/... -count=1 — all pass
  • Docs built exactly as CI does it: docker run --rm -v $PWD/docs:/docs -w /docs python@sha256:401f6e1a... sh -c "pip install --require-hashes -r requirements.txt && mkdocs build"Documentation built in 3.39 seconds, hash check clean, no new warnings
  • jq empty vex/openvex.json
  • CI: govulncheck, CodeQL, Semgrep, build matrix

…lities 8 → 10)

Go (osv-scanner matches go.mod at module level, no reachability):
- klauspost/compress 1.18.4 → 1.18.7  (GO-2026-5841, s2 OOB read)
- google.golang.org/grpc 1.81.1 → 1.82.1  (GO-2026-6061 / GHSA-hrxh-6v49-42gf)
- golang.org/x/crypto 0.53.0 → 0.54.0  (hygiene, see below)

Python docs build chain (docs/requirements.in floors + pip-compile --upgrade):
- click 8.1.8 → 8.4.2  (PYSEC-2026-2132 / CVE-2026-7246)
- pymdown-extensions 10.21.3 → 11.0.1  (GHSA-9xwg-3r6f-jcx2 / CVE-2026-61632)
- setuptools 82.0.1 → 83.0.0  (PYSEC-2026-3447 / CVE-2026-59890)
- soupsieve 2.8.3 → 2.9.1  (PYSEC-2026-3071, PYSEC-2026-3072)

GO-2026-5932 (x/crypto/openpgp is unmaintained) carries introduced=0 with
no fix event, so no bump can ever close it. Nothing in the build graph
imports x/crypto/openpgp or its subpackages — OpenPGP work goes through
ProtonMail/go-crypto/openpgp, the maintained fork the advisory itself
recommends. Declared not_affected (vulnerable_code_not_present) in
vex/openvex.json and mirrored into osv-scanner.toml, which is the only
channel Scorecard reads.

Re-triaged the pre-existing suppressions: GO-2022-0635 / GO-2022-0646
(aws-sdk-go v1 s3crypto) dropped out of go.mod via module pruning after
the Pulumi upgrades, so osv-scanner reported both as unused ignores —
removed from osv-scanner.toml, VEX statements flipped to status: fixed.

Also in scope: tools.go deps pre-baked so CI's build-setup 'go get tools'
is a no-op before 'go generate'; /vex/ and /osv-scanner.toml named in
CODEOWNERS; DEPENDENCIES.md documents the mirror and the per-pass
re-triage requirement.

Verification:
- osv-scanner scan source -r . → No issues found (was 8)
- govulncheck -mode=source ./... → 0 reachable vulnerabilities
- docs build in the pinned python:3.12-slim digest → OK
- go build ./... + pkg/api/secrets + pkg/security tests → pass

Signed-off-by: Dmitrii Creed <creeed22@gmail.com>
@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown

Semgrep Scan Results

Repository: api | Commit: 2559d89

Check Status Details
⚠️ Semgrep Warning 1 warning(s), 5 total

Scanned at 2026-08-02 19:56 UTC

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown

Security Scan Results

Repository: api | Commit: 2559d89

Check Status Details
✅ Secret Scan Pass No secrets detected
✅ Dependencies (Trivy) Pass 1 total (no critical/high)
✅ Dependencies (Grype) Pass 1 total (no critical/high)
📦 SBOM Generated 523 components (CycloneDX)

Scanned at 2026-08-02 19:57 UTC

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown

📊 Statement coverage

Measured on the documented included set (see docs/TESTING.md → Coverage scope). Observe-only — no regression gate is enforced yet.

Scope This PR main baseline Δ
Included set (Gold-tier denominator) 90.4% 90.4% +0.0 pp
Full set (whole repo, transparency) 28.3% 28.3% +0.0 pp

Baseline: main @ 24c1417

@Cre-eD
Cre-eD merged commit 442f351 into main Aug 3, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants