Repository navigation
fix(nvca): bump distroless/go base image to v4.1.4 on v3.2 - #2129
Merged
apartha-nv merged 1 commit intoSep 28, 2026
Merged
apartha-nv merged 1 commit into
apartha-nv merged 1 commit into
Conversation
The nvca, nvca-operator, and cluster-validator 3.2.25 images all report the same 9 out-of-SLA vulnerabilities on the nSpect LaunchAPI container-oss-vulns-out-of-sla gate, despite: - govulncheck showing 0 code-reachable Go vulnerabilities (nvca, cluster-validator) - trivy, scanning the base image's own SBOM against Debian's vendor security tracker, showing 0 vulnerabilities for all 9 packages in nvcr.io/nvidia/distroless/go:v4.0.8 The identical count across all three images (including cluster-validator, which doesn't depend on grpc) points to a shared, non-application-specific source on the base OS layer -- likely raw NVD version-string matching against Debian's backport patch versions, which vendor-aware scanners already treat as patched. Bumping to v4.1.4 (latest available, same distroless family) picks up newer patch versions of libc6, libssl3t64/openssl-provider-fips, and tzdata, which may shift past whatever version nSpect's matcher is keying on. trivy scan of the v4.1.4 SBOM also reports 0 vulnerabilities. Verified with a full bazel build of the nvca, nvca-operator, and cluster-validator targets. Closes NO-REF
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. 🗂️ Base branches to auto review (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: NVIDIA/nvcf/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
vrv3814
approved these changes
Sep 28, 2026
shobham-nv
approved these changes
Sep 28, 2026
apartha-nv
merged commit Sep 28, 2026
7a5e56f
into
release-src/compute-plane-services/nvca/v3.2
18 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
nvca,nvca-operator, andcluster-validator3.2.25images all fail the nSpect LaunchAPIcontainer-oss-vulns-out-of-slagate with an identical9count.govulncheckshows 0 code-reachable Go vulnerabilities (post fix(nvca): bump grpc to remediate container OSS vuln SLA failures on v3.2 #2118 grpc bump).trivy, scanning thedistroless/go:v4.0.8base image SBOM against Debian's own vendor security tracker, also shows 0 vulnerabilities across all 9 packages.cluster-validator, which doesn't usegrpc), this points to the shared base OS layer — most likely raw-NVD version matching flagging Debian backport patches (+deb13uN) that vendor-aware scanners already treat as fixed.Change
distroless_gobase image pin fromv4.0.8→v4.1.4(latest, same family). Picks up newerlibc6,libssl3t64/openssl-provider-fips, andtzdatapatch versions, which may shift past whatever version nSpect's NVD matcher is keying on.trivyscan of thev4.1.4SBOM also reports 0 vulnerabilities.Test plan
bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator}succeeds