Skip to content

Assess agent tar-link applicability and record the StringPrep fix - #43

Merged
LouisLotter merged 1 commit into
mainfrom
agent-python-fixed-vex
Sep 18, 2026
Merged

LouisLotter merged 1 commit into
mainfrom
agent-python-fixed-vex

Conversation

@LouisLotter

@LouisLotter LouisLotter commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Add an image-scoped not_affected assessment for tar-link CVE-2026-87910 and a fixed statement for the exact StringPrep source commit in agent PR529.

AMD64/ARM64 inspection of published agent 13451dce (index sha256:32a25b904072a24df3c6e1d3da22e8fb7fee9e34ad98b4a73756b091acba4060) found identical tar call-site files: runtime readers use extractfile; filtered filesystem extraction belongs to unused build tooling. This assertion covers shipped integrations, not arbitrary customer checks.

Grype controls apply the four existing Python statements plus tar-link, leaving StringPrep active; an unrelated image name suppresses none. Index validation passes. The fixed statement deliberately identifies source only: add verified published image digests after PR529 merges, then verify both scanner consumers. It does not clear unpatched Python 3.13.15 images.

Detailed audit and publication handoff.

Tracking: #34 and https://github.com/StackVista/cve-reporter/issues/29. Rancher migration remains a post-merge follow-up.

@LouisLotter
LouisLotter merged commit 73cde84 into main Sep 18, 2026
1 check passed
@LouisLotter
LouisLotter deleted the agent-python-fixed-vex branch September 18, 2026 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants