diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8d69da8..4c9d0a7 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -4,7 +4,7 @@ on: workflow_dispatch: inputs: release_tag: - description: Numeric semantic release tag, for example v0.20.11 + description: Numeric semantic release tag, for example v0.20.12 required: true type: string @@ -72,6 +72,7 @@ jobs: run_build() { local command=$1 + test -z "$(git -C source status --porcelain)" docker run --rm \ --volume "${source_path}:/go/src/github.com/PastureStack/catalog-service" \ --env "DAPPER_UID=$(id -u)" \ @@ -97,6 +98,14 @@ jobs: test -x artifact-check/catalog-service test -x artifact-check/catalog-service-sqlite test "$(find artifact-check -maxdepth 1 -type f | wc -l)" -eq 2 + for binary in catalog-service catalog-service-sqlite; do + test "$(artifact-check/"$binary" --version)" = "$RELEASE_TAG" + docker run --rm --entrypoint sh \ + --volume "$PWD/artifact-check:/artifacts:ro" "$image" -lc \ + "go version -m /artifacts/$binary" >"artifact-check/$binary.buildinfo" + grep -Fx $'\tbuild\tvcs.revision='"$SOURCE_SHA" "artifact-check/$binary.buildinfo" >/dev/null + grep -Fx $'\tbuild\tvcs.modified=false' "artifact-check/$binary.buildinfo" >/dev/null + done sha256sum "$artifact" | sed "s# source/dist/artifacts/# #" \ >"${artifact}.sha256" @@ -117,11 +126,12 @@ jobs: { printf '# PastureStack Catalog Service %s\n\n' "$RELEASE_TAG" - printf 'This release enforces operator-authorized catalog origins, rooted cache access, bounded Helm inputs, and plain-text readme delivery.\n\n' + printf 'This release excludes Git metadata from template traversal, validates version directories before allocating templates, omits metadata-only entries without a template definition, preserves template/version READMEs and icons, and rebuilds same-commit empty or unnamed indexes transactionally. Existing catalog origin, rooted-cache and bounded-input protections are retained.\n\n' printf '## Immutable coordinates\n\n' printf -- '- Source commit: `%s`\n' "$SOURCE_SHA" printf -- '- Artifact SHA-256: `%s`\n\n' "$artifact_sha" printf 'The full test suite passed, and two clean builds produced byte-identical archives.\n\n' + printf 'Python test dependencies are hash-locked; bootstrap installers are removed from the completed build image. Build-header VEX exceptions remain explicitly recorded and do not claim an absence of all CVEs. Server packaging and real catalog migration/UI acceptance are separate and not claimed by this component release.\n\n' printf 'PastureStack is an independent community effort to preserve, audit, and modernize the Rancher 1.6 ecosystem. It is not affiliated with or endorsed by Rancher Labs or SUSE.\n' } >release-notes.md diff --git a/.github/workflows/security-release-gate.yml b/.github/workflows/security-release-gate.yml index d8f5b1d..2613f05 100644 --- a/.github/workflows/security-release-gate.yml +++ b/.github/workflows/security-release-gate.yml @@ -20,7 +20,7 @@ jobs: env: DAPPER_IMAGE: pasturestack/catalog-service-dapper:${{ github.sha }} TRIVY_IMAGE: aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969 - VERSION_OVERRIDE: v0.20.11 + VERSION_OVERRIDE: v0.20.12 steps: - name: Check out candidate @@ -60,6 +60,9 @@ jobs: source_path="$GITHUB_WORKSPACE" source_epoch="$(git show -s --format=%ct HEAD)" run_ci() { + # Generated review artifacts are ignored; any actual source drift + # must fail before Go captures vcs.modified in the binaries. + test -z "$(git status --porcelain)" docker run --rm \ --volume "${source_path}:/go/src/github.com/PastureStack/catalog-service" \ --env "DAPPER_UID=$(id -u)" \ @@ -71,7 +74,7 @@ jobs: } run_ci - artifact="dist/artifacts/catalog-service-0.20.11.tar.xz" + artifact="dist/artifacts/catalog-service-0.20.12.tar.xz" test -s "$artifact" cp "$artifact" /tmp/catalog-service-first.tar.xz @@ -85,8 +88,8 @@ jobs: test "$(find evidence/product -maxdepth 1 -type f | wc -l)" -eq 2 test -x evidence/product/catalog-service test -x evidence/product/catalog-service-sqlite - test "$(evidence/product/catalog-service --version)" = 'v0.20.11' - test "$(evidence/product/catalog-service-sqlite --version)" = 'v0.20.11' + test "$(evidence/product/catalog-service --version)" = 'v0.20.12' + test "$(evidence/product/catalog-service-sqlite --version)" = 'v0.20.12' sha256sum "$artifact" > evidence/catalog-service.tar.xz.sha256 docker run --rm --entrypoint sh \ --volume "$PWD:/work:ro" \ @@ -105,6 +108,10 @@ jobs: > evidence/product-linkage.txt grep -F $'build\tCGO_ENABLED=0' evidence/catalog-service-go-version.txt >/dev/null grep -F $'build\tCGO_ENABLED=1' evidence/catalog-service-sqlite-go-version.txt >/dev/null + for metadata in evidence/catalog-service-go-version.txt evidence/catalog-service-sqlite-go-version.txt; do + grep -Fx $'\tbuild\tvcs.revision='"$GITHUB_SHA" "$metadata" >/dev/null + grep -Fx $'\tbuild\tvcs.modified=false' "$metadata" >/dev/null + done grep -Eq 'catalog-service:[[:space:]]+ELF' evidence/product-linkage.txt grep -F 'statically linked' evidence/product-linkage.txt >/dev/null grep -Eq 'catalog-service-sqlite:[[:space:]]+ELF' evidence/product-linkage.txt @@ -118,7 +125,7 @@ jobs: "printf 'package\tversion\n'; dpkg-query -W -f='\${binary:Package}\t\${Version}\n' | LC_ALL=C sort" \ > evidence/dapper-dpkg.tsv docker run --rm --entrypoint sh "$DAPPER_IMAGE" -lc \ - '/opt/tox/bin/pip freeze --all | LC_ALL=C sort' \ + '/opt/tox/bin/python -I -c '\''import importlib.metadata as m; print("\n".join(sorted(d.metadata["Name"] + "==" + d.version for d in m.distributions())))'\''' \ > evidence/dapper-python.txt docker run --rm \ -v "$PWD/scripts/verify-dapper-vex:/verify-dapper-vex:ro" \ diff --git a/.gitignore b/.gitignore index 95d3a63..4a1ee59 100644 --- a/.gitignore +++ b/.gitignore @@ -1,6 +1,7 @@ /.dapper /bin /dist +/evidence *.swp /.trash-cache /cache diff --git a/COMPATIBILITY.md b/COMPATIBILITY.md index d55ecd5..743ba45 100644 --- a/COMPATIBILITY.md +++ b/COMPATIBILITY.md @@ -15,3 +15,11 @@ The `0.20.9` candidate replaces MD5 cache directory names with SHA-256 names. Th The `0.20.11` candidate preserves those database table names and JSON resource shapes while moving to GORM v2 and a bounded project-owned catalog API compatibility layer. The retired Rancher client HTML renderer is intentionally not preserved; Catalog API responses are JSON. Its MySQL DSN construction preserves the current driver's compatibility defaults required by existing installations. Release validation covers `platformVersion` precedence and legacy fallback, both legacy metadata layouts, catalog refresh, database migration, empty default configuration, icon and readme routes, version ordering, upgrade links, malformed repositories, empty-index recovery, outbound-origin and path boundaries, Helm archive limits, SQLite and non-SQLite binaries, and rollback. + +The `0.20.12` source adds Git-metadata exclusion and rejects invalid version +folders before reading or allocating a template. A same-commit index containing +an empty or NULL template folder is rebuilt by the existing catalog transaction; +the check is confined to the selected catalog name and environment. The database +surrogate IDs may change on reindexing, as on an ordinary catalog refresh, while +public catalog/template identifiers and the reviewed source commit remain +unchanged. No operator SQL cleanup or catalog recreation is required. diff --git a/Dockerfile.dapper b/Dockerfile.dapper index a486493..62c184f 100644 --- a/Dockerfile.dapper +++ b/Dockerfile.dapper @@ -43,15 +43,13 @@ RUN set -eux; \ gcc="${UBUNTU_APT_GCC_VERSION}" \ git="${UBUNTU_APT_GIT_VERSION}" \ libc6-dev="${UBUNTU_APT_LIBC6_DEV_VERSION}" \ + libssl3t64="${UBUNTU_APT_OPENSSL_VERSION}" \ + openssl="${UBUNTU_APT_OPENSSL_VERSION}" \ + openssl-provider-legacy="${UBUNTU_APT_OPENSSL_VERSION}" \ python3="${UBUNTU_APT_PYTHON3_VERSION}" \ python3-pip="${UBUNTU_APT_PYTHON3_PIP_VERSION}" \ - python3-venv="${UBUNTU_APT_PYTHON3_VENV_VERSION}" \ tar="${UBUNTU_APT_TAR_VERSION}" \ xz-utils="${UBUNTU_APT_XZ_UTILS_VERSION}"; \ - { \ - printf 'snapshot\t%s\n' "${UBUNTU_APT_SNAPSHOT}"; \ - dpkg-query -W -f='${binary:Package}\t${Version}\n' | LC_ALL=C sort; \ - } > /licenses/CATALOG-SERVICE-UBUNTU-APT-PACKAGES.tsv; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* /usr/bin/pebble; \ rm -f /bin/sh; \ @@ -69,8 +67,8 @@ RUN case "${DAPPER_HOST_ARCH}" in \ echo "${go_sha} /tmp/go.tgz" | sha256sum -c - && \ tar -C /usr/local -xzf /tmp/go.tgz && \ rm -f /tmp/go.tgz && \ - python3 -m venv /opt/tox && \ - /opt/tox/bin/pip install --no-cache-dir --require-hashes \ + /usr/bin/python3 -m venv --without-pip /opt/tox && \ + /usr/bin/python3 -m pip --python /opt/tox install --no-cache-dir --require-hashes \ --requirement /tmp/catalog-service-build-requirements.lock && \ mkdir -p /go/bin /go/src && \ go version && \ @@ -79,10 +77,31 @@ RUN case "${DAPPER_HOST_ARCH}" in \ COPY integration/requirements.lock /tmp/catalog-service-test-requirements.lock RUN mkdir -p /opt/catalog-service-wheelhouse && \ - /opt/tox/bin/pip download --require-hashes --no-deps --only-binary=:all: \ + /opt/tox/bin/pip download --no-cache-dir --require-hashes --no-deps --only-binary=:all: \ --platform any --python-version 3.14 --implementation py --abi none \ --dest /opt/catalog-service-wheelhouse \ --requirement /tmp/catalog-service-test-requirements.lock && \ + /opt/tox/bin/pip install --no-cache-dir --require-hashes --no-deps \ + --no-index --find-links=/opt/catalog-service-wheelhouse \ + --requirement /tmp/catalog-service-test-requirements.lock && \ + cp /tmp/catalog-service-test-requirements.lock \ + /licenses/CATALOG-SERVICE-TEST-REQUIREMENTS.lock && \ + /opt/tox/bin/pip uninstall -y cachetools distlib filelock platformdirs \ + pyproject-api python-discovery setuptools tomli-w tox virtualenv wheel && \ + /opt/tox/bin/pip uninstall -y pip && \ + for package in python3-pip python3-pip-whl; do \ + if dpkg-query -W -f='${db:Status-Status}\n' "${package}" 2>/dev/null \ + | grep -qx installed; then \ + apt-get purge -y "${package}" || exit 1; \ + fi; \ + done && \ + . /licenses/ubuntu-apt.lock && \ + { \ + printf 'snapshot\t%s\n' "${UBUNTU_APT_SNAPSHOT}"; \ + dpkg-query -W -f='${binary:Package}\t${Version}\n' | LC_ALL=C sort; \ + } > /licenses/CATALOG-SERVICE-UBUNTU-APT-PACKAGES.tsv && \ + /opt/tox/bin/python -I -m flake8 --version && \ + /opt/tox/bin/python -I -m pytest --version && \ rm -f /tmp/catalog-service-build-requirements.lock \ /tmp/catalog-service-test-requirements.lock diff --git a/README.md b/README.md index 6ca907b..48ad3c8 100644 --- a/README.md +++ b/README.md @@ -8,14 +8,42 @@ PastureStack is an independent community effort to preserve, audit, and moderniz ## Project status -The current numeric maintenance release is `0.20.11`, consumed by PastureStack -Server `v1.6.410`. It retains the Ubuntu 26.04, Go 1.27.0, database, dependency, version-filter, TLS, and build maintenance completed after the preserved upstream boundary. Product-owned imports, binaries, default configuration, version query, and operator messages use PastureStack naming. The default `repo.json` is intentionally empty; no unreviewed catalog is cloned. Python build and integration-test dependencies are transitively pinned with package hashes and installed from an offline wheelhouse inside the disposable build image. The historical `--track` flag is accepted only for command-line compatibility; the service does not read or transmit an installation identifier. MySQL DSNs are created from the driver's reviewed defaults so existing `mysql_native_password` installations remain compatible after the driver upgrade. +This source prepares numeric maintenance release `0.20.12`; the latest published +release is still `0.20.11`, included in PastureStack Server through `v1.6.513`. +The next server integration target is `v1.6.514`; publication and 8080 acceptance +are not yet complete. The indexing fix skips Git's `.git` metadata, validates a +numeric revision or semantic-version folder before reading a version file or +allocating a template, and rebuilds a same-commit index containing unnamed +templates through the existing catalog transaction. Other catalogs are not +included in that cache check. Native revision numbers, semantic versions, +template metadata, labels and public API identifiers remain compatible. +README, icon and version files alone do not emit templates: a successfully +parsed `config.yml` or `template.yml` must establish the folder identity. +Root README files are resolved from their containing directory rather than +mistaken for version folders. This repairs previously empty root README fields +from repository bytes; version README files, icons and valid numeric or semantic +versions retain their existing contents and interpretation. + +It retains the Ubuntu 26.04, Go 1.27.0, database, dependency, version-filter, TLS, and build maintenance completed after the preserved upstream boundary. Product-owned imports, binaries, default configuration, version query, and operator messages use PastureStack naming. The default `repo.json` is intentionally empty; no unreviewed catalog is cloned. Python build and integration-test dependencies are transitively pinned with package hashes and installed from an offline wheelhouse inside the disposable build image. The historical `--track` flag is accepted only for command-line compatibility; the service does not read or transmit an installation identifier. MySQL DSNs are created from the driver's reviewed defaults so existing `mysql_native_password` installations remain compatible after the driver upgrade. The archived `docker/libcompose` parser and the unmaintained `go-rancher` client are no longer imported or vendored. A small project-owned compatibility layer now emits only the resource, schema, link, and JSON shapes this service actually uses. Catalog metadata is decoded through YAML v3 with focused compatibility tests for top-level legacy metadata, Compose v2 service metadata, alias fields, precedence, malformed input, and empty metadata. A source gate prevents the removed parser from returning. Database access uses GORM v2 with current MySQL and SQLite drivers. Dependencies are resolved by Go Modules, locked by `go.mod` and `go.sum`, and rebuilt into `vendor/` so release builds remain offline and reproducible. -The disposable build image is pinned by digest. Its Ubuntu package source is fixed to the `20260808T000000Z` official snapshot, and every directly installed APT package has an exact version in `ubuntu-apt.lock`. The candidate security workflow builds and packages twice, runs the complete test, race, validation, and packaging path, scans source, product binaries, and the exported build-image filesystem, and uploads review evidence without publishing or deploying anything. Both the image-metadata and exported-filesystem raw reports are retained. Findings originating from an embedded third-party SBOM require exact OpenVEX set equality plus executable checks that the affected implementation and call path are absent; installed package databases remain independent evidence and product binaries are gated separately. +The disposable build image is pinned by digest. Its Ubuntu package source is fixed to the `20261002T000000Z` official snapshot, and every directly installed APT package has an exact version in `ubuntu-apt.lock`. The candidate security workflow builds and packages twice, runs the complete test, race, validation, and packaging path, scans source, product binaries, and the exported build-image filesystem, and uploads review evidence without publishing or deploying anything. Both the image-metadata and exported-filesystem raw reports are retained. Findings originating from an embedded third-party SBOM require exact OpenVEX set equality plus executable checks that the affected implementation and call path are absent; installed package databases remain independent evidence and product binaries are gated separately. + +The same hash-locked integration dependencies are preinstalled in the isolated +`/opt/tox` environment, which runs flake8 and pytest directly without seeding +another environment. Bootstrap invokes Ubuntu's `/usr/bin/python3` explicitly +so the seedless environment placed first on PATH cannot shadow the installer. +The official pip installer, tox and virtualenv are retired +with their supported uninstall commands after preparation; the system pip +packages are explicitly purged without autoremove. The developer `tox.ini` is +retained. Bootstrap dependency locks remain provenance, not a claim that the +bootstrap phase has no vulnerabilities: pip's embedded urllib3 is not fixed by +installing an unrelated top-level urllib3. The final image must prove that the +retired installer code and packages are absent and that the exact test +dependencies remain installed; no urllib3 OpenVEX exception is permitted. Catalog sources are denied unless their exact origin is authorized by the service operator. Reviewed public GitHub origins are built in. Add private HTTPS origins as a comma-separated list in `PASTURESTACK_CATALOG_ALLOWED_EXTERNAL_ORIGINS`; each entry must contain only a scheme, hostname, and optional port. Plain HTTP is accepted only for loopback tests. Local Git catalogs are restricted to isolated tests: `PASTURESTACK_CATALOG_ALLOWED_LOCAL_ROOTS` may enable only the platform temporary root. Catalog documents, API callers, redirects, icon links, and chart links cannot expand either policy. diff --git a/integration/build-requirements.lock b/integration/build-requirements.lock index 074d19b..598632e 100644 --- a/integration/build-requirements.lock +++ b/integration/build-requirements.lock @@ -7,11 +7,11 @@ pip==26.2.1 --hash=sha256:71138adf1f4ca900cdb7d289c21b7494329f2332b6d85f0e1c4210 platformdirs==4.11.2 --hash=sha256:7f89089b6ea71bda7962953edcf784b2e2d9d285b40ad88be2bb75c6e9d82ab4 pluggy==1.6.0 --hash=sha256:e920276dd6813095e9377c0bc5566d94c932c33b27a3e3945d8389c374dd4746 pyproject-api==1.11.0 --hash=sha256:860060c8832dce983b5eec6f41c4c43eb3ec06ff7332387a63acdf5ca27b68d8 -python-discovery==1.5.2 --hash=sha256:3e338c2d0f15dfaeea57493f4c2c6caebe0e998ea815c30ae8bf8ee21f1112d3 +python-discovery==1.6.0 --hash=sha256:d4e244cf17b8b29819ed78003d55fbacf86eda23425b075454fff9271b79377a setuptools==84.0.0 --hash=sha256:51a52592b3b99e102b609654876bd65f19f999935166d1352678931132b0c670 tomli==2.4.1 --hash=sha256:0d85819802132122da43cb86656f8d1f8c6587d54ae7dcaf30e90533028b49fe tomli-w==1.2.0 --hash=sha256:188306098d013b691fcadc011abd66727d3c414c571bb01b1a174ba8c983cf90 tox==4.59.0 --hash=sha256:fa9a1c968503302544498a98e785e7f46e85d22e9d5bf9bcce1731c8f3ffae01 typing-extensions==4.16.0 --hash=sha256:481caa481374e813c1b176ada14e97f1f67a4539ce9cfeb3f350d78d6370c2e8 -virtualenv==21.7.4 --hash=sha256:376ec93cd6aab3044fa395d7db226db38043b7b5748948044b2a87168525e843 +virtualenv==21.7.13 --hash=sha256:1bea5af7463f59c4719db48fe739579a2a4f569c96f26c086edda85c96da9f59 wheel==0.48.0 --hash=sha256:3217dcc807155e45db462d7ef2431f5ddda0d7273b700d05a67b271ceb1287ab diff --git a/integration/requirements.lock b/integration/requirements.lock index 3139277..e3dab7d 100644 --- a/integration/requirements.lock +++ b/integration/requirements.lock @@ -15,5 +15,5 @@ pytest==9.1.1 --hash=sha256:37a86b45efb9a47a61a36449063e8e18d0cab3161329fc099eb2 requests==2.34.2 --hash=sha256:2a0d60c172f83ac6ab31e4554906c0f3b3588d37b5cb939b1c061f4907e278e0 tomli==2.4.1 --hash=sha256:0d85819802132122da43cb86656f8d1f8c6587d54ae7dcaf30e90533028b49fe typing-extensions==4.16.0 --hash=sha256:481caa481374e813c1b176ada14e97f1f67a4539ce9cfeb3f350d78d6370c2e8 -urllib3==2.7.0 --hash=sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897 +urllib3==2.8.0 --hash=sha256:0cf3cae568d36aa9576b28dfb35f11328f1cb974ca7647d9475ebb86c75ac6e3 wait-for==2.0 --hash=sha256:b1799a8ef2060c676453497823682b80911e54aeefeb634dd1f2085348e42985 diff --git a/manager/manager.go b/manager/manager.go index 8d1e754..dbb5071 100644 --- a/manager/manager.go +++ b/manager/manager.go @@ -134,7 +134,7 @@ func (m *Manager) refreshCatalog(catalog model.Catalog, update bool) error { log.Debug("Catalog is already up to date") return nil } - log.Warn("Catalog has no indexed templates; rebuilding") + log.Warn("Catalog index is empty or contains unnamed templates; rebuilding") } templates, errs, err := traverseFiles(repoRoot, catalog.Kind, catalogType, m.httpClient, catalog.URL) @@ -154,10 +154,14 @@ func (m *Manager) refreshCatalog(catalog model.Catalog, update bool) error { } func (m *Manager) catalogHasTemplates(catalog model.Catalog) (bool, error) { - var count int64 + var counts struct { + Total int64 + Blank int64 + } err := m.db.Table("catalog_template"). + Select("COUNT(*) AS total, COALESCE(SUM(CASE WHEN catalog_template.folder_name IS NULL OR catalog_template.folder_name = '' THEN 1 ELSE 0 END), 0) AS blank"). Joins("JOIN catalog ON catalog.id = catalog_template.catalog_id"). Where("catalog.name = ? AND catalog.environment_id = ?", catalog.Name, catalog.EnvironmentId). - Count(&count).Error - return count > 0, err + Scan(&counts).Error + return counts.Total > 0 && counts.Blank == 0, err } diff --git a/manager/manager_test.go b/manager/manager_test.go index 3910fc3..5b9914f 100644 --- a/manager/manager_test.go +++ b/manager/manager_test.go @@ -34,7 +34,8 @@ func openCatalogIndexTestDB(t *testing.T) *gorm.DB { `CREATE TABLE catalog_template ( id INTEGER PRIMARY KEY, catalog_id INTEGER NOT NULL, - environment_id TEXT NOT NULL + environment_id TEXT NOT NULL, + folder_name TEXT )`, } { if err := db.Exec(statement).Error; err != nil { @@ -66,8 +67,8 @@ func TestCatalogHasTemplates(t *testing.T) { } if err := db.Exec( - `INSERT INTO catalog_template (id, catalog_id, environment_id) VALUES (?, ?, ?)`, - 1, 1, catalog.EnvironmentId, + `INSERT INTO catalog_template (id, catalog_id, environment_id, folder_name) VALUES (?, ?, ?, ?)`, + 1, 1, catalog.EnvironmentId, "fixture", ).Error; err != nil { t.Fatal(err) } @@ -92,8 +93,8 @@ func TestCatalogHasTemplatesDoesNotCrossEnvironments(t *testing.T) { t.Fatal(err) } if err := db.Exec( - `INSERT INTO catalog_template (id, catalog_id, environment_id) VALUES (?, ?, ?)`, - 1, 1, "project-a", + `INSERT INTO catalog_template (id, catalog_id, environment_id, folder_name) VALUES (?, ?, ?, ?)`, + 1, 1, "project-a", "fixture", ).Error; err != nil { t.Fatal(err) } @@ -109,3 +110,44 @@ func TestCatalogHasTemplatesDoesNotCrossEnvironments(t *testing.T) { t.Fatal("catalog index check matched a different environment") } } + +func TestCatalogHasTemplatesRejectsBlankCachedRows(t *testing.T) { + for _, blank := range []interface{}{"", nil} { + db := openCatalogIndexTestDB(t) + manager := &Manager{db: db} + catalog := model.Catalog{Name: "qa-catalog", EnvironmentId: "project-a"} + if err := db.Exec(`INSERT INTO catalog (id, name, environment_id) VALUES (?, ?, ?)`, 1, catalog.Name, catalog.EnvironmentId).Error; err != nil { + t.Fatal(err) + } + if err := db.Exec(`INSERT INTO catalog_template (id, catalog_id, environment_id, folder_name) VALUES (?, ?, ?, ?), (?, ?, ?, ?)`, 1, 1, catalog.EnvironmentId, "fixture", 2, 1, catalog.EnvironmentId, blank).Error; err != nil { + t.Fatal(err) + } + populated, err := manager.catalogHasTemplates(catalog) + if err != nil || populated { + t.Fatalf("index containing blank template %v bypassed repair: %v", blank, err) + } + if err := db.Exec(`DELETE FROM catalog_template WHERE id = ?`, 2).Error; err != nil { + t.Fatal(err) + } + populated, err = manager.catalogHasTemplates(catalog) + if err != nil || !populated { + t.Fatalf("clean same-commit index was not reusable: %v", err) + } + } +} + +func TestCatalogHasTemplatesIgnoresBlankRowsFromOtherCatalogs(t *testing.T) { + db := openCatalogIndexTestDB(t) + manager := &Manager{db: db} + catalog := model.Catalog{Name: "qa-catalog", EnvironmentId: "project-a"} + if err := db.Exec(`INSERT INTO catalog (id, name, environment_id) VALUES (?, ?, ?), (?, ?, ?), (?, ?, ?)`, 1, catalog.Name, catalog.EnvironmentId, 2, "other-catalog", catalog.EnvironmentId, 3, catalog.Name, "project-b").Error; err != nil { + t.Fatal(err) + } + if err := db.Exec(`INSERT INTO catalog_template (id, catalog_id, environment_id, folder_name) VALUES (?, ?, ?, ?), (?, ?, ?, ?), (?, ?, ?, ?)`, 1, 1, catalog.EnvironmentId, "fixture", 2, 2, catalog.EnvironmentId, "", 3, 3, "project-b", "").Error; err != nil { + t.Fatal(err) + } + populated, err := manager.catalogHasTemplates(catalog) + if err != nil || !populated { + t.Fatalf("foreign blank index affected the clean selected Catalog: %v", err) + } +} diff --git a/manager/traverse.go b/manager/traverse.go index 97f08f7..fe093d6 100644 --- a/manager/traverse.go +++ b/manager/traverse.go @@ -176,6 +176,9 @@ func traverseGitFiles(root *os.Root) ([]model.Template, []error, error) { if err != nil { return err } + if relativePath == ".git" && entry != nil && entry.IsDir() { + return fs.SkipDir + } if relativePath == "." || entry == nil || entry.IsDir() { return nil } @@ -205,6 +208,10 @@ func traverseGitFiles(root *os.Root) ([]model.Template, []error, error) { templates := []model.Template{} for _, template := range templateIndex { + // Metadata and version files may precede config; only parsed config gives a template its identity. + if template.FolderName == "" { + continue + } for i, version := range template.Versions { var readme string for _, file := range version.Files { @@ -326,7 +333,7 @@ func handleFile(root *os.Root, templateIndex map[string]*model.Template, relativ return nil } - _, _, _, parsedCorrectly = parse.VersionPath(relativePath) + _, _, _, parsedCorrectly = parse.VersionPath(path.Dir(relativePath)) if parsedCorrectly { return handleVersionFile(root, templateIndex, relativePath, filename) } @@ -355,6 +362,13 @@ func handleVersionFile(root *os.Root, templateIndex map[string]*model.Template, return nil } + revision, revisionErr := strconv.Atoi(folderName) + if revisionErr != nil { + if _, versionErr := semver.StrictNewVersion(strings.Trim(folderName, "v")); versionErr != nil { + return nil + } + } + contents, err := readRepositoryFile(root, relativePath) if err != nil { return err @@ -371,8 +385,7 @@ func handleVersionFile(root *os.Root, templateIndex map[string]*model.Template, } // Handle case where folder name is a revision (just a number) - revision, err := strconv.Atoi(folderName) - if err == nil { + if revisionErr == nil { for i, version := range templateIndex[key].Versions { if version.Revision != nil && *version.Revision == revision { templateIndex[key].Versions[i].Files = append(version.Files, file) @@ -387,20 +400,16 @@ func handleVersionFile(root *os.Root, templateIndex map[string]*model.Template, } // Handle case where folder name is version (must be in semver format) - _, err = semver.StrictNewVersion(strings.Trim(folderName, "v")) - if err == nil { - for i, version := range templateIndex[key].Versions { - if version.Version == folderName { - templateIndex[key].Versions[i].Files = append(version.Files, file) - return nil - } + for i, version := range templateIndex[key].Versions { + if version.Version == folderName { + templateIndex[key].Versions[i].Files = append(version.Files, file) + return nil } - templateIndex[key].Versions = append(templateIndex[key].Versions, model.Version{ - Version: folderName, - Files: []model.File{file}, - }) - return nil } + templateIndex[key].Versions = append(templateIndex[key].Versions, model.Version{ + Version: folderName, + Files: []model.File{file}, + }) return nil } diff --git a/manager/traverse_test.go b/manager/traverse_test.go new file mode 100644 index 0000000..5b9e252 --- /dev/null +++ b/manager/traverse_test.go @@ -0,0 +1,239 @@ +package manager + +import ( + "encoding/base64" + "os" + "path/filepath" + "reflect" + "strconv" + "testing" + + "github.com/PastureStack/catalog-service/model" +) + +func writeTraversalFile(t *testing.T, dir, name, contents string) { + t.Helper() + file := filepath.Join(dir, filepath.FromSlash(name)) + if err := os.MkdirAll(filepath.Dir(file), 0755); err != nil { + t.Fatal(err) + } + if err := os.WriteFile(file, []byte(contents), 0644); err != nil { + t.Fatal(err) + } +} + +func openTraversalRoot(t *testing.T, dir string) *os.Root { + t.Helper() + root, err := os.OpenRoot(dir) + if err != nil { + t.Fatal(err) + } + t.Cleanup(func() { _ = root.Close() }) + return root +} + +func TestTraverseGitFilesIgnoresGitMetadata(t *testing.T) { + dir := t.TempDir() + files := map[string]string{ + "templates/qa-zero-scale-ab/config.yml": `name: QA private Catalog A-B +description: Isolated native Catalog indexing regression +version: 1.0.0 +labels: + io.rancher.orchestration.supported: cattle + io.pasturestack.catalog.name.zh-tw: 原生範本 + io.pasturestack.catalog.description.zh-tw: 零規模測試 +`, + "templates/qa-zero-scale-ab/0/docker-compose.yml": "version: '2'\nservices:\n qa-probe:\n image: busybox:1.36.1\n", + "templates/qa-zero-scale-ab/0/rancher-compose.yml": "version: '2'\n.catalog:\n version: 1.0.0\nservices:\n qa-probe:\n scale: 0\n start_on_create: false\n", + "templates/qa-zero-scale-ab/1/docker-compose.yml": "version: '2'\nservices:\n qa-probe:\n image: busybox:1.36.1\n", + "templates/qa-zero-scale-ab/1/rancher-compose.yml": "version: '2'\n.catalog:\n version: 1.0.1\n upgrade_from: '=1.0.0'\nservices:\n qa-probe:\n scale: 0\n start_on_create: false\n", + ".git/hooks/pre-commit.sample": "git metadata\n", + ".git/info/exclude": "git metadata\n", + ".git/logs/HEAD": "git metadata\n", + ".git/objects/ab/object": "git metadata\n", + ".git/objects/12/object": "git metadata in a numeric object directory\n", + ".git/refs/heads/qa": "git metadata\n", + } + for name, contents := range files { + writeTraversalFile(t, dir, name, contents) + } + templates, parseErrors, err := traverseGitFiles(openTraversalRoot(t, dir)) + if err != nil || len(parseErrors) != 0 { + t.Fatalf("traversal failed: %v, %v", err, parseErrors) + } + if len(templates) != 1 { + t.Fatalf("got %d templates, want exactly the one fixture and no Git stubs", len(templates)) + } + template := templates[0] + labels := map[string]string{ + "io.rancher.orchestration.supported": "cattle", + "io.pasturestack.catalog.name.zh-tw": "原生範本", + "io.pasturestack.catalog.description.zh-tw": "零規模測試", + } + if template.FolderName != "qa-zero-scale-ab" || template.Base != "" || template.Name != "QA private Catalog A-B" || template.DefaultVersion != "1.0.0" || !reflect.DeepEqual(template.Labels, labels) { + t.Fatalf("fixture metadata changed: %#v", template) + } + if len(template.Versions) != 2 { + t.Fatalf("got %d versions, want 2", len(template.Versions)) + } + seen := map[int]bool{} + for _, version := range template.Versions { + if version.Revision == nil || seen[*version.Revision] || len(version.Files) != 2 { + t.Fatalf("unexpected fixture version: %#v", version) + } + revision := *version.Revision + seen[revision] = true + wantVersion, wantUpgrade := "1.0.0", "" + if revision == 1 { + wantVersion, wantUpgrade = "1.0.1", "=1.0.0" + } else if revision != 0 { + t.Fatalf("unexpected revision %d", revision) + } + if version.Version != wantVersion || version.UpgradeFrom != wantUpgrade { + t.Fatalf("version metadata changed: %#v", version) + } + seenFiles := map[string]bool{} + for _, file := range version.Files { + if seenFiles[file.Name] || file.Contents != files["templates/qa-zero-scale-ab/"+strconv.Itoa(revision)+"/"+file.Name] { + t.Fatalf("unexpected fixture file: %#v", file) + } + seenFiles[file.Name] = true + } + if !seenFiles["docker-compose.yml"] || !seenFiles["rancher-compose.yml"] { + t.Fatalf("compose files changed: %#v", seenFiles) + } + } +} + +func TestHandleVersionFileRejectsInvalidFolderBeforeReading(t *testing.T) { + root := openTraversalRoot(t, t.TempDir()) + for _, folder := range []string{"not-a-version", "v", "1.2", "01.2.3"} { + index := map[string]*model.Template{} + err := handleVersionFile(root, index, "templates/rejected/"+folder+"/missing.yml", "missing.yml") + if err != nil || len(index) != 0 { + t.Fatalf("invalid folder %q caused a read or empty template: %v, %#v", folder, err, index) + } + } +} + +func TestHandleVersionFilePreservesNumericAndSemverFolders(t *testing.T) { + for _, folder := range []string{"0", "12", "1.2.3", "v1.2.3"} { + t.Run(folder, func(t *testing.T) { + dir := t.TempDir() + name := "templates/example/" + folder + "/notes.txt" + writeTraversalFile(t, dir, name, "kept bytes\n") + index := map[string]*model.Template{} + if err := handleVersionFile(openTraversalRoot(t, dir), index, name, "notes.txt"); err != nil { + t.Fatal(err) + } + if len(index) != 1 || index["example"] == nil || len(index["example"].Versions) != 1 { + t.Fatalf("valid folder did not produce exactly one version: %#v", index) + } + version := index["example"].Versions[0] + if len(version.Files) != 1 || version.Files[0].Name != "notes.txt" || version.Files[0].Contents != "kept bytes\n" { + t.Fatalf("valid file changed: %#v", version) + } + if folder == "0" || folder == "12" { + wantRevision := 0 + if folder == "12" { + wantRevision = 12 + } + if version.Revision == nil || *version.Revision != wantRevision || version.Version != "" { + t.Fatalf("numeric semantics changed: %#v", version) + } + } else if version.Revision != nil || version.Version != folder { + t.Fatalf("semver semantics changed: %#v", version) + } + }) + } +} + +func TestTraverseGitFilesRejectsMetadataOnlyTemplates(t *testing.T) { + for _, invalidConfig := range []bool{false, true} { + t.Run(strconv.FormatBool(invalidConfig), func(t *testing.T) { + dir := t.TempDir() + files := map[string]string{ + "docs/README.md": "repository documentation\n", + "docs/icon.png": "repository icon\n", + "templates/metadata-only/README.md": "template placeholder\n", + "templates/metadata-only/catalogIcon.png": "template placeholder icon\n", + "templates/version-only/1.2.3/README.md": "version placeholder\n", + "templates/version-only/1.2.3/docker-compose.yml": "services: {}\n", + } + if invalidConfig { + files["templates/metadata-only/config.yml"] = "name: [" + } + for name, contents := range files { + writeTraversalFile(t, dir, name, contents) + } + templates, parseErrors, err := traverseGitFiles(openTraversalRoot(t, dir)) + if err != nil { + t.Fatal(err) + } + wantErrors := 0 + if invalidConfig { + wantErrors = 1 + } + if len(parseErrors) != wantErrors || len(templates) != 0 { + t.Fatalf("metadata without a parsed config emitted templates or hid errors: %#v, %v", templates, parseErrors) + } + }) + } +} + +func TestTraverseGitFilesPreservesConfiguredMetadataAndVersions(t *testing.T) { + for _, configName := range []string{"config.yml", "template.yml"} { + t.Run(configName, func(t *testing.T) { + dir := t.TempDir() + files := map[string]string{ + "infra-templates/example/" + configName: "name: Example\nversion: 1.2.3\nlabels:\n kept: metadata\n", + "infra-templates/example/README.md": "template readme\n", + "infra-templates/example/icon.png": "icon bytes\n", + } + for _, folder := range []string{"0", "12", "1.2.3", "v1.2.3"} { + prefix := "infra-templates/example/" + folder + "/" + files[prefix+"README.md"] = "version readme " + folder + "\n" + if folder == "0" || folder == "12" { + files[prefix+"rancher-compose.yml"] = ".catalog:\n version: 1.0." + folder + "\n" + } else { + files[prefix+"docker-compose.yml"] = "services: {}\n" + } + } + for name, contents := range files { + writeTraversalFile(t, dir, name, contents) + } + templates, parseErrors, err := traverseGitFiles(openTraversalRoot(t, dir)) + if err != nil || len(parseErrors) != 0 || len(templates) != 1 { + t.Fatalf("configured traversal failed: %v, %v, %#v", err, parseErrors, templates) + } + template := templates[0] + if template.FolderName != "example" || template.Base != "infra" || template.Name != "Example" || template.DefaultVersion != "1.2.3" || !reflect.DeepEqual(template.Labels, map[string]string{"kept": "metadata"}) { + t.Fatalf("configured identity or metadata changed: %#v", template) + } + if template.Readme != "template readme\n" || template.Icon != base64.StdEncoding.EncodeToString([]byte("icon bytes\n")) || template.IconFilename != "icon.png" || len(template.Versions) != 4 { + t.Fatalf("configured readme, icon or versions changed: %#v", template) + } + seen := map[string]bool{} + for _, version := range template.Versions { + folder := version.Version + if version.Revision != nil { + folder = strconv.Itoa(*version.Revision) + if (folder != "0" && folder != "12") || version.Version != "1.0."+folder { + t.Fatalf("numeric version semantics changed: %#v", version) + } + } else if folder != "1.2.3" && folder != "v1.2.3" { + t.Fatalf("semver semantics changed: %#v", version) + } + if seen[folder] || version.Readme != "version readme "+folder+"\n" || len(version.Files) != 2 { + t.Fatalf("version metadata changed: %#v", version) + } + seen[folder] = true + for _, file := range version.Files { + if file.Contents != files["infra-templates/example/"+folder+"/"+file.Name] { + t.Fatalf("version file changed: %#v", file) + } + } + } + }) + } +} diff --git a/scripts/test b/scripts/test index 2ad9b30..800b3a3 100755 --- a/scripts/test +++ b/scripts/test @@ -37,4 +37,6 @@ go test -mod=vendor ${RACE} -cover -tags=test ./... ./bin/catalog-service-sqlite --sqlite --config scripts/test-repo.json -p 8088 --track=false & SERVICE_PID=$! cd integration -tox -e flake8,py314 +/opt/tox/bin/python -I -m flake8 core +cd core +/opt/tox/bin/python -I -m pytest --durations=20 diff --git a/scripts/test-dapper-installer-retirement.py b/scripts/test-dapper-installer-retirement.py new file mode 100644 index 0000000..54e3d89 --- /dev/null +++ b/scripts/test-dapper-installer-retirement.py @@ -0,0 +1,177 @@ +"""Offline controls for the final Dapper test environment, using stdlib only.""" +import ast +from contextlib import redirect_stdout +from hashlib import sha256 +import io +import json +import os +from pathlib import Path +import re +import shutil +import subprocess +import sys +import tempfile +import unittest +import venv +import zipfile + + +ROOT = Path(__file__).resolve().parents[1] +VERIFIER = (ROOT / "scripts/verify-dapper-vex").read_text(encoding="utf-8") +PYTHON = VERIFIER.split("python3 - <<'PY'\n", 1)[1].rsplit("\nPY", 1)[0] +TREE = ast.parse(PYTHON) +TREE.body.pop() # Keep the real pure checker; do not run container-only paths locally. +MODULE = {} +exec(compile(TREE, "verify-dapper-vex", "exec"), MODULE) + + +class InstallerRetirement(unittest.TestCase): + def setUp(self): + self.temporary = tempfile.TemporaryDirectory() + self.addCleanup(self.temporary.cleanup) + root = Path(self.temporary.name) + self.site = root / "site" + self.system = root / "system" + self.seeds = root / "seeds" + self.wheels = root / "wheelhouse" + for directory in (self.site, self.system, self.seeds, self.wheels): + directory.mkdir() + lines = [] + for line in (ROOT / "integration/requirements.lock").read_text(encoding="utf-8").splitlines(): + name, version = line.split(" --hash=", 1)[0].split("==") + canonical = MODULE["canonical"](name) + content = (canonical + "==" + version).encode("ascii") + (self.wheels / (canonical + ".whl")).write_bytes(content) + lines.append(name + "==" + version + " --hash=sha256:" + sha256(content).hexdigest()) + self.distribution(canonical, version) + self.requirements = root / "requirements.lock" + self.requirements.write_text("\n".join(lines) + "\n", encoding="utf-8") + self.lock_sha = sha256(self.requirements.read_bytes()).hexdigest() + + def distribution(self, name, version, root=None): + metadata = (root or self.site) / (name.replace("-", "_") + "-" + version + ".dist-info") + metadata.mkdir() + (metadata / "METADATA").write_text("Name: " + name + "\nVersion: " + version + "\n", encoding="utf-8") + + def check(self): + with redirect_stdout(io.StringIO()): + MODULE["verify"](self.site, self.requirements, self.system, + self.seeds, self.wheels, self.lock_sha) + + def test_exact_test_environment_passes(self): + self.check() + + def test_extra_or_changed_distribution_rejected(self): + self.distribution("pip", "26.2.1") + with self.assertRaises(SystemExit): + self.check() + extra = self.site / "pip-26.2.1.dist-info/METADATA" + extra.unlink() + extra.parent.rmdir() + (self.site / "urllib3-2.8.0.dist-info/METADATA").write_text("Name: urllib3\nVersion: 2.7.0\n", encoding="utf-8") + with self.assertRaises(SystemExit): + self.check() + (self.site / "urllib3-2.8.0.dist-info/METADATA").unlink() + (self.site / "urllib3-2.8.0.dist-info").rmdir() + with self.assertRaises(SystemExit): + self.check() + + def test_code_without_metadata_rejected(self): + for root in (self.site, self.system): + for name in MODULE["RETIRED"]: + code = root / name + code.mkdir() + with self.assertRaises(SystemExit): + self.check() + code.rmdir() + + def test_system_distribution_and_seed_rejected(self): + self.distribution("pip", "25.1.1", self.system) + with self.assertRaises(SystemExit): + self.check() + metadata = self.system / "pip-25.1.1.dist-info/METADATA" + metadata.unlink() + metadata.parent.rmdir() + (self.seeds / "pip-26.2.1-py3-none-any.whl").write_bytes(b"seed") + with self.assertRaises(SystemExit): + self.check() + + def test_lock_and_wheel_mutation_rejected(self): + original = self.requirements.read_bytes() + self.requirements.write_bytes(original + b"unlocked\n") + with self.assertRaises(SystemExit): + self.check() + self.requirements.write_bytes(original) + next(self.wheels.iterdir()).write_bytes(b"changed") + with self.assertRaises(SystemExit): + self.check() + + def test_source_contract_and_same_test_entry_points(self): + self.assertEqual(MODULE["TEST_LOCK_SHA256"], sha256((ROOT / "integration/requirements.lock").read_bytes()).hexdigest()) + docker = (ROOT / "Dockerfile.dapper").read_text(encoding="utf-8") + self.assertIn("/usr/bin/python3 -m venv --without-pip /opt/tox", docker) + self.assertIn("/usr/bin/python3 -m pip --python /opt/tox install --no-cache-dir --require-hashes", docker) + self.assertNotIn("autoremove", docker) + self.assertIn("for package in python3-pip python3-pip-whl; do", docker) + self.assertIn('apt-get purge -y "${package}" || exit 1;', docker) + build = {line.split("==")[0].lower() for line in (ROOT / "integration/build-requirements.lock").read_text().splitlines()} + test = {line.split("==")[0].lower() for line in (ROOT / "integration/requirements.lock").read_text().splitlines()} + uninstall = re.search(r"pip uninstall -y (.*?) &&", docker, re.S).group(1).replace("\\", "").split() + self.assertEqual(set(uninstall), build - test - {"pip"}) + self.assertIn("/opt/tox/bin/pip uninstall -y pip &&", docker) + runner = (ROOT / "scripts/test").read_text(encoding="utf-8") + self.assertIn("go test -mod=vendor ${RACE} -cover -tags=test ./...", runner) + self.assertTrue(runner.endswith("cd integration\n/opt/tox/bin/python -I -m flake8 core\ncd core\n/opt/tox/bin/python -I -m pytest --durations=20\n")) + + def test_absolute_bootstrap_with_seedless_venv_first_on_path(self): + root = Path(self.temporary.name) + target = root / "venv" + venv.EnvBuilder(with_pip=False).create(target) + binary = target / ("Scripts" if os.name == "nt" else "bin") + environment = dict(os.environ, PATH=str(binary) + os.pathsep + os.environ["PATH"], + PIP_DISABLE_PIP_VERSION_CHECK="1", PIP_CONFIG_FILE=os.devnull) + # Reproduce the Docker PATH shadowing with a real empty venv interpreter. + shadowed = binary / Path(sys.executable).name + selected = shutil.which(Path(sys.executable).name, path=environment["PATH"]) + self.assertEqual(Path(selected), shadowed) + empty_environment = dict(environment) + empty_environment.pop("PYTHONPATH", None) + old = subprocess.run([str(shadowed), "-m", "pip", "--python", + str(target), "--version"], env=empty_environment, + capture_output=True, text=True, timeout=30) + self.assertNotEqual(old.returncode, 0) + self.assertIn("No module named pip", old.stderr) + + wheel = root / "bootstrap_probe-1.0-py3-none-any.whl" + metadata = "bootstrap_probe-1.0.dist-info/" + with zipfile.ZipFile(wheel, "w") as archive: + archive.writestr("bootstrap_probe.py", "VALUE = 1\n") + archive.writestr(metadata + "METADATA", "Metadata-Version: 2.1\nName: bootstrap-probe\nVersion: 1.0\n") + archive.writestr(metadata + "WHEEL", "Wheel-Version: 1.0\nGenerator: regression-test\nRoot-Is-Purelib: true\nTag: py3-none-any\n") + archive.writestr(metadata + "RECORD", "") + lock = root / "bootstrap.lock" + lock.write_text(str(wheel) + " --hash=sha256:" + sha256(wheel.read_bytes()).hexdigest() + "\n", encoding="utf-8") + # The absolute base interpreter delegates to the same seedless target. + fixed = subprocess.run([sys.executable, "-m", "pip", "--python", str(target), + "install", "--no-index", "--no-cache-dir", "--no-deps", + "--require-hashes", "--requirement", str(lock)], + env=environment, capture_output=True, text=True, timeout=30) + self.assertEqual(fixed.returncode, 0, fixed.stderr) + check = subprocess.run([str(binary / Path(sys.executable).name), "-I", "-c", + "import bootstrap_probe,importlib.util; " + "assert bootstrap_probe.VALUE == 1; " + "assert importlib.util.find_spec('pip') is None"], + env=environment, capture_output=True, text=True, timeout=30) + self.assertEqual(check.returncode, 0, check.stderr) + + def test_vex_only_exact_reviewed_header_package(self): + vex = json.loads((ROOT / "security/dapper.openvex.json").read_text(encoding="utf-8")) + pairs = [(s["vulnerability"]["name"], s["products"][0]["@id"]) for s in vex["statements"]] + self.assertEqual(len(pairs), 82) + self.assertEqual(len(set(pairs)), 82) + self.assertEqual({p for _, p in pairs}, {"pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04"}) + self.assertTrue(all(s["status"] == "not_affected" and s["justification"] == "vulnerable_code_not_present" for s in vex["statements"])) + + +if __name__ == "__main__": + unittest.main() diff --git a/scripts/verify-dapper-vex b/scripts/verify-dapper-vex index a63d29a..abd5e9e 100755 --- a/scripts/verify-dapper-vex +++ b/scripts/verify-dapper-vex @@ -3,105 +3,76 @@ set -euo pipefail python3 - <<'PY' +from hashlib import sha256 from importlib.metadata import Distribution -import os from pathlib import Path import re -import sys - -expected_pip = "26.2.1" -expected_setuptools = "84.0.0" -site_packages = Path( - os.environ.get( - "PASTURESTACK_DAPPER_SITE_PACKAGES", - "/opt/tox/lib/python3.14/site-packages", - ) -) +TEST_LOCK_SHA256 = "7b6c0962b69cf4bff9ae08f9f6da0c4088f959bcbd7a58ef10bd8d6db2ac3a91" +RETIRED = {"pip", "tox", "virtualenv"} -def exact_installed_version(package_name): - matches = sorted(site_packages.glob(f"{package_name}-*.dist-info")) - if len(matches) != 1: - sys.exit( - f"expected one {package_name} distribution in {site_packages}, " - f"found {len(matches)}" - ) - return Distribution.at(matches[0]).version +def canonical(name): + return re.sub(r"[-_.]+", "-", name).lower() -installed_pip = exact_installed_version("pip") -if installed_pip != expected_pip: - sys.exit( - f"pip changed from the reviewed {expected_pip} to {installed_pip}; " - "review the vendored SBOM and OpenVEX statements again" - ) -installed_setuptools = exact_installed_version("setuptools") -if installed_setuptools != expected_setuptools: - sys.exit( - f"setuptools changed from the reviewed {expected_setuptools} to " - f"{installed_setuptools}; review CVE-2025-47273 again" - ) +def require(condition, message): + if not condition: + raise SystemExit(message) -pip_root = site_packages / "pip" -vendor_root = pip_root / "_vendor" -vendor_manifest = vendor_root / "vendor.txt" -if not vendor_manifest.is_file(): - sys.exit(f"missing pip vendor manifest: {vendor_manifest}") -vendored_versions = {} -for raw_line in vendor_manifest.read_text(encoding="utf-8").splitlines(): - line = raw_line.strip() - if "==" not in line: - continue - name, package_version = line.split("==", 1) - vendored_versions[name] = package_version +def verify(site_packages, requirements, system_site, seed_wheels, wheelhouse, + expected_lock_sha256): + lock_bytes = requirements.read_bytes() + require(sha256(lock_bytes).hexdigest() == expected_lock_sha256, + "test requirements differ from the reviewed lock") + expected = {} + wheel_hashes = set() + for line in lock_bytes.decode("utf-8").splitlines(): + match = re.fullmatch(r"([A-Za-z0-9_.-]+)==([^\s]+) --hash=sha256:([0-9a-f]{64})", line) + require(match is not None, "test requirement is not an exact hash-locked wheel") + name, version, wheel_hash = match.groups() + name = canonical(name) + require(name not in expected and wheel_hash not in wheel_hashes, + "duplicate test requirement") + expected[name] = version + wheel_hashes.add(wheel_hash) + require(len(expected) == 19 and not (set(expected) & RETIRED), + "review the exact integration dependency set") -if vendored_versions.get("msgpack") != "1.1.2": - sys.exit("pip's reviewed vendored msgpack version changed") -if vendored_versions.get("setuptools") != "70.3.0": - sys.exit("pip's reviewed vendored setuptools version changed") + installed = {} + for distribution in Distribution.discover(path=[str(site_packages)]): + name = canonical(distribution.metadata["Name"]) + require(name not in installed, "duplicate installed test distribution") + installed[name] = distribution.version + require(installed == expected, "installed distributions differ from the test lock") + for root in (site_packages, system_site): + require(not any((root / name).exists() for name in RETIRED), + "retired installer code is still present") + require(not any(canonical(d.metadata["Name"]) in RETIRED + for d in Distribution.discover(path=[str(root)])), + "retired installer distribution is still present") + require(not list(seed_wheels.glob("pip*.whl")), + "system pip seed wheel is still present") + wheels = list(wheelhouse.iterdir()) + require(len(wheels) == 19 and all(p.is_file() and p.suffix == ".whl" for p in wheels), + "wheelhouse contains an unreviewed artifact") + require({sha256(p.read_bytes()).hexdigest() for p in wheels} == wheel_hashes, + "wheelhouse differs from the test lock") + print("test_dependencies=19") + print("retired_installer_code=absent") + print("retired_installer_distributions=absent") + print("system_pip_seed_wheels=absent") + print("test_wheelhouse=exact_hash_locked_19") + print("installed_urllib3=" + installed["urllib3"]) -msgpack_root = vendor_root / "msgpack" -if not (msgpack_root / "fallback.py").is_file(): - sys.exit("pip's reviewed pure-Python msgpack fallback is missing") -compiled_unpackers = sorted(msgpack_root.glob("_cmsgpack*")) -if compiled_unpackers: - sys.exit( - "the vendored msgpack C extension is present; " - "GHSA-6v7p-g79w-8964 must be treated as applicable" - ) -streaming_unpacker_patterns = ( - re.compile(r"\bmsgpack\.Unpacker\s*\("), - re.compile(r"\bfrom\s+pip\._vendor\.msgpack\s+import\s+.*\bUnpacker\b"), +verify( + Path("/opt/tox/lib/python3.14/site-packages"), + Path("/licenses/CATALOG-SERVICE-TEST-REQUIREMENTS.lock"), + Path("/usr/lib/python3/dist-packages"), + Path("/usr/share/python-wheels"), + Path("/opt/catalog-service-wheelhouse"), + TEST_LOCK_SHA256, ) -streaming_unpacker_callers = [] -for source in pip_root.rglob("*.py"): - relative = source.relative_to(pip_root) - if relative.parts[:2] == ("_vendor", "msgpack"): - continue - text = source.read_text(encoding="utf-8", errors="strict") - if any(pattern.search(text) for pattern in streaming_unpacker_patterns): - streaming_unpacker_callers.append(str(relative)) -if streaming_unpacker_callers: - sys.exit( - "pip calls the vendored streaming msgpack Unpacker outside its library: " - + ", ".join(streaming_unpacker_callers) - ) - -vulnerable_package_index = vendor_root / "setuptools" / "package_index.py" -if vulnerable_package_index.exists(): - sys.exit( - "setuptools/package_index.py is present; " - "CVE-2025-47273 must be treated as applicable" - ) - -print(f"pip={installed_pip}") -print(f"installed_setuptools={installed_setuptools}") -print(f"vendored_msgpack={vendored_versions['msgpack']}") -print("msgpack_compiled_unpacker=absent") -print("msgpack_streaming_unpacker_callers=0") -print(f"vendored_setuptools={vendored_versions['setuptools']}") -print("setuptools_package_index=absent") PY diff --git a/security/dapper.openvex.json b/security/dapper.openvex.json index 6b4cddf..757b099 100644 --- a/security/dapper.openvex.json +++ b/security/dapper.openvex.json @@ -1,1868 +1,1075 @@ { "@context": "https://openvex.dev/ns/v0.2.0", - "@id": "https://github.com/PastureStack/catalog-service/security/openvex/dapper/2026-08-26", + "@id": "https://github.com/PastureStack/catalog-service/security/openvex/dapper/2026-10-04", "author": "PastureStack contributors", - "timestamp": "2026-08-26T03:04:43Z", - "version": 3, + "timestamp": "2026-10-04T03:58:17Z", + "version": 4, "statements": [ - { - "vulnerability": { - "name": "CVE-2025-10263" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, { "vulnerability": { "name": "CVE-2025-40190" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2025-47273" - }, - "products": [ - { - "@id": "pkg:pypi/setuptools@70.3.0" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "pip 26.2.1 records setuptools 70.3.0 in its embedded SBOM, but pip's vendored subset in this ephemeral builder does not contain setuptools/package_index.py or the vulnerable PackageIndex._resolve_download_filename implementation. PastureStack verifies that absence inside the built image and fails closed if pip or its vendored subset changes. The independently installed setuptools is 84.0.0, and the builder is not shipped as the product." - }, - { - "vulnerability": { - "name": "CVE-2026-52908" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-52909" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-52910" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53145" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53148" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53153" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53159" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53170" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53171" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53172" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53173" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53178" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53182" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-53183" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53185" + "name": "CVE-2026-64543" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53192" + "name": "CVE-2026-64548" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53193" + "name": "CVE-2026-64554" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53196" + "name": "CVE-2026-64557" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53198" + "name": "CVE-2026-64558" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53235" + "name": "CVE-2026-64562" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53239" + "name": "CVE-2026-64564" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53240" + "name": "CVE-2026-64567" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53250" + "name": "CVE-2026-68098" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53254" + "name": "CVE-2026-68117" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53256" + "name": "CVE-2026-68121" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53259" + "name": "CVE-2026-68147" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53262" + "name": "CVE-2026-68162" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53264" + "name": "CVE-2026-68189" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53266" + "name": "CVE-2026-68196" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53269" + "name": "CVE-2026-68198" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53270" + "name": "CVE-2026-68199" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53275" + "name": "CVE-2026-68201" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53276" + "name": "CVE-2026-68204" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53356" + "name": "CVE-2026-68236" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53388" + "name": "CVE-2026-68257" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53398" + "name": "CVE-2026-68284" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-53399" + "name": "CVE-2026-68323" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-63801" + "name": "CVE-2026-68329" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-63809" + "name": "CVE-2026-68380" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-63815" + "name": "CVE-2026-68393" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-63823" + "name": "CVE-2026-68399" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64188" + "name": "CVE-2026-68442" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64191" + "name": "CVE-2026-68446" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64260" + "name": "CVE-2026-68451" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64266" + "name": "CVE-2026-68470" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64269" + "name": "CVE-2026-72003" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64276" + "name": "CVE-2026-72024" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64300" + "name": "CVE-2026-72110" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64361" + "name": "CVE-2026-72111" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64367" + "name": "CVE-2026-72123" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64380" + "name": "CVE-2026-72124" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64383" + "name": "CVE-2026-72135" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64385" + "name": "CVE-2026-72151" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64386" + "name": "CVE-2026-72195" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64387" + "name": "CVE-2026-72331" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64390" + "name": "CVE-2026-72338" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64393" + "name": "CVE-2026-72372" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64396" + "name": "CVE-2026-72390" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64423" + "name": "CVE-2026-72461" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64432" + "name": "CVE-2026-72462" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64440" + "name": "CVE-2026-72478" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64441" + "name": "CVE-2026-74317" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64442" + "name": "CVE-2026-74334" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64467" + "name": "CVE-2026-74341" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64490" + "name": "CVE-2026-74363" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64531" + "name": "CVE-2026-74378" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64535" + "name": "CVE-2026-74390" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64543" + "name": "CVE-2026-74411" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64548" + "name": "CVE-2026-74438" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64554" + "name": "CVE-2026-74446" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64557" + "name": "CVE-2026-74465" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64558" + "name": "CVE-2026-74470" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64562" + "name": "CVE-2026-74506" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64564" + "name": "CVE-2026-74510" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64567" + "name": "CVE-2026-74529" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64597" + "name": "CVE-2026-74534" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-64601" + "name": "CVE-2026-74535" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68085" + "name": "CVE-2026-80631" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68098" + "name": "CVE-2026-80634" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68117" + "name": "CVE-2026-80637" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68121" + "name": "CVE-2026-80644" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68147" + "name": "CVE-2026-80668" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68162" + "name": "CVE-2026-80671" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68189" + "name": "CVE-2026-80681" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68196" + "name": "CVE-2026-80683" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68198" + "name": "CVE-2026-80691" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68199" + "name": "CVE-2026-80692" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68201" + "name": "CVE-2026-80693" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68204" + "name": "CVE-2026-80700" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68236" + "name": "CVE-2026-80702" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68257" + "name": "CVE-2026-80710" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68284" + "name": "CVE-2026-80714" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68323" + "name": "CVE-2026-80716" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "CVE-2026-68329" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-68380" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-68393" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-68399" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-68442" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-68446" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-68451" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-68470" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72003" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72024" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72110" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72111" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72123" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72124" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72135" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72151" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72195" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72287" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72288" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72331" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72338" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72372" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72390" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72461" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72462" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72472" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-72478" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74268" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74317" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74334" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74341" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74363" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74378" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74390" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74394" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74411" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74427" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74438" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74446" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74465" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74470" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74506" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74510" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74529" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74534" - }, - "products": [ - { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." - }, - { - "vulnerability": { - "name": "CVE-2026-74535" + "name": "CVE-2026-80718" }, "products": [ { - "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "linux-libc-dev is present only in the ephemeral Dapper builder as user-space API headers pulled by libc6-dev for GCC and Go race tests. The builder contains no Linux kernel image or module package and is never shipped or run as the product. The shipped archive contains the reviewed catalog-service and catalog-service-sqlite executables; their raw Trivy scan is enforced separately and reports zero Critical or High findings." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." }, { "vulnerability": { - "name": "GHSA-6v7p-g79w-8964" + "name": "CVE-2026-80721" }, "products": [ { - "@id": "pkg:pypi/msgpack@1.1.2" + "@id": "pkg:deb/ubuntu/linux-libc-dev@7.0.0-38.38?arch=amd64&distro=ubuntu-26.04" } ], "status": "not_affected", "justification": "vulnerable_code_not_present", - "impact_statement": "pip 26.2.1 records msgpack 1.1.2 in its embedded SBOM, but this ephemeral builder contains only pip's pure-Python fallback and no _cmsgpack extension whose reusable parser context causes the advisory's out-of-bounds read and process crash. PastureStack's enforced inspection also proves that pip has no caller of the vendored streaming Unpacker outside the msgpack library; its cache serializer uses one-shot loads. The builder is not shipped as the product, and any pip or vendored-version change fails the review assertion." + "impact_statement": "The exact linux-libc-dev 7.0.0-38.38 amd64 package contains user-space API headers and documentation only. It is present in the ephemeral Dapper builder for GCC and Go race tests, with no Linux kernel image or module package. Kernel implementations affected by this vulnerability are absent. The builder is not shipped as the product; product binaries and raw builder findings are gated separately. This statement does not cover Python installer or runtime libraries." } ] } diff --git a/ubuntu-apt.lock b/ubuntu-apt.lock index aff4d24..46de469 100644 --- a/ubuntu-apt.lock +++ b/ubuntu-apt.lock @@ -1,17 +1,17 @@ # Ubuntu 26.04 package lock for reproducible PastureStack builds. # Refresh the snapshot and every exact direct-package version together. -UBUNTU_APT_SNAPSHOT='20260808T000000Z' +UBUNTU_APT_SNAPSHOT='20261002T000000Z' UBUNTU_APT_BASH_VERSION='5.3-2ubuntu1' UBUNTU_APT_CA_CERTIFICATES_VERSION='20260601~26.04.1' -UBUNTU_APT_CURL_VERSION='8.18.0-1ubuntu2.3' +UBUNTU_APT_CURL_VERSION='8.18.0-1ubuntu2.7' UBUNTU_APT_FILE_VERSION='1:5.46-5build2' UBUNTU_APT_GCC_VERSION='4:15.2.0-5ubuntu1' UBUNTU_APT_GIT_VERSION='1:2.53.0-1ubuntu1' -UBUNTU_APT_LIBC6_DEV_VERSION='2.43-2ubuntu2.3' +UBUNTU_APT_LIBC6_DEV_VERSION='2.43-2ubuntu2.4' +UBUNTU_APT_OPENSSL_VERSION='3.5.5-1ubuntu3.7' UBUNTU_APT_PYTHON3_VERSION='3.14.3-0ubuntu2' UBUNTU_APT_PYTHON3_PIP_VERSION='25.1.1+dfsg-1ubuntu2' -UBUNTU_APT_PYTHON3_VENV_VERSION='3.14.3-0ubuntu2' UBUNTU_APT_TAR_VERSION='1.35+dfsg-4ubuntu0.4' UBUNTU_APT_XZ_UTILS_VERSION='5.8.3-1'