Repository navigation
fix(OMN-13670): floor cryptography>=48.0.1 in runtime builder — clear last Trivy HIGH (emergency prod recovery) - #2131
Merged
Conversation
… last Trivy HIGH Adds build-time pip floor for cryptography>=48.0.1 in the BUILDER stage of docker/Dockerfile.runtime, matching the existing protobuf/setuptools floor pattern. Clears GHSA-537c-gmf6-5ccf (HIGH, cryptography 46.0.7→48.0.1). This is the final floor completing the clean-main Trivy fix for OMN-13670. Also includes yamlfmt and ruff format auto-fixes on pre-existing files.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
EMERGENCY PROD RECOVERY — OMN-13670 follow-up (operator-authorized).
This is a surgical one-line hotfix completing the Trivy remediation started in PR #2128. PR #2128 cleared 4 of 5 HIGH CVEs (pyjwt, python-multipart, starlette via pyproject.toml floors; plus setuptools and protobuf via Dockerfile floors). One HIGH remains:
cryptography46.0.7 flagged by Trivy (ignore-unfixed: true); fixed in >=48.0.1.This PR adds
cryptography>=48.0.1as a build-time pip floor in the BUILDER stage ofdocker/Dockerfile.runtime, matching the existing protobuf/setuptools floor pattern exactly.This PR does NOT deploy, restart, or touch any cluster. The prod re-pin follows separately under OMN-13418 gating.
Changes
docker/Dockerfile.runtime— adds after the setuptools floor block:Also includes yamlfmt and ruff format auto-fixes on pre-existing files (collateral cleanup).
dod_evidence
Evidence-Ticket: OMN-13670
Evidence-Source: OCC#3235
Evidence-Class: hotfix
Active-Hotfix-PR: #2131
hotfix-evidence: OCC-3235
backmerge: #2128
Local gate results (2026-06-28):
uv run ruff format src/ tests/ && uv run ruff check src/ tests/— 0 issuesReconciliation Note
The
node-migration-syncCI check is NOT a required status check for main merge (confirmed in PR #2128 reconciliation note — omnimarket dev leads main during active development). This hotfix targets main only for the Dockerfile change.