Skip to content

Phase 5: bump flask 3.0.0->3.1.3, SBOM (syft) + scout cross-check + G…#3

Merged
MetaMaaz merged 1 commit into
mainfrom
phase-5-supply-chain
Jun 23, 2026
Merged

Phase 5: bump flask 3.0.0->3.1.3, SBOM (syft) + scout cross-check + G…#3
MetaMaaz merged 1 commit into
mainfrom
phase-5-supply-chain

Conversation

@MetaMaaz

Copy link
Copy Markdown
Owner

Phase 5 — supply-chain extras.

  • Bumped flask 3.0.0 → 3.1.3 to clear CVE-2026-27205 (LOW, cache-of-sensitive-info) that docker scout flagged but the Trivy CRITICAL/HIGH gate filtered by design.
  • Generated an SPDX SBOM with syft (results/sbom.json) — 41 components, no shell / apt / perl, confirming the distroless attack-surface claim.
  • Cross-checked with docker scout (results/scout-summary.txt): 0C/0H/0M/0L after the bump. Scout and Trivy disagree on the base-OS DoS CVEs — kept both as a methodology note.
  • Published the image to GHCR: ghcr.io/metamaaz/myapp:latest and :v4-distroless.

No Dockerfile changes; image rebuilt and re-scanned clean before publishing.

@MetaMaaz
MetaMaaz merged commit 7c3f89b into main Jun 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant