Skip to content

🛡️ Patch Buccaneerr virtualenv and retire fixed nghttp2 workaround - #103

Merged
scottgigawatt merged 2 commits into
mainfrom
wee/no-bilge-left-behind
Oct 4, 2026
Merged

scottgigawatt merged 2 commits into
mainfrom
wee/no-bilge-left-behind

Conversation

@scottgigawatt

@scottgigawatt scottgigawatt commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Buccaneerr's Alpine virtualenv 21.3.3 has four published security fixes that Docker Scout detects even though the current Trivy CI gate passes. Install pre-commit 4.6.2 and virtualenv 21.7.13 in an isolated test environment with exact versions and SHA-256 hashes for every dependency; remove the bootstrap pip after installation so its vulnerable bundled libraries do not remain in the image. Remove the obsolete nghttp2 edge-repository override from both Dockerfiles now that Alpine 3.24 stable supplies fixed nghttp2 1.70.0-r0 on every supported architecture. Buccaneerr retains the separate setuptools edge exception, which stable still needs.

Renovate manages the new Python lockfile and respects virtualenv's filelock <4 requirement. Refresh the container scan review with all-platform immutable edge/latest scans, the already-fixed containerd/Python/PCRE2/npm findings, the remaining unfixed braces issue and scanner metadata reports, and the stable release needed to deliver source fixes through latest.

Validation:

  • Buccaneerr build and both-image builds for amd64, arm64, and arm/v7 passed.
  • Full offline suite passed, including strict typing, Ruff lint/format, shell and workflow checks, helper tests, and 38 Python tests. Isolated worktree validation mounted its Git metadata read-only.
  • All repository hooks, project-wide CSpell, strict documentation build, and staged whitespace checks passed. The signed commit also ran normal repository hooks with the worktree's Git metadata mounted read-only.
  • Fresh rebuilt ARM64 artifact scan: all four virtualenv CVEs removed; Trivy reports only unfixed braces CVE-2026-93687 and the OpenPGP module warning. Scout reports those plus Windows-only Docker CLI/x/sys and patched gRPC 1.84.0 metadata.

No live PIA/VPN behavior changed. Published latest remains v2.1.2 until a separately authorized stable release refreshes it; the scan review records its current fixed vulnerabilities honestly. 🏳️‍🌈🏴‍☠️

@scottgigawatt scottgigawatt changed the title 🛡️ Patch Buccaneerr virtualenv and refresh image scan evidence 🛡️ Patch Buccaneerr virtualenv and retire fixed nghttp2 workaround Oct 4, 2026
@scottgigawatt
scottgigawatt merged commit 7ad0bc2 into main Oct 4, 2026
5 checks passed
@scottgigawatt
scottgigawatt deleted the wee/no-bilge-left-behind branch October 4, 2026 20:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant