Skip to content

Commit ee6058f

Browse files
authored
Update README.md for Day-07 with findings.
Update README.md for Day-07 with findings.
1 parent 1459bea commit ee6058f

1 file changed

Lines changed: 203 additions & 0 deletions

File tree

Day-07/README.md

Lines changed: 203 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,3 +46,206 @@ Compiler: gc
4646
Syft Version: v1.45.1
4747
Supported DB Schema: 6
4848
```
49+
50+
---
51+
52+
## Security Assessment Workflow
53+
54+
The security assessment followed the process below:
55+
56+
1. Scan the existing container image.
57+
2. Review vulnerability findings.
58+
3. Investigate affected packages.
59+
4. Apply remediation.
60+
5. Rebuild the image.
61+
6. Validate improvements through rescanning.
62+
63+
---
64+
65+
## Initial Scan Results (fastapi-v3)
66+
67+
The existing application image was scanned using Grype:
68+
69+
```bash
70+
# Let's identify the critical and the high vulnerabilities of the 'janemils/janemils-app:fastapi-v3' image using grype.
71+
root@ubuntu-host ~ ➜ grype janemils/janemils-app:fastapi-v3 --only-fixed | grep -E "High|Critical"
72+
✔ Loaded image janemils/janemils-app:fastapi-v3
73+
✔ Parsed image sha256:f2448c57f6d36309d03cfe51b17c54d103f32d8f811f19a92
74+
✔ Cataloged contents eb3de8a439e428d95b2aba9379f0f9b256c85e9b5ba6db022d08a858
75+
├── ✔ Packages [127 packages]
76+
├── ✔ Executables [759 executables]
77+
├── ✔ File metadata [2,729 locations]
78+
└── ✔ File digests [2,729 files]
79+
✔ Scanned for vulnerabilities [114 vulnerability matches]
80+
├── by severity: 12 critical, 74 high, 72 medium, 14 low, 51 negligible
81+
└── by status: 114 fixed, 109 not-fixed, 109 ignored
82+
python 3.11.15 3.15.0b2 binary CVE-2026-7210 Critical 0.2% (40th) 0.2
83+
libssl3t64 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28389 High 0.1% (34th) 0.1
84+
openssl 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28389 High 0.1% (34th) 0.1
85+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28389 High 0.1% (34th) 0.1
86+
libssl3t64 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28390 High 0.1% (34th) 0.1
87+
openssl 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28390 High 0.1% (34th) 0.1
88+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28390 High 0.1% (34th) 0.1
89+
jaraco-context 5.3.0 6.1.0 python GHSA-58pv-8j8x-9vj2 High 0.1% (27th) < 0.1
90+
libssl3t64 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-45447 High < 0.1% (26th) < 0.1
91+
openssl 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-45447 High < 0.1% (26th) < 0.1
92+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-45447 High < 0.1% (26th) < 0.1
93+
libssl3t64 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-9076 High < 0.1% (26th) < 0.1
94+
openssl 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-9076 High < 0.1% (26th) < 0.1
95+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-9076 High < 0.1% (26th) < 0.1
96+
libc-bin 2.41-12+deb13u1 2.41-12+deb13u2 deb CVE-2025-15281 High < 0.1% (25th) < 0.1
97+
libc6 2.41-12+deb13u1 2.41-12+deb13u2 deb CVE-2025-15281 High < 0.1% (25th) < 0.1
98+
libc-bin 2.41-12+deb13u1 2.41-12+deb13u3 deb CVE-2026-4437 High < 0.1% (25th) < 0.1
99+
libc6 2.41-12+deb13u1 2.41-12+deb13u3 deb CVE-2026-4437 High < 0.1% (25th) < 0.1
100+
python 3.11.15 *3.13.13, 3.14.4, 3.15.0a8 binary CVE-2026-4224 High < 0.1% (25th) < 0.1
101+
libc-bin 2.41-12+deb13u1 2.41-12+deb13u3 deb CVE-2026-4046 High < 0.1% (24th) < 0.1
102+
libc6 2.41-12+deb13u1 2.41-12+deb13u3 deb CVE-2026-4046 High < 0.1% (24th) < 0.1
103+
libssl3t64 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-7383 High < 0.1% (20th) < 0.1
104+
openssl 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-7383 High < 0.1% (20th) < 0.1
105+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-7383 High < 0.1% (20th) < 0.1
106+
libssl3t64 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34180 High < 0.1% (18th) < 0.1
107+
openssl 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34180 High < 0.1% (18th) < 0.1
108+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34180 High < 0.1% (18th) < 0.1
109+
libssl3t64 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28388 High < 0.1% (17th) < 0.1
110+
openssl 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28388 High < 0.1% (17th) < 0.1
111+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28388 High < 0.1% (17th) < 0.1
112+
python 3.11.15 *3.13.13, 3.14.4, 3.15.0a8 binary CVE-2026-3644 High < 0.1% (18th) < 0.1
113+
libssl3t64 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28387 High < 0.1% (15th) < 0.1
114+
openssl 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28387 High < 0.1% (15th) < 0.1
115+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-28387 High < 0.1% (15th) < 0.1
116+
libssl3t64 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-31790 High < 0.1% (13th) < 0.1
117+
openssl 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-31790 High < 0.1% (13th) < 0.1
118+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-31790 High < 0.1% (13th) < 0.1
119+
libssl3t64 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-42764 High < 0.1% (13th) < 0.1
120+
openssl 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-42764 High < 0.1% (13th) < 0.1
121+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-42764 High < 0.1% (13th) < 0.1
122+
libssl3t64 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34183 High < 0.1% (11th) < 0.1
123+
openssl 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34183 High < 0.1% (11th) < 0.1
124+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34183 High < 0.1% (11th) < 0.1
125+
dpkg 1.22.21 1.22.22 deb CVE-2026-2219 High < 0.1% (7th) < 0.1
126+
libc-bin 2.41-12+deb13u1 2.41-12+deb13u2 deb CVE-2026-0915 High < 0.1% (4th) < 0.1
127+
libc6 2.41-12+deb13u1 2.41-12+deb13u2 deb CVE-2026-0915 High < 0.1% (4th) < 0.1
128+
libssl3t64 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-45445 High < 0.1% (4th) < 0.1
129+
openssl 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-45445 High < 0.1% (4th) < 0.1
130+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-45445 High < 0.1% (4th) < 0.1
131+
wheel 0.45.1 0.46.2 python GHSA-8rrh-rw8j-w5fx High < 0.1% (3rd) < 0.1
132+
libcap2 1:2.75-10+b3 1:2.75-10+deb13u1 deb CVE-2026-4878 High < 0.1% (2nd) < 0.1
133+
libc-bin 2.41-12+deb13u1 2.41-12+deb13u2 deb CVE-2026-0861 High < 0.1% (1st) < 0.1
134+
libc6 2.41-12+deb13u1 2.41-12+deb13u2 deb CVE-2026-0861 High < 0.1% (1st) < 0.1
135+
libssl3t64 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-31789 Critical < 0.1% (0th) < 0.1
136+
openssl 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-31789 Critical < 0.1% (0th) < 0.1
137+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.5-1~deb13u2 deb CVE-2026-31789 Critical < 0.1% (0th) < 0.1
138+
libssl3t64 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34182 Critical < 0.1% (0th) < 0.1
139+
openssl 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34182 Critical < 0.1% (0th) < 0.1
140+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34182 Critical < 0.1% (0th) < 0.1
141+
libssl3t64 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34181 High < 0.1% (0th) < 0.1
142+
openssl 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34181 High < 0.1% (0th) < 0.1
143+
openssl-provider-legacy 3.5.4-1~deb13u2 3.5.6-1~deb13u2 deb CVE-2026-34181 High < 0.1% (0th) < 0.1
144+
145+
```
146+
147+
### Analysis
148+
149+
The scan results suggested that many vulnerabilities originated from components inherited from the base image rather than the application code itself.
150+
151+
To validate this assumption, the base image was upgraded from Python 3.11 Slim to Python 3.13 Slim and the image was rebuilt.
152+
153+
After rebuilding and rescanning, the number of fixable High and Critical vulnerabilities dropped significantly, confirming that the base image version was a major contributor to the overall vulnerability count.
154+
155+
---
156+
157+
## Remediation
158+
159+
The application image was originally built using:
160+
161+
```dockerfile
162+
FROM python:3.11-slim
163+
```
164+
165+
To reduce exposure to known vulnerabilities, the base image was upgraded to (latest stable version at the time of this update: 15-06-2026):
166+
167+
```dockerfile
168+
FROM python:3.13-slim
169+
```
170+
171+
The image was rebuilt, pushed to dockerhub and published as:
172+
173+
```text
174+
janemils/janemils-app:fastapi-v4
175+
```
176+
177+
The Kubernetes deployment manifests and Terraform configuration were updated to reference the remediated image version.
178+
179+
Changes were then committed and deployed through the existing GitOps workflow.
180+
181+
---
182+
183+
## Validation Scan Results (fastapi-v4)
184+
185+
The updated image was rescanned using Grype:
186+
187+
```bash
188+
# Let's identify the critical and the high vulnerabilities of the 'janemils/janemils-app:fastapi-v4' image using grype.
189+
root@ubuntu-host Devops-Project-1 on  main [!?] ➜ grype janemils/janemils-app:fastapi-v4 --only-fixed | grep -E "High|Critical"
190+
✔ Loaded image janemils/janemils-app:fastapi-v4
191+
✔ Parsed image sha256:f9d242eb6987413af266d8ae0803791d65b28e6916b3ec550
192+
✔ Cataloged contents 07c7e2c0a20176464a70279cc3f910c0a229e6fb3fa9b1bc03c15c1f
193+
├── ✔ Packages [109 packages]
194+
├── ✔ Executables [752 executables]
195+
├── ✔ File metadata [2,681 locations]
196+
└── ✔ File digests [2,681 files]
197+
✔ Scanned for vulnerabilities [9 vulnerability matches]
198+
├── by severity: 6 critical, 18 high, 40 medium, 4 low, 50 negligible
199+
└── by status: 9 fixed, 109 not-fixed, 109 ignored
200+
python 3.13.14 3.15.0b2 binary CVE-2026-7210 Critical 0.2% (40th) 0.2
201+
```
202+
203+
### Outcome
204+
205+
The updated image significantly reduced the number of fixable vulnerabilities compared to the previous version.
206+
207+
```
208+
# With the v3 version:
209+
24 fixed vulnerabilities
210+
6 Critical
211+
23 High
212+
```
213+
214+
```
215+
# With the v4 version:
216+
9 fixed vulnerabilities
217+
1 Critical
218+
0 High
219+
```
220+
221+
This demonstrates a common remediation strategy used in production environments where updating base images and dependencies can improve security posture without requiring application code changes.
222+
223+
---
224+
225+
## Remaining Findings
226+
227+
A small number of vulnerabilities remained after remediation.
228+
229+
One notable finding affected the Python runtime itself, where the recommended fix was only available in a beta Python release.
230+
231+
Since beta runtimes are generally not considered production-ready, the finding was documented and accepted temporarily rather than introducing an unstable runtime into the application.
232+
233+
This reflects a common real-world security trade-off where risk must be balanced against operational stability.
234+
235+
---
236+
237+
## Key Takeaways
238+
239+
* Vulnerability scanning should be performed regularly.
240+
* Container images inherit vulnerabilities from their base images.
241+
* Many vulnerabilities can be remediated through dependency and runtime upgrades.
242+
* Not every vulnerability has an immediate production-ready fix.
243+
* Security findings should be analyzed before remediation decisions are made.
244+
* Vulnerability scanning is most effective when integrated into CI/CD pipelines.
245+
246+
---
247+
248+
## Next Steps
249+
250+
Now that you have an understanding of how grype works and have tested it out locally, the next phase of this project will integrate Grype into the GitHub Actions workflow to automate vulnerability scanning during the CI process and prevent vulnerable images from progressing further through the delivery pipeline.
251+

0 commit comments

Comments
 (0)