Commit e3947ab
authored
fix(images): remediate Retina OSS image vulnerabilities (#2807)
# Description
Remediate vulnerabilities across the Retina OSS Linux image set by
updating
Azure Linux base image versions and explicitly selecting fixed OS
package
versions that were not upgraded automatically from the pinned base
snapshots.
The changes cover `retina-agent`, `retina-init`, `retina-operator`,
`retina-shell`, `kubectl-retina`, and `kubectl-retina-shell` on both
AMD64 and
ARM64. Enterprise images and `retina-synth` are not part of this change.
| File | Change |
| --- | --- |
| `controller/Dockerfile` | Update Azure Linux core and distroless
images to `3.0.20260909`; select PCRE2 `10.48-1.azl3` in the
library-producing tools stage. |
| `operator/Dockerfile` | Update distroless to `3.0.20260909`; select
fixed libxml2, PCRE2, and util-linux versions in the builder whose
libraries are copied into the runtime. |
| `shell/Dockerfile` | Update Azure Linux core to `3.0.20260909`; select
PCRE2 `10.48-1.azl3`. |
| `cli/Dockerfile` | Select PCRE2 `10.48-1.azl3` in both the distroless
library source and shell-enabled target. |
No Go modules or application logic changed.
## Related Issue
Follow-up to #2803. No separate issue is associated with this PR.
## Checklist
- [x] I have read the [contributing
documentation](https://retina.sh/docs/Contributing/overview).
- [x] I signed and signed-off the commits (`git commit -S -s ...`). See
[this
documentation](https://docs.github.com/en/authentication/managing-commit-signature-verification/about-commit-signature-verification)
on signing commits.
- [x] I have correctly attributed the author(s) of the code.
- [x] I have tested the changes locally.
- [x] I have followed the project's style guidelines.
- [x] I have updated the documentation, if necessary. N/A: this is an
image package-version update with no user-facing behavior change.
- [x] I have added tests, if applicable. N/A: existing source tests and
per-platform image scans cover the change.
## Screenshots (if applicable) or Testing Completed
### Vulnerability disposition
| Finding | Published/current observed version | Fixed version or
disposition | Final evidence |
| --- | --- | --- | --- |
| `CVE-2026-84445` / gRPC | v1.83.1 | v1.83.2 | Absent from all final Go
binary scans. |
| `CVE-2026-56743` / Cilium | v1.19.4 | v1.19.5 | Absent from all final
Go binary scans. |
| `CVE-2026-56855`, `CVE-2026-78662` / `x/crypto` | v0.55.0 | v0.56.0 |
Absent from all final Go binary scans. |
| OpenSSL CVEs including `CVE-2026-63076` | `3.3.7-4.azl3` |
`3.3.7-6.azl3` | Absent from final shell and copied-library stage scans.
|
| RPM `CVE-2026-44605` | `4.18.2-1.azl3` | `4.18.2-2.azl3` | Absent from
final shell scans. |
| PCRE2 `CVE-2026-86145`, `CVE-2026-89156`, `CVE-2026-89157`,
`CVE-2026-89158`, `CVE-2026-89160` | `10.42-3.azl3` | `10.48-1.azl3` |
Absent from all final image and hidden-library stage scans. |
| libxml2 CVEs including `CVE-2026-74860` and `CVE-2026-86140` |
`2.11.5-10.azl3` | `2.11.5-11.azl3` | Absent from the final operator
builder-stage scan. |
| util-linux `CVE-2026-76642`, `CVE-2026-78408`, `CVE-2026-78410` |
`2.40.2-5.azl3` | `2.40.2-6.azl3` | Absent from the final operator
builder-stage scan. |
| `GO-2026-5932` / `x/crypto/openpgp` | Trivy reports the containing
`x/crypto v0.56.0` module | Not affected / not reachable | `go list
-deps`, `go mod why`, `go tool nm`, binary strings, and `govulncheck
-mode=binary` confirm no OpenPGP package or symbol is compiled or
called. |
The published `retina-shell:v1.2.8` scan contained 144 package
occurrences
across 31 CVE IDs. The current-main pre-change shell build contained 46
occurrences across 13 CVE IDs. Both final shell platforms contain zero
findings.
### Source validation
| Command | Result |
| --- | --- |
| `go mod download all` | Passed |
| `go mod tidy` | Passed; no module changes |
| `go mod verify` | Passed; all modules verified |
| `go build -o <external-output> ./cli` | Passed |
| `make test` | Passed with Go 1.26.8 and bpftool 7.4.0 |
| `make lint` | Passed; 0 issues |
### Final image scans
Trivy v0.74.0 scanned OS packages and Go binaries in each
architecture-specific
OCI artifact.
| Image | AMD64 | ARM64 | Final result |
| --- | --- | --- | --- |
| `retina-agent` | Passed | Passed | 0 findings |
| `retina-init` | Passed | Passed | 0 findings |
| `retina-operator` | Passed | Passed | Only `GO-2026-5932`; proven not
compiled or reachable |
| `retina-shell` | Passed | Passed | 0 findings |
| `kubectl-retina` | Passed | Passed | Only `GO-2026-5932`; proven not
compiled or reachable |
| `kubectl-retina-shell` | Passed | Passed | Only `GO-2026-5932`; proven
not compiled or reachable |
Trivy also scanned the library-producing stages that are copied into
distroless images but are not represented completely by the final RPM
manifest:
| Stage | AMD64 | ARM64 |
| --- | --- | --- |
| `controller/Dockerfile` target `tools` | 0 findings | 0 findings |
| `cli/Dockerfile` target `libs` | 0 findings | 0 findings |
| `operator/Dockerfile` target `builder` | Only non-reachable
`GO-2026-5932` | The final ARM64 build uses the same `$BUILDPLATFORM`
builder stage |
### Artifact identities
| Image | Platform | OCI archive SHA-256 |
| --- | --- | --- |
| `retina-agent` | AMD64 |
`ba079cea0b359cffc91604acb89dbcbfcf249cf19dc1c4ddfef8841dc33e271a` |
| `retina-agent` | ARM64 |
`971ef708af792d7d9619deebdf8f9dc3158d37c9342860111d86961ad7571953` |
| `retina-init` | AMD64 |
`ebc37da632d85d6f152375945deed95ec3183a3f487584b6290f3702831dad7b` |
| `retina-init` | ARM64 |
`f25bb822e9b9181f14d3836eebcf970f2a9549504232a09d16e20dbdc54b2c38` |
| `retina-operator` | AMD64 |
`9383c24244356337ffe0e43832e9bfca45c8da2f24e34395644c32eeee66c80b` |
| `retina-operator` | ARM64 |
`36df02fe0de559aca8a70016984826bfdd640827a7b0a050a180e9a7a4d6f539` |
| `retina-shell` | AMD64 |
`0a29989411814f51d63d4980a328c305ce4654b45a72814ef6cff73420930dd2` |
| `retina-shell` | ARM64 |
`7c39544f14914ed2745753a2080a498dc5fea3520457a7e162e77bb63c2e9a15` |
| `kubectl-retina` | AMD64 |
`13dea08cf8caca25e00ca2b1a8e9c91ec8694d6b712e6d294ff1cf0a6ac53bd0` |
| `kubectl-retina` | ARM64 |
`5b5af2cfb7db4d43fff586842fc485736fca11e5eb61d774e74be14187879963` |
| `kubectl-retina-shell` | AMD64 |
`8ce3f449622362d1920604b2d5007a5b51e90ad88ad12810657ad9c766865103` |
| `kubectl-retina-shell` | ARM64 |
`7cdebfe5af70cc8ec7251af7ad9a63b4d78be3f62e7291684e84fda26774e4e7` |
### Remaining HIGH or CRITICAL findings
None.
## Additional Notes
- The remaining `GO-2026-5932` Trivy entries are module-granularity
matches.
The affected OpenPGP packages are absent from the compiled operator and
CLI
binaries, and binary-mode `govulncheck` reports zero affected
vulnerabilities.
- Trivy reports are the local unpublished after-state. Published release
telemetry will change only after fixed images are built and published.
- All tools, OCI archives, caches, and scan reports were stored outside
the
repository.
---
Please refer to the [CONTRIBUTING.md](../CONTRIBUTING.md) file for more
information on how to contribute to this project.
---------
Signed-off-by: mushiboy <mushi025@gmail.com>1 parent 12eaeae commit e3947ab
4 files changed
Lines changed: 19 additions & 7 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
| 34 | + | |
33 | 35 | | |
34 | 36 | | |
35 | 37 | | |
| |||
49 | 51 | | |
50 | 52 | | |
51 | 53 | | |
| 54 | + | |
| 55 | + | |
52 | 56 | | |
53 | 57 | | |
54 | 58 | | |
55 | 59 | | |
56 | 60 | | |
57 | 61 | | |
58 | | - | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
| 11 | + | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
| 14 | + | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
| |||
121 | 121 | | |
122 | 122 | | |
123 | 123 | | |
| 124 | + | |
124 | 125 | | |
125 | 126 | | |
126 | 127 | | |
127 | 128 | | |
128 | 129 | | |
| 130 | + | |
129 | 131 | | |
130 | 132 | | |
131 | 133 | | |
| |||
148 | 150 | | |
149 | 151 | | |
150 | 152 | | |
151 | | - | |
| 153 | + | |
152 | 154 | | |
153 | 155 | | |
154 | 156 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
15 | 20 | | |
16 | 21 | | |
17 | 22 | | |
| |||
36 | 41 | | |
37 | 42 | | |
38 | 43 | | |
39 | | - | |
| 44 | + | |
40 | 45 | | |
41 | 46 | | |
42 | 47 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | | - | |
| 29 | + | |
30 | 30 | | |
| 31 | + | |
31 | 32 | | |
32 | 33 | | |
33 | 34 | | |
| |||
47 | 48 | | |
48 | 49 | | |
49 | 50 | | |
| 51 | + | |
50 | 52 | | |
51 | 53 | | |
52 | 54 | | |
| |||
0 commit comments