Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/compose-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -195,7 +195,7 @@ jobs:
FLOWTEST_FEATURE_EVENT_PROTOCOLS_ENABLED: "true"
FLOWTEST_FEATURE_PERFORMANCE_LAB_ENABLED: "true"
FLOWTEST_FEATURE_ENVIRONMENT_LAB_ENABLED: "true"
FLOWTEST_ENVIRONMENT_IMAGE_ALLOWLIST: '["docker.io/nginxinc/nginx-unprivileged@sha256:123fb7283ffb4788e260d4e980005a978995fefedcdbb04d268077a19b84576d"]'
FLOWTEST_ENVIRONMENT_IMAGE_ALLOWLIST: '["cgr.dev/chainguard/nginx@sha256:a104d1995e56b7a15e8f152078dfbdb1ecbf9f9d1af311e7906e7b4c0c790cf2"]'
FLOWTEST_AI_BASE_URL: http://mock-target:8080/v1
FLOWTEST_AI_MODEL: flowtest-compose-model
FLOWTEST_AI_API_KEY: flowtest-mock-ai-key
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/security-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -82,8 +82,8 @@ jobs:
done
- name: Prepare pinned environment fixture
run: |
docker pull docker.io/nginxinc/nginx-unprivileged@sha256:123fb7283ffb4788e260d4e980005a978995fefedcdbb04d268077a19b84576d
docker tag docker.io/nginxinc/nginx-unprivileged@sha256:123fb7283ffb4788e260d4e980005a978995fefedcdbb04d268077a19b84576d flowtest-environment-fixture:ci
docker pull cgr.dev/chainguard/nginx@sha256:a104d1995e56b7a15e8f152078dfbdb1ecbf9f9d1af311e7906e7b4c0c790cf2
docker tag cgr.dev/chainguard/nginx@sha256:a104d1995e56b7a15e8f152078dfbdb1ecbf9f9d1af311e7906e7b4c0c790cf2 flowtest-environment-fixture:ci
- name: Scan backend image
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 # v7.4.0
with:
Expand Down
10 changes: 10 additions & 0 deletions backend/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -140,6 +140,7 @@ RUN set -eux; \
ctr --version

FROM ${FLOWTEST_ENVIRONMENT_DAEMON_BASE} AS environment-daemon
RUN apk add --no-cache --upgrade 'pcre2>=10.49-r0' 'libexpat>=2.8.5-r0'

FROM debian:trixie-slim AS python-base-source

Expand Down Expand Up @@ -244,6 +245,15 @@ ENV PYTHONDONTWRITEBYTECODE=1 \
PIP_NO_CACHE_DIR=1

FROM ${FLOWTEST_PYTHON_BASE} AS python-runtime
# Refresh fixed Debian libraries after selecting the reusable Python base.
RUN set -eux; \
apt-get update; \
apt-get install -y --no-install-recommends --only-upgrade \
libssl3t64 openssl-provider-legacy libpcre2-8-0; \
dpkg --compare-versions "$(dpkg-query -W -f='${Version}' libssl3t64)" ge '3.5.7-1~deb13u3'; \
dpkg --compare-versions "$(dpkg-query -W -f='${Version}' openssl-provider-legacy)" ge '3.5.7-1~deb13u3'; \
dpkg --compare-versions "$(dpkg-query -W -f='${Version}' libpcre2-8-0)" ge '10.46-1~deb13u3'; \
apt-get dist-clean
WORKDIR /app

COPY --from=uv /uv /uvx /bin/
Expand Down
4 changes: 2 additions & 2 deletions backend/tests/test_environment_lab.py
Original file line number Diff line number Diff line change
Expand Up @@ -42,8 +42,8 @@
USER_EMAIL = "environment-user@example.com"
USER_PASSWORD = "environment-user-password-123!"
FIXTURE_IMAGE = (
"docker.io/nginxinc/nginx-unprivileged@sha256:"
"123fb7283ffb4788e260d4e980005a978995fefedcdbb04d268077a19b84576d"
"cgr.dev/chainguard/nginx@sha256:"
"a104d1995e56b7a15e8f152078dfbdb1ecbf9f9d1af311e7906e7b4c0c790cf2"
)


Expand Down
6 changes: 3 additions & 3 deletions backend/uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

30 changes: 30 additions & 0 deletions docs/operations/environment-fixture-security-2026-10-03.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
# 环境夹具与运行时安全更新(2026-10-03)

## 问题与修改范围

固定的 Nginx 环境夹具包含 PCRE2 10.48,现有 High / Critical 门禁报告可修复的 CVE-2026-103111。官方最新 Alpine 与 Debian 镜像的实际依赖仍未消除当前扫描阻塞。

将环境实验室默认示例、前后端测试、S26 验收脚本、Compose 允许列表及安全扫描统一更新为以下多架构不可变镜像:

```text
cgr.dev/chainguard/nginx@sha256:a104d1995e56b7a15e8f152078dfbdb1ecbf9f9d1af311e7906e7b4c0c790cf2
```

该镜像可匿名拉取,amd64 与 arm64 均包含 PCRE2 10.49-r1,使用 UID / GID 65532,默认监听 8080。[供应方兼容说明](https://images.chainguard.dev/directory/image/nginx/overview)列出非 root 用户、端口及只读根文件系统所需的 `/run`、`/var/lib/nginx/tmp`,与现有环境执行器的固定安全参数一致。

同时纳入本次门禁已定位的依赖修复:urllib3 2.8.0、Axios 1.20.0 / follow-redirects 1.16.1;Python 与 Mock 镜像在选择基础镜像后安装已修复的 Debian OpenSSL / PCRE2;前端镜像要求 Alpine PCRE2 至少 10.49-r0;环境 daemon 要求 PCRE2 至少 10.49-r0、Expat 至少 2.8.5-r0。Python、Node、pnpm、Go 与测试框架版本维持原样。

## 已执行验证

- 使用注册表返回的多架构摘要、子清单和各层 SHA-256 校验下载结果,检查两个架构的实际镜像配置与包数据库。
- 对两个架构的原始 OCI 镜像执行 Grype 0.116.1,沿用 `.grype.yaml`、`--only-fixed --fail-on high`:High / Critical 均为 0。扫描对象未加入诊断工具。
- 原始 arm64 镜像的临时诊断构建仅增加 BusyBox 及其加载器,在 UID / GID 65532 下验证 Nginx 配置及 HTTP 根路径:200。该构建未用于安全扫描,也不作为只读容器或完整 S26 验收的证明。
- `make test-backend-targeted`:环境实验室、CI 计划与 Required Gate 的 131 项测试通过;`make test-frontend-targeted`:环境页面 3 项测试通过。
- 受影响 Python 文件的 Ruff 格式与规则、前端文件的 Prettier / ESLint、全部工作流 YAML 解析及六处夹具引用一致性检查通过。
- `pnpm --dir frontend build` 通过;`pip-audit` 无已知漏洞,`pnpm audit --audit-level high` 通过。后者保留测试框架已有的两个 moderate 报告,不在本次改动中升级工具链。

## 合并与验收边界

两处 CI 工作流仅修改镜像引用,不调整检查矩阵、漏洞阈值、忽略规则或正式状态发布器。该改动属于治理文件变更,必须按[受控 Bootstrap 流程](../development-efficiency-phase3.md#验证性能与激活)核对最新 Head 的完整远程检查及 Review Thread,再实施普通合并并恢复原门禁配置。具体远程运行与合并证据记录在对应 PR。

既有签名模板和项目允许列表不自动迁移;部署方仍需明确允许所选镜像。未执行生产部署、生产数据库迁移、Compact 容量 RC、真实外部服务或发布签字。本机普通 Docker 容器启动停留在 Created,已清理本次临时容器;完整的只读安全参数、Seed、重启后清理以 Bootstrap 的真实 Compose / S26 验收为准。原工作区及七个原有健康服务保持不变。
2 changes: 1 addition & 1 deletion frontend/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ COPY . .
RUN pnpm build

FROM nginx:1.31.3-alpine-slim
RUN apk upgrade --no-cache libcrypto3 libssl3
RUN apk add --no-cache --upgrade libcrypto3 libssl3 'pcre2>=10.49-r0'
COPY nginx.conf /etc/nginx/conf.d/default.conf
COPY --from=build /app/dist /usr/share/nginx/html

Expand Down
2 changes: 1 addition & 1 deletion frontend/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@
"@tanstack/react-query": "^5.101.4",
"@xyflow/react": "^12.11.2",
"antd": "^6.5.4",
"axios": "^1.13.5",
"axios": "^1.20.0",
"echarts": "^6.0.0",
"react": "^19.2.8",
"react-dom": "^19.2.8",
Expand Down
18 changes: 9 additions & 9 deletions frontend/pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion frontend/src/pages/EnvironmentLabPage.test.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ import { server } from '../test/server'
import EnvironmentLabPage from './EnvironmentLabPage'

const fixtureImage =
'docker.io/nginxinc/nginx-unprivileged@sha256:123fb7283ffb4788e260d4e980005a978995fefedcdbb04d268077a19b84576d'
'cgr.dev/chainguard/nginx@sha256:a104d1995e56b7a15e8f152078dfbdb1ecbf9f9d1af311e7906e7b4c0c790cf2'

const template: EnvironmentTemplateVersion = {
id: '00000000-0000-4000-8000-000000001001',
Expand Down
2 changes: 1 addition & 1 deletion frontend/src/pages/EnvironmentLabPage.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -549,7 +549,7 @@ function TemplateDialog({
}

const fixtureImage =
'docker.io/nginxinc/nginx-unprivileged@sha256:123fb7283ffb4788e260d4e980005a978995fefedcdbb04d268077a19b84576d'
'cgr.dev/chainguard/nginx@sha256:a104d1995e56b7a15e8f152078dfbdb1ecbf9f9d1af311e7906e7b4c0c790cf2'

function templateFormValues(base?: EnvironmentTemplateVersion): TemplateForm {
return base ? versionFormValues(base) : defaultTemplateFormValues
Expand Down
10 changes: 10 additions & 0 deletions mock-target/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,16 @@ ENV PYTHONDONTWRITEBYTECODE=1 \
PYTHONUNBUFFERED=1 \
PIP_NO_CACHE_DIR=1

# Refresh fixed Debian libraries after the cached Python bootstrap.
RUN set -eux; \
apt-get update; \
apt-get install -y --no-install-recommends --only-upgrade \
libssl3t64 openssl-provider-legacy libpcre2-8-0; \
dpkg --compare-versions "$(dpkg-query -W -f='${Version}' libssl3t64)" ge '3.5.7-1~deb13u3'; \
dpkg --compare-versions "$(dpkg-query -W -f='${Version}' openssl-provider-legacy)" ge '3.5.7-1~deb13u3'; \
dpkg --compare-versions "$(dpkg-query -W -f='${Version}' libpcre2-8-0)" ge '10.46-1~deb13u3'; \
apt-get dist-clean

WORKDIR /app
COPY --from=uv /uv /uvx /bin/
COPY pyproject.toml uv.lock ./
Expand Down
4 changes: 2 additions & 2 deletions scripts/smoke_s26.py
Original file line number Diff line number Diff line change
Expand Up @@ -14,8 +14,8 @@
from smoke_s4 import APIClient, SmokeConfig, _change_password

FIXTURE_IMAGE = (
"docker.io/nginxinc/nginx-unprivileged@sha256:"
"123fb7283ffb4788e260d4e980005a978995fefedcdbb04d268077a19b84576d"
"cgr.dev/chainguard/nginx@sha256:"
"a104d1995e56b7a15e8f152078dfbdb1ecbf9f9d1af311e7906e7b4c0c790cf2"
)


Expand Down
Loading