Skip to content

fix(security): remediate git-server runtime dependencies - #42

Open
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/remediate-git-server-deps-1790350000000
Open

plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/remediate-git-server-deps-1790350000000

Conversation

@plural-copilot

Copy link
Copy Markdown

Deployment context

  • Service inventory finding: mgmt/console
  • Affected image: ghcr.io/pluralsh/git-server:v0.12.47

Remediation

  • Runtime/base: alpine:edge → alpine:3.23, with explicit expat=2.8.5-r0. Alpine's expat package installs libexpat, remediating libexpat 2.8.4-r0 → 2.8.5-r0 deterministically.
  • Go: golang.org/x/crypto v0.53.0 → v0.56.0, covering CVE-2026-78662, CVE-2026-56855, and CVE-2026-56854.
  • Resolved compatible indirect Go dependencies were updated as required: x/net 0.56.0 → 0.57.0, x/sync 0.21.0 → 0.22.0, x/sys 0.46.0 → 0.47.0, x/text 0.39.0 → 0.41.0, and x/tools 0.47.0 → 0.48.0; go.sum records the corresponding x/mod 0.38.0 and x/term 0.45.0 checksums.

Validation

Passed using Docker/DinD:

  • go mod verify — all modules verified
  • go mod tidy -diff — passed with no diff
  • go list -m golang.org/x/crypto — golang.org/x/crypto v0.56.0
  • docker build --no-cache -t soft-serve-libexpat-validation:local . — passed; installed libexpat (2.8.5-r0)
  • docker run --rm --entrypoint sh soft-serve-libexpat-validation:local -ec 'apk info -e expat=2.8.5-r0; apk info -e libexpat=2.8.5-r0; apk info -W /usr/lib/libexpat.so.1' — passed; ownership reported libexpat-2.8.5-r0
  • go test ./pkg/config/... ./pkg/ssh/... — pkg/config passed; the remaining SSH portion was stopped while the container was fetching github.com/matryer/is, so it is not claimed as complete.

Scope and residuals

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create one focused remediation PR in this repository for the live mgmt/console service inventory finding in image ghcr.io/pluralsh/git-server:v0.12.47....
🔗 Run history View run history

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang.org/​x/​crypto@​v0.53.0 ⏵ v0.56.074100100100100
Updatedgolang.org/​x/​sync@​v0.21.0 ⏵ v0.22.099 +1100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants