Skip to content

chore(trivy): ignore CVE-2026-102633 until Alpine 3.24 ships libexpat 2.9.0 - #562

Merged
Neophytis merged 1 commit into
feature/docker-masterfrom
neophytis/trivy-ignore-libexpat-cve
Oct 8, 2026
Merged

Neophytis merged 1 commit into
feature/docker-masterfrom
neophytis/trivy-ignore-libexpat-cve

Conversation

@Neophytis

Copy link
Copy Markdown
Contributor

Target branch: feature/docker-master.

Why

Since 2026-10-08, every image build fails Scan image on CVE-2026-102633 (libexpat, MEDIUM, DoS). This blocks the stage auto-deploy and the prod Create GitHub release job, which both depend on the scan.

  • The fix, libexpat 2.9.0-r0, exists only in Alpine edge (edge secdb lists it).
  • Alpine 3.24 (our base, php:8.3.33-fpm-alpine3.24) still ships 2.8.5-r0. The 3.24-stable APKBUILD is unchanged, and the 3.24 secdb has no entry.
  • The daily apk upgrade (APK_REFRESH, fix(docker): refresh apk packages daily despite the layer cache; drop unused python3 #538) ran today but has nothing newer to install.
  • Trivy reports the CVE as fixed, so ignore-unfixed doesn't skip it.

This is the case .trivyignore is for ("no fixed package available yet"), the same as the nghttp2 entry that #539 removed.

Exposure

Minimal. Only git depends on libexpat in the image (apk info -r libexpat → git). PHP's XML extensions use libxml2 2.13.9, and git only uses expat for WebDAV pushes, which nothing in the container does.

Test

A stage image build on this branch (sha-f9f7784, before the comment-only amend) passed every job, including Scan image.

Removal

Remove the line once Alpine 3.24 ships libexpat >= 2.9.0-r0. The daily refresh then picks it up automatically.

Unblocks #561 and the next prod release.

… 2.9.0

The fix (libexpat 2.9.0-r0) exists only in Alpine edge; 3.24-stable still
ships 2.8.5-r0, so the daily apk refresh cannot pick it up and every image
scan fails, which blocks the stage auto-deploy and the prod release job.
Only git depends on libexpat in the image (PHP XML uses libxml2).
@Neophytis
Neophytis merged commit 1298cf7 into feature/docker-master Oct 8, 2026
3 of 11 checks passed
@Neophytis
Neophytis deleted the neophytis/trivy-ignore-libexpat-cve branch October 8, 2026 21:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant