Remediate RC6 container scan findings
GeoIntel release gates / Compile, test, contracts and builds (push) Canceled after 0s
GeoIntel release gates / Python and npm vulnerability policy (push) Canceled after 0s
GeoIntel release gates / GIS image, SBOM and container scan (push) Canceled after 0s

This commit is contained in:
Codex
2026-07-18 04:28:46 +02:00
parent 027e4b078b
commit 6a22fcd1f8
8 changed files with 65 additions and 2 deletions
+4 -1
View File
@@ -73,12 +73,15 @@ The dependency job:
- publishes both unfiltered and policy-filtered Python JSON reports plus the
npm JSON report, including on failure.
The only current Python exceptions are the Starlette 2026 advisories recorded
The only current Python/container exceptions are the Starlette 2026 advisories recorded
in `security/pip-audit-exceptions.json`. FastAPI 0.139.2 still constrains
Starlette below 0.53 while patched releases begin at 1.x. GeoIntel applies
request-target, form-content, route-class and Linux-runtime compensating
controls. The exception file has a mandatory review date; readiness and CI
fail automatically after it expires. New advisories are never auto-ignored.
The all-in-one image replaces the Go-based base-image `gosu` helper with a
small `setpriv` exec wrapper and upgrades packaged setuptools/wheel metadata;
these scanner findings are fixed rather than excepted.
The container job builds a non-AI all-in-one image and uses digest-pinned
scanner images: