Skip to content

SimpleRisk 20260917-001 Release - #171

Merged
jsokol merged 7 commits into
masterfrom
release-20260917-001
Sep 29, 2026
Merged

jsokol merged 7 commits into
masterfrom
release-20260917-001

Conversation

@simplerisk-core-sync

Copy link
Copy Markdown

GA promotion of the 20260917-001 release candidate.

Opened automatically by code-development's promote_docker_release workflow
when 20260917-001 landed on code-development master.

Merging this publishes the release: the push to master fires
promote-latest.yml, which retags Docker Hub :latest to the
already-built RC digest, mirrors it to GHCR cosign-signed, and moves the
tier=latest SSM tag. No image is rebuilt.

The required image-build checks on this PR are the gate.

SimpleRisk Updater and others added 7 commits September 18, 2026 04:24
…ckerOne #3764027)

The Dockerfile generated a CA key/cert and Apache TLS key/cert at build
time, baked both into the published image layer, and installed the CA
into the container's system trust store. Anyone who pulled the image
could extract the CA private key and forge certs for any hostname the
container's own outbound HTTPS calls (e.g. the schema fetch in
entrypoint.sh) would then trust.

Removes the custom CA entirely -- unnecessary, since the non-minimal
simplerisk image self-signs its Apache cert directly without one -- and
moves self-signed cert generation from build time to container startup,
so each deployment gets its own key instead of a key shared by every
pull of the same tag.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
/var/www/simplerisk (including cron/cron.php) is chowned to www-data,
but the cron.d entry executed it as root every minute. Any web-tier
compromise that gets code execution as www-data could overwrite
cron.php and escalate to root on the next cron tick -- the same
CWE-732 privilege-boundary crossing reported and fixed upstream in
simplerisk/setup-scripts as HackerOne #3761952, just baked into this
image's Dockerfile instead of the bare-metal installer script.

cron.php only runs application-level jobs that already execute as
www-data under Apache, so it doesn't need root.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
CVE-2026-19931 and CVE-2026-18924 are the same pre-existing Grype
false positive already documented above (binary classifier reads the
PHP interpreter's embedded version string out of curl.so and reports
it as curl's own version), just newly published CVE IDs against that
same fictitious version. Verified via `grype -o json`: the only match
is /usr/local/lib/php/extensions/.../curl.so; the real Debian curl
package is a separate match Debian's tracker marks "wont-fix", which
--only-fixed already excludes on its own. This was failing
container-validation.yml on all three simplerisk-minimal PHP variants.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…cker-ssl-and-cron-privesc

Fix CA-key-in-image (HackerOne #3764027) and root-cron privesc in simplerisk
…ositive

- SSL cert generation section still described the pre-fix simplerisk-minimal
  behavior (build-time CA). Updated to reflect the runtime self-signed cert.
- GA promotion was documented as a manual dispatch; promote-latest.yml was
  changed to auto-fire on push to master, so merging testing -> master now
  ships to production immediately with no separate approval step.
- Documented the testing branch's required-review ruleset (hit this session
  as a merge block) and the recurring Grype curl/PHP-version-string false
  positive in simplerisk-minimal (diagnosed this session).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ype-notes

docs: correct stale CI/CD and SSL claims in CLAUDE.md
@jsokol
jsokol merged commit 39d5e9b into master Sep 29, 2026
10 checks passed
@jsokol
jsokol deleted the release-20260917-001 branch September 29, 2026 15:51

This branch was successfully deployed

1 active deployment
testing — 89c1d7b5 Deployed Sep 20, 2026 by jsokol via Publish simplerisk (full-stack) RC images #22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant