fix(mcp): patch the two high sqlite CVEs in the container image (#12537)

This commit is contained in:
Rubén De la Torre Vico
2026-08-25 17:41:44 +02:00
committed by GitHub
parent 465e35bf54
commit f299e1d9ac
4 changed files with 15 additions and 0 deletions
@@ -114,6 +114,8 @@ jobs:
egress-policy: block
allowed-endpoints: >
auth.docker.io:443
dl-cdn.alpinelinux.org:443
dualstack.j.sni.global.fastly.net:443
files.pythonhosted.org:443
ghcr.io:443
github.com:443
@@ -81,6 +81,8 @@ jobs:
pkg-containers.githubusercontent.com:443
files.pythonhosted.org:443
pypi.org:443
dl-cdn.alpinelinux.org:443
dualstack.j.sni.global.fastly.net:443
api.github.com:443
mirror.gcr.io:443
check.trivy.dev:443
+10
View File
@@ -29,6 +29,16 @@ FROM python:3.13.14-alpine3.23@sha256:9fdbf2e3e82628351513560b121e2ee6ce31cac212
LABEL maintainer="https://github.com/prowler-cloud"
# CVE-2026-11822 and CVE-2026-11824, both high, are fixed in Alpine 3.23's
# sqlite 3.53.4-r0. The base image pins python 3.13.14, which has not been
# rebuilt since that package was published and still ships 3.51.2-r0, so the
# upgrade is taken here rather than by moving the pin -- the newest published
# python:3.13-alpine3.23 carries the same vulnerable version.
# `>=` rather than `=`: Alpine keeps only the newest build of a package in a
# branch's index, so an exact pin breaks this build the day 3.53.4-r0 is
# superseded. Drop this once the base image ships 3.53.4-r0 or later.
RUN apk add --no-cache --upgrade "sqlite-libs>=3.53.4-r0"
# Create non-root user for security
# Using specific UID/GID for consistency across environments
RUN addgroup -g 1001 prowler && \
@@ -0,0 +1 @@
`sqlite-libs` upgraded to 3.53.4-r0 in the container image, patching CVE-2026-11822 and CVE-2026-11824