Skip to content

[sec-check] fix: checksum-verify zig download; digest-pin lib-c-docs base images - #42

Merged
hanthor-hive-agent[bot] merged 1 commit into
ptyxis-portfrom
sec/fix/dockerfile-harden
Sep 5, 2026
Merged

hanthor-hive-agent[bot] merged 1 commit into
ptyxis-portfrom
sec/fix/dockerfile-harden

Conversation

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

Security Fix

Two supply-chain issues in the build Dockerfiles:

1. Unverified Zig toolchain download (blueshell#41)

src/build/docker/debian/Dockerfile (used by test.yml's docker build) downloaded Zig with curl -L and no SHA256 check. A tampered mirror/CDN or compromised ziglang.org release substitutes arbitrary code into the CI build image. Now verified fail-closed against the shasums published in ziglang.org/download/index.json for 0.15.2, per architecture (x86_64 + aarch64), with an explicit unsupported-arch error.

2. Mutable base images (blueshell#28)

src/build/docker/lib-c-docs/Dockerfile: archlinux:latest (rolling release) and nginx:alpine (floating tag) — the same commit could build different images, and a bad :latest push silently changes what ships. Both now digest-pinned (resolved against Docker Hub 2026-08-24; lib-c-docs builds are amd64-pinned so single-arch digests are correct).

Verification: Dockerfile contents assert-correct; digests resolved live from the registries.

Refs #41, Refs #28


Filed by sec-check agent (ACMM L6 — full mode)

— hive: agent=sec-check backend=pi model=deepseek-v4-flash

…base images

Two supply-chain issues in the build Dockerfiles:

1. src/build/docker/debian/Dockerfile (used by test.yml docker build):
   the Zig toolchain was downloaded with curl -L and NO SHA256 check.
   A tampered mirror/CDN or compromised ziglang.org release substitutes
   arbitrary code into the CI build image. Now verified against the
   shasums published in ziglang.org/download/index.json for this version
   and architecture (x86_64 + aarch64), fail-closed (blueshell#41).

2. src/build/docker/lib-c-docs/Dockerfile: archlinux:latest (rolling) and
   nginx:alpine (floating) mutable bases — same commit could build
   different images, and a bad :latest push silently changes what ships.
   Now digest-pinned (blueshell#28).

Refs #41, Refs #28

Signed-off-by: hanthor-hive-agent[bot] <290068839+hanthor-hive-agent[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants