Skip to content

RHAIENG-2846 [3/3]: Hermetic Dockerfile + build patches + Tekton for codeserver - #2985

Merged
ysok merged 1 commit into
opendatahub-io:mainfrom
ysok-opendatahub-io:odh-hermetic-codeserver-build
Feb 28, 2026
Merged

ysok merged 1 commit into
opendatahub-io:mainfrom
ysok-opendatahub-io:odh-hermetic-codeserver-build

RHAIENG-2846 [3/3]: Hermetic Dockerfile + build patches + Tekton for …

bbffd5b
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Feb 28, 2026 in 3s

5 new alerts including 4 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 4 high
  • 1 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 16619 in codeserver/ubi9-python-3.12/prefetch-input/patches/code-server-v4.106.3/lib/vscode/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives High library

Package: tar
Installed Version: 6.2.1
Vulnerability CVE-2026-23745
Severity: HIGH
Fixed Version: 7.5.3
Link: CVE-2026-23745

Check failure on line 16619 in codeserver/ubi9-python-3.12/prefetch-input/patches/code-server-v4.106.3/lib/vscode/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition High library

Package: tar
Installed Version: 6.2.1
Vulnerability CVE-2026-23950
Severity: HIGH
Fixed Version: 7.5.4
Link: CVE-2026-23950

Check failure on line 16619 in codeserver/ubi9-python-3.12/prefetch-input/patches/code-server-v4.106.3/lib/vscode/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check High library

Package: tar
Installed Version: 6.2.1
Vulnerability CVE-2026-24842
Severity: HIGH
Fixed Version: 7.5.7
Link: CVE-2026-24842

Check failure on line 16619 in codeserver/ubi9-python-3.12/prefetch-input/patches/code-server-v4.106.3/lib/vscode/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation High library

Package: tar
Installed Version: 6.2.1
Vulnerability CVE-2026-26960
Severity: HIGH
Fixed Version: 7.5.8
Link: CVE-2026-26960

Check warning on line 17385 in codeserver/ubi9-python-3.12/prefetch-input/patches/code-server-v4.106.3/lib/vscode/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

undici: Undici: Denial of Service via excessive decompression steps Medium library

Package: undici
Installed Version: 7.9.0
Vulnerability CVE-2026-22036
Severity: MEDIUM
Fixed Version: 7.18.2, 6.23.0
Link: CVE-2026-22036