SimpleRisk 20260917-001 Release - #171
Merged
Merged
Conversation
…ckerOne #3764027) The Dockerfile generated a CA key/cert and Apache TLS key/cert at build time, baked both into the published image layer, and installed the CA into the container's system trust store. Anyone who pulled the image could extract the CA private key and forge certs for any hostname the container's own outbound HTTPS calls (e.g. the schema fetch in entrypoint.sh) would then trust. Removes the custom CA entirely -- unnecessary, since the non-minimal simplerisk image self-signs its Apache cert directly without one -- and moves self-signed cert generation from build time to container startup, so each deployment gets its own key instead of a key shared by every pull of the same tag. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
/var/www/simplerisk (including cron/cron.php) is chowned to www-data, but the cron.d entry executed it as root every minute. Any web-tier compromise that gets code execution as www-data could overwrite cron.php and escalate to root on the next cron tick -- the same CWE-732 privilege-boundary crossing reported and fixed upstream in simplerisk/setup-scripts as HackerOne #3761952, just baked into this image's Dockerfile instead of the bare-metal installer script. cron.php only runs application-level jobs that already execute as www-data under Apache, so it doesn't need root. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
CVE-2026-19931 and CVE-2026-18924 are the same pre-existing Grype false positive already documented above (binary classifier reads the PHP interpreter's embedded version string out of curl.so and reports it as curl's own version), just newly published CVE IDs against that same fictitious version. Verified via `grype -o json`: the only match is /usr/local/lib/php/extensions/.../curl.so; the real Debian curl package is a separate match Debian's tracker marks "wont-fix", which --only-fixed already excludes on its own. This was failing container-validation.yml on all three simplerisk-minimal PHP variants. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…cker-ssl-and-cron-privesc Fix CA-key-in-image (HackerOne #3764027) and root-cron privesc in simplerisk
…ositive - SSL cert generation section still described the pre-fix simplerisk-minimal behavior (build-time CA). Updated to reflect the runtime self-signed cert. - GA promotion was documented as a manual dispatch; promote-latest.yml was changed to auto-fire on push to master, so merging testing -> master now ships to production immediately with no separate approval step. - Documented the testing branch's required-review ruleset (hit this session as a merge block) and the recurring Grype curl/PHP-version-string false positive in simplerisk-minimal (diagnosed this session). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ype-notes docs: correct stale CI/CD and SSL claims in CLAUDE.md
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GA promotion of the
20260917-001release candidate.Opened automatically by code-development's
promote_docker_releaseworkflowwhen
20260917-001landed on code-developmentmaster.Merging this publishes the release: the push to
masterfirespromote-latest.yml, which retags Docker Hub:latestto thealready-built RC digest, mirrors it to GHCR cosign-signed, and moves the
tier=latestSSM tag. No image is rebuilt.The required image-build checks on this PR are the gate.