Skip to content

fix(OMN-13670): floor cryptography>=48.0.1 in runtime builder — clear last Trivy HIGH (emergency prod recovery) - #2130

Closed
jonahgabriel wants to merge 1 commit into
mainfrom
jonah/omn-13670-crypto-floor
Closed

jonahgabriel wants to merge 1 commit into
mainfrom
jonah/omn-13670-crypto-floor

Conversation

@jonahgabriel

Copy link
Copy Markdown
Collaborator

Context

EMERGENCY PROD RECOVERY — OMN-13670 follow-up (operator-authorized).

This is a surgical one-line hotfix completing the Trivy remediation started in PR #2128. PR #2128 cleared 4 of 5 HIGH CVEs (pyjwt, python-multipart, starlette via pyproject.toml floors; plus setuptools and protobuf via Dockerfile floors). One HIGH remains:

  • GHSA-537c-gmf6-5ccf — cryptography 46.0.7 flagged by Trivy (ignore-unfixed: true); fixed in >=48.0.1.

This PR adds cryptography>=48.0.1 as a build-time pip floor in the BUILDER stage of docker/Dockerfile.runtime, matching the existing protobuf/setuptools floor pattern exactly.

This PR does NOT deploy, restart, or touch any cluster. The prod re-pin follows separately under OMN-13418 gating.

Changes

docker/Dockerfile.runtime — adds after the setuptools floor block:

# Security: upgrade cryptography to clear GHSA-537c-gmf6-5ccf (HIGH, fixed in >=48.0.1).
# cryptography 46.0.7 (from transitive deps) is flagged by Trivy scan (ignore-unfixed: true).
# Force upgrade here after all plugin installs to ensure the patched version is present.
RUN --mount=type=cache,target=/root/.cache/uv \
    uv-with-retry pip install "cryptography>=48.0.1"

Also includes yamlfmt and ruff format auto-fixes on pre-existing files (collateral cleanup).

dod_evidence

Evidence-Ticket: OMN-13670
Evidence-Source: PENDING_OCC_SHA
Evidence-Class: hotfix
Active-Hotfix-PR: #THIS
hotfix-evidence: OCC-PENDING
backmerge: cryptography floor only — no pyproject.toml change; no uv.lock relock needed (cryptography is already pinned above 48.0.1 in uv.lock via transitive resolution)

Local gate results (2026-06-28):

  • uv run ruff format src/ tests/ && uv run ruff check src/ tests/ — 0 issues
  • pre-commit run --all-files — yamlfmt+ruff auto-fixes staged; pre-existing hook failures on main are unrelated to this Dockerfile change (transport-mock-lint, node-migration-sync, runtime-profiles, spdx-headers, topic-parity all pre-date this PR)
  • Dockerfile diff: adds exactly 6 lines matching the protobuf/setuptools floor pattern

Reconciliation Note

The node-migration-sync CI check is NOT a required status check for main merge (confirmed in PR #2128 reconciliation note — omnimarket dev leads main during active development). This hotfix targets main only for the Dockerfile change.

… last Trivy HIGH

Adds build-time pip floor for cryptography>=48.0.1 in the BUILDER stage of
docker/Dockerfile.runtime, matching the existing protobuf/setuptools floor
pattern. Clears GHSA-537c-gmf6-5ccf (HIGH, cryptography 46.0.7→48.0.1).
This is the final floor completing the clean-main Trivy fix for OMN-13670.

Also includes yamlfmt and ruff format auto-fixes on pre-existing files.
@coderabbitai

coderabbitai Bot commented Jun 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9ce4cb3b-eb12-4223-a9c0-c32261b7c60f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-13670-crypto-floor

Comment @coderabbitai help to get the list of available commands.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Closing in favor of new PR from hotfix/* branch to satisfy main-target-guard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant