Repository navigation
chore(security): add OpenVEX for gosu findings in the Laminar Postgres image - #1376
Draft
aivong-openhands wants to merge 1 commit into
Draft
aivong-openhands wants to merge 1 commit into
aivong-openhands wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The Laminar subchart's database image,
postgres:15, has 1 critical and 21 high Trivy findings with fixes available, and all 22 are Go standard-library CVEs in thegosubinary (v1.19.0, built with Go 1.24.6). They are flagged by toolchain version, not by use:govulncheck -mode=binaryon the binary shows 21 are in packages not compiled intogosuand the remaining one (CVE-2026-39822,os) is never called. They cannot be fixed from our side, sincegosuupstream only rebuilds for reachable vulnerabilities and docker-library/postgres#1350 (replacegosuwithsetpriv) is unmerged.This adds
security/vex/laminar-postgres-gosu.openvex.json, an OpenVEX document marking those 22 IDsnot_affectedwith the per-CVE justification, plus a README with the evidence, scope and regeneration steps. Scanners that read VEX can then suppress them with a recorded reason instead of ad-hoc ignores.Validation
trivy image --vex ... postgres:15goes from 2 critical / 82 high (1 / 21 fixable) to 1 / 61 (0 / 0 fixable). The 22 suppressed IDs are exactly thegosufindings, and the remaining no-fix findings are unchanged.postgres:15-alpine, which ships the samegosu, is suppressed the same way; an unrelated Go image (ghcr.io/squat/generic-device-plugin:2cc50b0) keeps all 25 of its findings.gosuhas the same sha256 as the one in the currentpostgres:15(postgres@sha256:c961aa28…).This PR was drafted by an AI agent on behalf of the user.