Skip to content

fix(docker): patch the base-OS pcre2 CVE in the nginx images - #33

Merged
santidev21 merged 1 commit into
mainfrom
fix/trivy-pcre2-cve
Oct 1, 2026
Merged

santidev21 merged 1 commit into
mainfrom
fix/trivy-pcre2-cve

Conversation

@santidev21

Copy link
Copy Markdown
Owner

Problem

The required check Docker Build & Trivy Scan fails on every branch (including main's next run) with:

splitit-frontend:test (alpine 3.24.2)
pcre2  CVE-2026-103111  HIGH  fixed  10.48-r0 -> 10.49-r0

The nginx base image still ships pcre2 10.48-r0, and the existing apk upgrade --no-cache layer is served from the Docker build cache, so the OS patch is never applied on rebuilds.

Fix

Require pcre2>=10.49-r0 explicitly in both nginx-based images (frontend and proxy). The generic apk upgrade --no-cache stays for the rest of the base OS. This also busts the stale cached layer.

Verified locally: the built layer upgrades pcre2 10.48-r0 -> 10.49-r0.

Unrelated to the coverage work; split out so that PR stays focused.

CVE-2026-103111 (HIGH, pcre2 out-of-bounds write) is present in nginx:1.31-alpine and fails the required Docker Build & Trivy Scan gate. The published nginx image still ships pcre2 10.48-r0 and the cached apk upgrade layer skips the fix, so require pcre2>=10.49-r0 explicitly in both nginx-based images (frontend and proxy). Generic apk upgrade is kept for the rest of the base OS.
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@santidev21
santidev21 merged commit 0ada423 into main Oct 1, 2026
12 checks passed
@santidev21
santidev21 deleted the fix/trivy-pcre2-cve branch October 1, 2026 21:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant