diff --git a/products/relay-v2/security/advisory-baseline.json b/products/relay-v2/security/advisory-baseline.json index 401023155..61d8dc167 100644 --- a/products/relay-v2/security/advisory-baseline.json +++ b/products/relay-v2/security/advisory-baseline.json @@ -27,7 +27,7 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:595ce1178134b3b30b0f17ae2af5d5340dec1402357815446ca25767486000be", + "sha256:dd3c98586309126e1a7daf7864a2fd4f39706f5d571d830b4ea1590cbb35e964", "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { @@ -52,7 +52,7 @@ "exposed_ports": ["8080/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:e44871ab38a4e76b10c843d6cfef3b4b2f0f01a0f1f9254e13b6bc3f2c7a2443" + "definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8" }, "policies": [ { @@ -75,8 +75,8 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.20.1 Linux AMD64 Relay candidate had no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-10", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Relay candidate had no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-14", "expires_at": "2026-08-28", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -93,14 +93,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:e44871ab38a4e76b10c843d6cfef3b4b2f0f01a0f1f9254e13b6bc3f2c7a2443", + "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0727843669569ad8816d9863d695f9450c0507894d859bfacb1b5b98354c76c2", - "reference_source_revision": "b9f6d12d7d4b62199558351087487550eedb2bdc", + "reference_image_digest": "sha256:0249df2c016c38bd1fd4ab89f69f819471eab84a733a9ed0b996b354ef00d887", + "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:e44871ab38a4e76b10c843d6cfef3b4b2f0f01a0f1f9254e13b6bc3f2c7a2443", + "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -120,10 +120,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:dc7c20db177a67ac474b61bdbb4e4de39f966955bb5b61a408c180fbb762ae6e" + "sha256": "sha256:944481f0421914ac0cde105db0a09676cf84f10dd1ce97c9e781d070f0802ed5" } ], - "definition_digest": "sha256:829d2dad5b71c3e41c15e3bc413741714cab30d72d0ed03431731e0ba5d79f13" + "definition_digest": "sha256:d4749980452f087d8fb78339616c8e86d312f4653dc6d224c8e5668529dc5cb2" } }, { @@ -133,8 +133,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.20.1 Linux AMD64 Relay candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-10", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Relay candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-14", "expires_at": "2026-08-28", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -151,14 +151,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:e44871ab38a4e76b10c843d6cfef3b4b2f0f01a0f1f9254e13b6bc3f2c7a2443", + "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0727843669569ad8816d9863d695f9450c0507894d859bfacb1b5b98354c76c2", - "reference_source_revision": "b9f6d12d7d4b62199558351087487550eedb2bdc", + "reference_image_digest": "sha256:0249df2c016c38bd1fd4ab89f69f819471eab84a733a9ed0b996b354ef00d887", + "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:e44871ab38a4e76b10c843d6cfef3b4b2f0f01a0f1f9254e13b6bc3f2c7a2443", + "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -178,10 +178,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:dc7c20db177a67ac474b61bdbb4e4de39f966955bb5b61a408c180fbb762ae6e" + "sha256": "sha256:944481f0421914ac0cde105db0a09676cf84f10dd1ce97c9e781d070f0802ed5" } ], - "definition_digest": "sha256:829d2dad5b71c3e41c15e3bc413741714cab30d72d0ed03431731e0ba5d79f13" + "definition_digest": "sha256:d4749980452f087d8fb78339616c8e86d312f4653dc6d224c8e5668529dc5cb2" } }, { @@ -191,8 +191,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed upstream or Trixie version. The official v0.20.1 Linux AMD64 Relay candidate had no effective vulnerable DNS-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-10", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Relay candidate had no effective vulnerable DNS-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-14", "expires_at": "2026-08-28", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -209,14 +209,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:e44871ab38a4e76b10c843d6cfef3b4b2f0f01a0f1f9254e13b6bc3f2c7a2443", + "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:0727843669569ad8816d9863d695f9450c0507894d859bfacb1b5b98354c76c2", - "reference_source_revision": "b9f6d12d7d4b62199558351087487550eedb2bdc", + "reference_image_digest": "sha256:0249df2c016c38bd1fd4ab89f69f819471eab84a733a9ed0b996b354ef00d887", + "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", "reference_provenance": "official_candidate", - "runtime_definition_digest": "sha256:e44871ab38a4e76b10c843d6cfef3b4b2f0f01a0f1f9254e13b6bc3f2c7a2443", + "runtime_definition_digest": "sha256:8ab5f29c1a17d6f9caec1c1309dc9a5f6bdabe1872dcfa6099c414828b8126a8", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -236,10 +236,10 @@ }, { "path": "/usr/local/bin/relay", - "sha256": "sha256:dc7c20db177a67ac474b61bdbb4e4de39f966955bb5b61a408c180fbb762ae6e" + "sha256": "sha256:944481f0421914ac0cde105db0a09676cf84f10dd1ce97c9e781d070f0802ed5" } ], - "definition_digest": "sha256:829d2dad5b71c3e41c15e3bc413741714cab30d72d0ed03431731e0ba5d79f13" + "definition_digest": "sha256:d4749980452f087d8fb78339616c8e86d312f4653dc6d224c8e5668529dc5cb2" } } ] diff --git a/release/scripts/test_check_advisory_baselines.py b/release/scripts/test_check_advisory_baselines.py index e782db8d7..516fa6ce8 100644 --- a/release/scripts/test_check_advisory_baselines.py +++ b/release/scripts/test_check_advisory_baselines.py @@ -24,15 +24,15 @@ ROOT / "release/security/mint-advisory-baseline.json", ) LIVE_REFERENCE_IMAGE_DIGESTS = { - "relay": "sha256:0727843669569ad8816d9863d695f9450c0507894d859bfacb1b5b98354c76c2", - "evidence": "sha256:833392109397d3365067ba542475ff5b63a91986a785bf5d4f9ec4fe685c2a9d", - "mint": "sha256:caeebab010a3d3634a52ce977a7f0a2a03f444378695eb49ebf5b89ebdf84bfb", + "relay": "sha256:0249df2c016c38bd1fd4ab89f69f819471eab84a733a9ed0b996b354ef00d887", + "evidence": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3", + "mint": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12", } -LIVE_REFERENCE_SOURCE_REVISION = "b9f6d12d7d4b62199558351087487550eedb2bdc" +LIVE_REFERENCE_SOURCE_REVISION = "0ddd1fa6481ef0154d9f11a13815ba35ab942053" LIVE_REFERENCE_PROVENANCE = { "relay": "official_candidate", - "evidence": "local_reproduction", - "mint": "local_reproduction", + "evidence": "official_candidate", + "mint": "official_candidate", } LIVE_EXECUTABLES = { "relay": "/usr/local/bin/relay", @@ -1368,7 +1368,7 @@ def test_all_live_baselines_use_evaluable_whole_image_fingerprints(self): list(normalized.findings), normalized.image, synthetic_baseline, - self.module.parse_date("2026-08-13", "today"), + self.module.parse_date("2026-08-14", "today"), self.rootfs, live_assertion["reference_image_digest"], copy.deepcopy(baseline["runtime"]["config"]), diff --git a/release/security/evidence-advisory-baseline.json b/release/security/evidence-advisory-baseline.json index 0be25e6ee..8727e696b 100644 --- a/release/security/evidence-advisory-baseline.json +++ b/release/security/evidence-advisory-baseline.json @@ -27,7 +27,8 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:1a3a76602977106ea792f0a5848f318428f2f90682182c665b0be65cca36d45d" + "sha256:9c9226dd6fa9be3fb68e2702d21430ee4a7a5bd9121df7cfbfaaa1b221fa8b34", + "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { "user": "65532", @@ -44,7 +45,7 @@ "exposed_ports": ["8080/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:fdca4898fdc24ac1184a7affa233fee80870b696cead8e257641eb20d6724814" + "definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7" }, "policies": [ { @@ -67,8 +68,8 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. A local v0.20.1 Linux AMD64 Evidence reproduction from the recorded source revision provided the reviewed rootfs bytes; no official retained Evidence candidate report is claimed. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-12", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Evidence candidate had only fixed-format %lu and %lx sscanf call sites and no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-14", "expires_at": "2026-08-28", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -85,14 +86,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:fdca4898fdc24ac1184a7affa233fee80870b696cead8e257641eb20d6724814", + "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:833392109397d3365067ba542475ff5b63a91986a785bf5d4f9ec4fe685c2a9d", - "reference_source_revision": "b9f6d12d7d4b62199558351087487550eedb2bdc", - "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:fdca4898fdc24ac1184a7affa233fee80870b696cead8e257641eb20d6724814", + "reference_image_digest": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3", + "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -112,10 +113,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:114e249d2f76cd6534a619c339ace46a1f56824f807b65434b593a8d43799a8f" + "sha256": "sha256:f10c16ad811f63289c2eb36582db7bcb79308ff9012c86addbfbef11bbf70439" } ], - "definition_digest": "sha256:6fbd70ac0ae9fa877692770419d13821fc6a7dde41d60e7a0862d9b54e4d272e" + "definition_digest": "sha256:2dcf75b57667b0bd40d53920c27f2a4a4be9cd236497fd2b2e174cd86b2e77e9" } }, { @@ -125,8 +126,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. A local v0.20.1 Linux AMD64 Evidence reproduction from the recorded source revision provided the reviewed rootfs bytes; no official retained Evidence candidate report is claimed. Libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-12", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Evidence candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-14", "expires_at": "2026-08-28", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -143,14 +144,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:fdca4898fdc24ac1184a7affa233fee80870b696cead8e257641eb20d6724814", + "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:833392109397d3365067ba542475ff5b63a91986a785bf5d4f9ec4fe685c2a9d", - "reference_source_revision": "b9f6d12d7d4b62199558351087487550eedb2bdc", - "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:fdca4898fdc24ac1184a7affa233fee80870b696cead8e257641eb20d6724814", + "reference_image_digest": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3", + "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -170,10 +171,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:114e249d2f76cd6534a619c339ace46a1f56824f807b65434b593a8d43799a8f" + "sha256": "sha256:f10c16ad811f63289c2eb36582db7bcb79308ff9012c86addbfbef11bbf70439" } ], - "definition_digest": "sha256:6fbd70ac0ae9fa877692770419d13821fc6a7dde41d60e7a0862d9b54e4d272e" + "definition_digest": "sha256:2dcf75b57667b0bd40d53920c27f2a4a4be9cd236497fd2b2e174cd86b2e77e9" } }, { @@ -183,8 +184,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. A local v0.20.1 Linux AMD64 Evidence reproduction from the recorded source revision provided the reviewed rootfs bytes; no official retained Evidence candidate report is claimed. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-12", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.22.0 Linux AMD64 Evidence candidate had no effective deprecated resolver-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-14", "expires_at": "2026-08-28", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -201,14 +202,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:fdca4898fdc24ac1184a7affa233fee80870b696cead8e257641eb20d6724814", + "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:833392109397d3365067ba542475ff5b63a91986a785bf5d4f9ec4fe685c2a9d", - "reference_source_revision": "b9f6d12d7d4b62199558351087487550eedb2bdc", - "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:fdca4898fdc24ac1184a7affa233fee80870b696cead8e257641eb20d6724814", + "reference_image_digest": "sha256:3ad995a2324d777a0c41c6d65635977514b132653916581b3e3e40f98225add3", + "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:d863d2bb36260e2a6e132b9e4c34c6e9bb6f72fa4baf4b77db9de14634fd86b7", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -228,10 +229,10 @@ }, { "path": "/usr/local/bin/evidence", - "sha256": "sha256:114e249d2f76cd6534a619c339ace46a1f56824f807b65434b593a8d43799a8f" + "sha256": "sha256:f10c16ad811f63289c2eb36582db7bcb79308ff9012c86addbfbef11bbf70439" } ], - "definition_digest": "sha256:6fbd70ac0ae9fa877692770419d13821fc6a7dde41d60e7a0862d9b54e4d272e" + "definition_digest": "sha256:2dcf75b57667b0bd40d53920c27f2a4a4be9cd236497fd2b2e174cd86b2e77e9" } } ] diff --git a/release/security/mint-advisory-baseline.json b/release/security/mint-advisory-baseline.json index f4bcb9667..48f7271b5 100644 --- a/release/security/mint-advisory-baseline.json +++ b/release/security/mint-advisory-baseline.json @@ -27,7 +27,8 @@ "sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614" ], "application_layer_ids": [ - "sha256:7380d81ffc5333b7e8f2c2b940f16e116c828a335c99d24ea934ed4649399baf" + "sha256:be33545edd3caceb5201ba9bcc736856d8fb4ee87442920e8bc6383db8df7384", + "sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef" ], "config": { "user": "65532", @@ -44,7 +45,7 @@ "exposed_ports": ["8081/tcp"], "stop_signal": "" }, - "definition_digest": "sha256:577dacdc96b807ba36e49dcee6fe3772b2840f8068a6d1531b2ff030a0555d09" + "definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2" }, "policies": [ { @@ -67,8 +68,8 @@ "severity": "Critical", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. A local v0.20.1 Linux AMD64 Mint reproduction from the recorded source revision provided the reviewed rootfs bytes; no official retained Mint candidate report is claimed. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-12", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Mint candidate had only fixed-format %lu and %lx sscanf call sites and no effective vulnerable allocating-character scanf path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-14", "expires_at": "2026-08-28", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -85,14 +86,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:577dacdc96b807ba36e49dcee6fe3772b2840f8068a6d1531b2ff030a0555d09", + "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:caeebab010a3d3634a52ce977a7f0a2a03f444378695eb49ebf5b89ebdf84bfb", - "reference_source_revision": "b9f6d12d7d4b62199558351087487550eedb2bdc", - "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:577dacdc96b807ba36e49dcee6fe3772b2840f8068a6d1531b2ff030a0555d09", + "reference_image_digest": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12", + "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -112,10 +113,10 @@ }, { "path": "/usr/local/bin/mint", - "sha256": "sha256:91908695241b8960532f1785f72fc3304b5b99776429f65c88c411da631581cc" + "sha256": "sha256:620321d21759a69e7a09cc133c60d0f1fad2804593c79d12332590de7aa05a89" } ], - "definition_digest": "sha256:64718e69d9693728a28b255fe8c9c33a79dc1041f0066af0f143fd36fd913ca4" + "definition_digest": "sha256:39945c382e5d58182d36aba32fca48d0dc42eef58373d8ead4eab246e14ecc6d" } }, { @@ -125,8 +126,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. A local v0.20.1 Linux AMD64 Mint reproduction from the recorded source revision provided the reviewed rootfs bytes; no official retained Mint candidate report is claimed. Libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-12", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The official v0.22.0 Linux AMD64 Mint candidate had no effective wide-character input path in the reviewed bytes; libc exporting ungetwc is expected. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-14", "expires_at": "2026-08-28", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -143,14 +144,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:577dacdc96b807ba36e49dcee6fe3772b2840f8068a6d1531b2ff030a0555d09", + "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:caeebab010a3d3634a52ce977a7f0a2a03f444378695eb49ebf5b89ebdf84bfb", - "reference_source_revision": "b9f6d12d7d4b62199558351087487550eedb2bdc", - "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:577dacdc96b807ba36e49dcee6fe3772b2840f8068a6d1531b2ff030a0555d09", + "reference_image_digest": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12", + "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -170,10 +171,10 @@ }, { "path": "/usr/local/bin/mint", - "sha256": "sha256:91908695241b8960532f1785f72fc3304b5b99776429f65c88c411da631581cc" + "sha256": "sha256:620321d21759a69e7a09cc133c60d0f1fad2804593c79d12332590de7aa05a89" } ], - "definition_digest": "sha256:64718e69d9693728a28b255fe8c9c33a79dc1041f0066af0f143fd36fd913ca4" + "definition_digest": "sha256:39945c382e5d58182d36aba32fca48d0dc42eef58373d8ead4eab246e14ecc6d" } }, { @@ -183,8 +184,8 @@ "severity": "High", "status": "accepted_risk", "owner": "@jeremi", - "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. A local v0.20.1 Linux AMD64 Mint reproduction from the recorded source revision provided the reviewed rootfs bytes; no official retained Mint candidate report is claimed. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", - "reviewed_at": "2026-08-12", + "rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no fixed Trixie version. The official v0.22.0 Linux AMD64 Mint candidate had no effective deprecated resolver-printing path in the reviewed bytes. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound executable closure digests.", + "reviewed_at": "2026-08-14", "expires_at": "2026-08-28", "invalidation_triggers": [ "candidate_image_identity_mismatch", @@ -201,14 +202,14 @@ "runtime_config_changed", "runtime_base_changed" ], - "runtime_definition_digest": "sha256:577dacdc96b807ba36e49dcee6fe3772b2840f8068a6d1531b2ff030a0555d09", + "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", "component_layer_id": "sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e", "exposure_assertion": { "kind": "whole_image_fingerprint_equals", - "reference_image_digest": "sha256:caeebab010a3d3634a52ce977a7f0a2a03f444378695eb49ebf5b89ebdf84bfb", - "reference_source_revision": "b9f6d12d7d4b62199558351087487550eedb2bdc", - "reference_provenance": "local_reproduction", - "runtime_definition_digest": "sha256:577dacdc96b807ba36e49dcee6fe3772b2840f8068a6d1531b2ff030a0555d09", + "reference_image_digest": "sha256:cc8f139d7755151dd6876f054d52c684214b128e3ab7978e90180c0b9ea4fb12", + "reference_source_revision": "0ddd1fa6481ef0154d9f11a13815ba35ab942053", + "reference_provenance": "official_candidate", + "runtime_definition_digest": "sha256:0f104ef8a0bcc31ecb930ec8fa64c31b3a710361112651ec40183d24ce52dcf2", "files": [ { "path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", @@ -228,10 +229,10 @@ }, { "path": "/usr/local/bin/mint", - "sha256": "sha256:91908695241b8960532f1785f72fc3304b5b99776429f65c88c411da631581cc" + "sha256": "sha256:620321d21759a69e7a09cc133c60d0f1fad2804593c79d12332590de7aa05a89" } ], - "definition_digest": "sha256:64718e69d9693728a28b255fe8c9c33a79dc1041f0066af0f143fd36fd913ca4" + "definition_digest": "sha256:39945c382e5d58182d36aba32fca48d0dc42eef58373d8ead4eab246e14ecc6d" } } ]