Skip to content

fix(OMN-13670): floor cryptography>=48.0.1 in runtime builder — clear last Trivy HIGH (emergency prod recovery) - #2131

Merged
jonahgabriel merged 2 commits into
mainfrom
hotfix/omn-13670-crypto-floor
Jun 28, 2026
Merged

jonahgabriel merged 2 commits into
mainfrom
hotfix/omn-13670-crypto-floor

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jun 28, 2026 •

Copy link
Copy Markdown
Collaborator

Context

EMERGENCY PROD RECOVERY — OMN-13670 follow-up (operator-authorized).

This is a surgical one-line hotfix completing the Trivy remediation started in PR #2128. PR #2128 cleared 4 of 5 HIGH CVEs (pyjwt, python-multipart, starlette via pyproject.toml floors; plus setuptools and protobuf via Dockerfile floors). One HIGH remains:

  • GHSA-537c-gmf6-5ccf — cryptography 46.0.7 flagged by Trivy (ignore-unfixed: true); fixed in >=48.0.1.

This PR adds cryptography>=48.0.1 as a build-time pip floor in the BUILDER stage of docker/Dockerfile.runtime, matching the existing protobuf/setuptools floor pattern exactly.

This PR does NOT deploy, restart, or touch any cluster. The prod re-pin follows separately under OMN-13418 gating.

Changes

docker/Dockerfile.runtime — adds after the setuptools floor block:

# Security: upgrade cryptography to clear GHSA-537c-gmf6-5ccf (HIGH, fixed in >=48.0.1).
# cryptography 46.0.7 (from transitive deps) is flagged by Trivy scan (ignore-unfixed: true).
# Force upgrade here after all plugin installs to ensure the patched version is present.
RUN --mount=type=cache,target=/root/.cache/uv \
    uv-with-retry pip install "cryptography>=48.0.1"

Also includes yamlfmt and ruff format auto-fixes on pre-existing files (collateral cleanup).

dod_evidence

Evidence-Ticket: OMN-13670
Evidence-Source: OCC#3235
Evidence-Class: hotfix
Active-Hotfix-PR: #2131
hotfix-evidence: OCC-3235
backmerge: #2128

Local gate results (2026-06-28):

  • uv run ruff format src/ tests/ && uv run ruff check src/ tests/ — 0 issues
  • Dockerfile diff: adds exactly 6 lines matching the protobuf/setuptools floor pattern

Reconciliation Note

The node-migration-sync CI check is NOT a required status check for main merge (confirmed in PR #2128 reconciliation note — omnimarket dev leads main during active development). This hotfix targets main only for the Dockerfile change.

… last Trivy HIGH

Adds build-time pip floor for cryptography>=48.0.1 in the BUILDER stage of
docker/Dockerfile.runtime, matching the existing protobuf/setuptools floor
pattern. Clears GHSA-537c-gmf6-5ccf (HIGH, cryptography 46.0.7→48.0.1).
This is the final floor completing the clean-main Trivy fix for OMN-13670.

Also includes yamlfmt and ruff format auto-fixes on pre-existing files.
@coderabbitai

coderabbitai Bot commented Jun 28, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3070501c-2f98-436e-9faf-9c638eaf8425

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch hotfix/omn-13670-crypto-floor

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant