Skip to content

fix(OMN-13670): expand Trivy CVE floors to green clean-main runtime build (emergency prod recovery) - #2129

Closed
jonahgabriel wants to merge 1 commit into
mainfrom
jonah/omn-13670-expand-trivy-floors
Closed

jonahgabriel wants to merge 1 commit into
mainfrom
jonah/omn-13670-expand-trivy-floors

Conversation

@jonahgabriel

Copy link
Copy Markdown
Collaborator

Context

EMERGENCY PROD RECOVERY — OMN-13670 (operator-authorized) — follow-up to #2128.

PR #2128 (merged 2026-06-27) re-applied OMN-13654 dep floors + OMN-13666 entrypoint tolerance.
However the ECR build-and-push-runtime.yml still fails after #2128 because:

  • cryptography==46.0.7 (the resolved version from the >=46.0.3 floor) triggers GHSA-537c-gmf6-5ccf (HIGH): vulnerable OpenSSL bundled in cryptography wheels; fixed in 48.0.1.

Trivy scanner log from run 28298553147 (post-#2128 push):

│ cryptography (METADATA) │ GHSA-537c-gmf6-5ccf │ HIGH │ fixed │ 46.0.7 │ 48.0.1 │ Vulnerable OpenSSL included in cryptography wheels │

Changes

Cryptography CVE floor expansion

pyproject.toml raises the cryptography floor from >=46.0.3 to >=48.0.1:

cryptography>=48.0.1,<49.0.0   # GHSA-537c-gmf6-5ccf: vulnerable OpenSSL in wheels <48.0.1

uv lock resolves: cryptography 48.0.1. Trivy gate passes 0 HIGH/CRITICAL at this version.

DoD evidence (dod-crypto-floor): grep -q 'cryptography>=48.0.1' pyproject.toml — passes.

dod_evidence

Evidence-Ticket: OMN-13670
Evidence-Source: OCC#3233
Evidence-Class: hotfix
Active-Hotfix-PR: #2129
hotfix-evidence: OCC-3233
backmerge: #2128 (original floors)

Local gate results (2026-06-28):

  • uv run ruff format src/ tests/ && uv run ruff check --fix src/ tests/ — 0 issues
  • uv run mypy src/ --strict — "Success: no issues found in 2442 source files"
  • uv run pytest tests/unit/docker/ tests/unit/runtime/ -q — 4976 passed, 8 skipped, 0 failed
  • pre-commit run --files pyproject.toml uv.lock (OMNIMARKET_SRC=omnimarket@main) — all hooks pass

Reconciliation Note

This is a targeted surgical extension of the OMN-13670 hotfix. The floor change is minimal:
only the cryptography lower-bound is raised (>=46.0.3 → >=48.0.1). uv.lock is relocked.
No other files are changed. The migration vendor tree remains in sync with omnimarket main
(the correct comparison base for a main-targeting hotfix).

The node-migration-sync CI check shows a non-fatal diff (omnimarket dev has progressed since
the last main promotion) — this is expected for any main-targeting PR during a period where
dev leads. node-migration-sync is NOT a required status check for main merge.

Post-merge

Prod re-pin (ECR retag + container restart) follows as a separate step, OMN-13418-gated with
fresh CODEOWNERS-approved grant.

…37c-gmf6-5ccf)

GHSA-537c-gmf6-5ccf (HIGH): cryptography wheels <48.0.1 bundle a
vulnerable OpenSSL build. Fixed in 48.0.1. Trivy gate was blocking
the ECR build with cryptography==46.0.7.

Raises the floor from >=46.0.3 to >=48.0.1. uv lock resolves:
cryptography 48.0.1.

DoD evidence: grep -q 'cryptography>=48.0.1' pyproject.toml — passes.
@coderabbitai

coderabbitai Bot commented Jun 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 2c93ad40-04b6-4541-8955-afc48d440da3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-13670-expand-trivy-floors

Comment @coderabbitai help to get the list of available commands.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Superseded by #2131 (single-line cryptography floor). Closing as duplicate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant