Skip to content

chore(secops): remediate critical vulnerabilities#185

Open
muscariello wants to merge 1 commit intoagntcy:mainfrom
muscariello:fix/secops-remediate-20260310
Open

chore(secops): remediate critical vulnerabilities#185
muscariello wants to merge 1 commit intoagntcy:mainfrom
muscariello:fix/secops-remediate-20260310

Conversation

@muscariello
Copy link
Member

Automated remediation for critical dependency vulnerabilities and container-image findings.

Dependency updates:

  • authlib: update_failed
  • nltk: update_failed
  • pillow: update_failed
  • cryptography: update_failed
  • cryptography: update_failed

Container image remediation guidance:

  • [CVE-2026-27171] zlib fixed in 1.3.2-r0 on ghcr.io/cirruslabs/flutter:stable in tourist_scheduling_system/containers/frontend/Dockerfile (base_image_refresh_recommended)
  • [CVE-2026-22184] zlib fixed in 1.3.2-r0 on ghcr.io/cirruslabs/flutter:stable in tourist_scheduling_system/containers/frontend/Dockerfile (base_image_refresh_recommended)
  • [CVE-2026-28802] Authlib in usr/local/lib/python3.12/site-packages/authlib-1.6.6.dist-info/METADATA (no_dockerfile_found)
  • [CVE-2026-25646] libpng fixed in 1.6.55-r0 on ghcr.io/cirruslabs/flutter:stable in tourist_scheduling_system/containers/frontend/Dockerfile (base_image_refresh_recommended)
  • [CVE-2025-14831] libgnutls30t64 in agntcy/apps/scheduler-agent (no_dockerfile_found)
  • [CVE-2025-14831] libgnutls30t64 in agntcy/apps/ui-agent (no_dockerfile_found)
  • [CVE-2026-26007] cryptography in usr/local/lib/python3.12/site-packages/cryptography-46.0.4.dist-info/METADATA (no_dockerfile_found)
  • [CVE-2026-25210] libexpat fixed in 2.7.4-r0 on ghcr.io/cirruslabs/flutter:stable in tourist_scheduling_system/containers/frontend/Dockerfile (base_image_refresh_recommended)
  • [CVE-2025-8869] pip in usr/local/lib/python3.12/site-packages/pip-25.0.1.dist-info/METADATA (no_dockerfile_found)

Fixes #184

Signed-off-by: Luca Muscariello <lumuscar@cisco.com>
@codecov-commenter
Copy link

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@muscariello muscariello requested a review from msardara March 10, 2026 11:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SecOps: remediate critical vulnerabilities

2 participants