Temporarily accept CVE-2026-82049 in Python 3.13.15 - #13
Merged
Merged
Conversation
Scope the Grype exception for CVE-2026-82049 to the Python 3.13.15 binary package while awaiting a fixed upstream image. Track removal in issue #12.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Grype blocks Python 3.13.15 images on CVE-2026-82049 while the upstream fix is awaiting a Python 3.13 release. Add a temporary exception limited to that CVE and the
pythonbinary package at exactly version3.13.15.This accepts the unresolved tarfile vulnerability; it does not patch it. Removal after adopting a fixed upstream image is tracked in #12. The existing Python 3.10 exception remains separately scoped.
Validation: YAML parsing, exact rule-scope checks, and
git diff --checkpassed. Image/Grype CI validation is pending.Related: wodby/images#20 adds Grype exception warnings to image update reports. The PRs can merge independently; reporting will discover this exception after it reaches the default branch. Keep #12 open until the exception is removed.