Skip to content

SecOps: remediate critical vulnerabilities #187

Description

@muscariello

Automated remediation guidance for critical dependency and container-image alerts.

Updates:

  • authlib: 1.6.7 (updated)
  • nltk: 3.9.3 (updated)
  • pillow: 12.1.1 (updated)
  • cryptography: 46.0.5 (updated)
  • cryptography: 46.0.5 (updated)
  • [CVE-2026-27171] zlib fixed in 1.3.2-r0 on base image ghcr.io/cirruslabs/flutter:stable in tourist_scheduling_system/containers/frontend/Dockerfile (base_image_refresh_recommended)
  • [CVE-2026-22184] zlib fixed in 1.3.2-r0 on base image ghcr.io/cirruslabs/flutter:stable in tourist_scheduling_system/containers/frontend/Dockerfile (base_image_refresh_recommended)
  • [CVE-2026-28802] Authlib fixed in 1.6.7 on base image python:3.12-slim in tourist_scheduling_system/containers/scheduler/Dockerfile (base_image_refresh_recommended)
  • [CVE-2026-25646] libpng fixed in 1.6.55-r0 on base image ghcr.io/cirruslabs/flutter:stable in tourist_scheduling_system/containers/frontend/Dockerfile (base_image_refresh_recommended)
  • [CVE-2025-14831] libgnutls30t64 fixed in 3.8.9-3+deb13u2 on base image python:3.12-slim in tourist_scheduling_system/containers/scheduler/Dockerfile (base_image_refresh_recommended)
  • [CVE-2025-14831] libgnutls30t64 fixed in 3.8.9-3+deb13u2 on base image python:3.12-slim in tourist_scheduling_system/containers/ui/Dockerfile (base_image_refresh_recommended)
  • [CVE-2026-26007] cryptography fixed in 46.0.5 on base image python:3.12-slim in tourist_scheduling_system/containers/scheduler/Dockerfile (base_image_refresh_recommended)
  • [CVE-2026-25210] libexpat fixed in 2.7.4-r0 on base image ghcr.io/cirruslabs/flutter:stable in tourist_scheduling_system/containers/frontend/Dockerfile (base_image_refresh_recommended)
  • [CVE-2025-8869] pip fixed in 25.3 on base image python:3.12-slim in tourist_scheduling_system/containers/scheduler/Dockerfile (base_image_refresh_recommended)

Generated by SHADI SecOps.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions