Skip to content

Generate CycloneDX SBOM with Conan deployer - #845

Open
mcc0nnell wants to merge 13 commits into
apache:masterfrom
mcc0nnell:feat/sbom-conan-deployer
Open

mcc0nnell wants to merge 13 commits into
apache:masterfrom
mcc0nnell:feat/sbom-conan-deployer

Conversation

@mcc0nnell

@mcc0nnell mcc0nnell commented Aug 27, 2026 •

Copy link
Copy Markdown

Fixes #824.

This supersedes #844 and incorporates the review feedback from @PengZheng and @pnoltes.

The change keeps SBOM generation in the existing Conan CI and uses Conan’s built-in cyclone_1.6 deployer. It also adds a committed Conan lockfile as a reproducible safe-default dependency baseline, while preserving the ability for downstream Celix users to select or override their own dependencies.

The safe-default lockfile is intentionally stored at:

conan/safe-defaults.lock

rather than as a root-level conan.lock. Conan automatically discovers a root conan.lock, which would implicitly constrain unrelated Celix builds. Keeping it at an explicit path makes use of the baseline opt-in.

For the Linux/GCC/Release configuration, CI generates the CycloneDX 1.6 SBOM with:

conan install .
--lockfile=conan/safe-defaults.lock
--deployer=cyclone_1.6
--deployer-folder=sbom
-b missing
-pr:b default
-pr:h default
-s:h build_type=Release
-o celix/:build_all=True
-o celix/
:celix_cxx17=True
-o mosquitto/*:broker=True
-o *:shared=True

CI publishes both:

  • conan/safe-defaults.lock
  • sbom/sbom-cyclonedx-1.6.json

together as the celix-conan-safe-defaults artifact.

The lockfile records the exact Conan recipe revisions used for this documented baseline. It is not intended to be repository-wide dependency policy: applications remain free to build without it, override dependency versions, or maintain their own lockfile and matching SBOM.

Documentation has also been added explaining the baseline, its scope, how CI generates the SBOM, and how users can opt into the same dependency graph locally.

Validation

  • Uses Conan’s built-in CycloneDX 1.6 deployer; no custom SBOM generator.
  • Uses a lockfile generated from the canonical Linux/GCC/Release full-feature Conan graph.
  • The lockfile and SBOM describe the same resolved dependency baseline.
  • Ordinary Celix builds do not implicitly consume the safe-default lockfile.
  • Different platforms, build options, and downstream dependency overrides remain supported.
  • SBOM guidance is linked from the main Celix documentation.

@PengZheng PengZheng left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would like to invite @pnoltes to have a look.

Comment thread .github/workflows/conan_create.yml Outdated
CXX: ${{ matrix.compiler[1] }}
run: |
conan create . -c tools.cmake.cmaketoolchain:generator=Ninja -b missing -o celix/*:build_all=True -o celix/*:enable_ccache=True -pr:b default -pr:h default -s:h build_type=${{ matrix.type }} -o celix/*:celix_cxx17=True -o celix/*:celix_install_deprecated_api=True -o mosquitto/*:broker=True -o *:shared=True
- name: Generate CycloneDX SBOM

@PengZheng PengZheng Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure whether conan_create.yml is the right place to add SBOM support, since a conan package is just a recipe to cook, not the final binary package and SBOM only makes sense for binary package.

For example, I can use --require-override conan option when building Celix to upgrade openssl to fix a security vulnerability without modifying either Celix or the Celix conan reciple. And in this case both SBOM and the final binary artifact will change

conan install . -o celix/*:build_all=True --deployer=cyclone_1.6 --deployer-folder=sbom -b missing -o *:shared=True
- name: Upload CycloneDX SBOM
if: matrix.compiler[0] == 'gcc'
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2

@PengZheng PengZheng Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To my understanding, SBOM should be used with the final binary, thus uploading SBOM alone makes no sense.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the SBOM to scan the resolved dependencies for vulnerabilities, as described in a separate follow-up ticket: [#825](#825).

Then we at least know which vulnerabilities exist in the dependencies selected by the current default resolution. However, I am not sure how useful this is without a conan.lock file. With a lockfile, the Celix sources would include a reproducible, resolved dependency list.

Maybe we could generate the lockfile for a GCC Linux build on Ubuntu with build_all=True and use it as our canonical dependency reference. It could then serve as the basis for future vulnerability scans and help ensure more reproducible builds. (and we should document the intended use for a the lockfile and explain that celix is useable without a lockfile).

@PengZheng, maybe we should introduce such a lockfile. WDYT?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the SBOM to scan the resolved dependencies for vulnerabilities, as described in a separate follow-up ticket: [#825](#825).

This can be done with Conan Audit. We can use it to generate vulnerabilities reports so that we can update Celix dependencies promptly to provide our users with safe defaults.

maybe we should introduce such a lockfile. WDYT?

Both SBOM and lockfile are associated with a specific set of dependencies/options, and our users have freedom to change them at their will. IMHO, providing them a safe defaults should be enough for now.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Both SBOM and lockfile are associated with a specific set of dependencies/options, and our users have freedom to change them at their will. IMHO, providing them a safe defaults should be enough for now.

To ensure we are the same page, do you mean that

a) we should not configure a lock file in our source control

or

b) we can provide a lock file and sbom, but we should communicate that this is a safe defaults, and users have to freedom to change the dependency versions when needed.

I think I prefer option b, but then also document this more clearly (lock file exists for safe defaults, and help in reproducible builds during development)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think I prefer option b, but then also document this more clearly (lock file exists for safe defaults, and help in reproducible builds during development)

I agree.

@mcc0nnell
mcc0nnell force-pushed the feat/sbom-conan-deployer branch from e87d52d to e0107b1 Compare August 28, 2026 02:51
@mcc0nnell

Copy link
Copy Markdown
Author

Thanks, this makes sense. I’ve updated the PR so the SBOM is now tied to the concrete Conan binary package rather than generated independently from the recipe.

The GCC job first creates celix/3.0.0, then consumes that package with the same settings/options and runs full_deploy and cyclone_1.6 in the same dependency-graph resolution. The publication step uses -b never so it cannot silently rebuild a different configuration.

CI now uploads the deployed binary packages and the matching CycloneDX SBOM together as a single artifact.

This should address the concern about dependency overrides changing the binary/SBOM relationship. Please let me know if you’d prefer a different packaging boundary.

@PengZheng

PengZheng commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

The action you modified is only for testing. We don't use it to release anything and SBOM generation should be added to the binary release process.

And I just noticed that we do not make any binary release.

@pnoltes
pnoltes self-requested a review August 28, 2026 08:36
@pnoltes

pnoltes commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

The action you modified is only for testing. We don't use it to release anything and SBOM generation should be added to the binary release process.

And I just noticed that we do not make any binary release.

What I have always understood is that ASF releases are primarily source releases, which is also what we do. Especially for Apache Celix, I expect a source release to be more useful because Celix is a framework rather than an end product. I personally see little value in installing a celix executable. The Celix libraries, bundles, and CMake files can of course be installed and used by downstream projects, but I am not sure whether we should provide and maintain an official binary distribution ourselves (small team).

@pnoltes

pnoltes commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

The action you modified is only for testing. We don't use it to release anything and SBOM generation should be added to the binary release process.
And I just noticed that we do not make any binary release.

What I have always understood is that ASF releases are primarily source releases, which is also what we do. Especially for Apache Celix, I expect a source release to be more useful because Celix is a framework rather than an end product. I personally see little value in installing a celix executable. The Celix libraries, bundles, and CMake files can of course be installed and used by downstream projects, but I am not sure whether we should provide and maintain an official binary distribution ourselves (small team).

What I do see as a possibility - and we already do this a bit - is that we provide and push an Apache Celix dev container so that users can more quickly build applications using Apache Celix.

Comment thread documents/building/sbom.md Outdated
Comment on lines +24 to +32
Apache Celix provides a committed `conan.lock` and a matching CycloneDX 1.6
SBOM for one documented Conan configuration. Together they provide a
reproducible **safe-default dependency baseline** for development and
vulnerability review.

The lockfile is not a repository-wide dependency mandate. Celix users remain
free to build without the lockfile, override dependency versions, or maintain a
lockfile for their own application configuration. When those inputs change,
the resulting dependency graph and SBOM can change as well.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 nice addition

@pnoltes pnoltes left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall LGTM, only thing left - IMO - is applying the lockfile in the rest of the conan CI builds.

run: |
rm -rf sbom
conan install . \
--lockfile=conan/safe-defaults.lock \

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we also need to use the lockfile for the conan create command. To ensure that both commands use the same deps (and do not build libs twice).

I also think we should use the lock file in the rest of the conan builds. This ensures that the CI builds are reproducible, including upstream dependencies.

Apply the committed dependency baseline to every dependency-resolving Conan CI build. Expand the lockfile to cover CI-only test/build requirements and macOS-specific dependencies, while keeping the published SBOM scoped to the documented Linux/GCC/Release graph.

Signed-off-by: Robert McConnell <robert@mcc0nnell.org>
@mcc0nnell

Copy link
Copy Markdown
Author

Addressed the remaining lockfile request in ca060752b.

All dependency-resolving Conan CI commands now use conan/safe-defaults.lock, including the regular Ubuntu/macOS builds, coverage, fuzzing, containers, conan create, and the dependency-deduction builds.

While validating this, I found the original Linux/GCC/Release lock was not sufficient for the full CI matrix: testing adds gtest/benchmark/ccache dependencies, and macOS adds gettext/libgettext. I expanded the committed lockfile to the union of the supported CI recipe revisions, while keeping the published CycloneDX SBOM explicitly scoped to the documented Linux/GCC/Release graph.

Validation covered Linux GCC, Linux Clang, Debug/RelWithDebInfo, fuzzing, and a macOS-resolved graph. YAML parses cleanly and every Conan build, create, and install invocation in the workflows now has the explicit lockfile.

@pnoltes pnoltes left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sorry for the delayed review, I did not notice this PR was updated.

LGTM, if possible I want 2 approvals before I merge (so 1 approval left).

@PengZheng PengZheng left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I apologize for this very late -1

Ubuntu regularly provides safety upgrades so that our normal Ubuntu build (via apt) is generally safe. However, using lockfile this way prevents automatic software update, and we will be forced to update the lockfile frequently to provide safe defaults, which seems an unnecessary burden. Considering SBOM only takes one Conan command to generate, I think we'd better leave it to the downstream users.

I do think we can proactively audit our dependencies in our CI. After setting up an audit provider properly, a single command will provide very informative report like the following:

conan audit scan . -o celix/*:build_all=True

*****************
* autoconf/2.71 *
*****************

No vulnerabilities found.


*******************
* automake/1.16.5 *
*******************

No vulnerabilities found.


***************
* bzip2/1.0.8 *
***************

No vulnerabilities found.


*****************
* civetweb/1.16 *
*****************

2 vulnerabilities found:

- CVE-2025-55763 (Severity: High - 7.5)

  Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows
  a remote attacker to achieve remote code execution via a crafted HTTP request.
  This vulnerability is triggered during request processing and may allow an
  attack...
  Published at: 2025-08-29T17:15:35.790Z
  url: https://github.com/civetweb/civetweb
  CVSS v3: 7.5

- CVE-2026-5789 (Severity: High - 7.8)

  Vulnerability related to an unquoted search path in CivetWeb v1.16. This
  vulnerability allows a local attacker to execute arbitrary code with elevated
  privileges by placing a malicious executable in a directory that is scanned
  before the in...
  Published at: 2026-04-21T15:16:37.713Z
  url: https://www.incibe.es/en/incibe-cert/notices/aviso/search-path-without-quotes-civetweb
  CVSS v3: 7.8
  CVSS v4: 8.5


****************
* cmake/3.31.5 *
****************

No vulnerabilities found.


***************
* cmake/4.2.3 *
***************

No vulnerabilities found.


***************************
* gnu-config/cci.20210814 *
***************************

No vulnerabilities found.


****************
* jansson/2.14 *
****************

No vulnerabilities found.


******************
* libcurl/8.18.0 *
******************

38 vulnerabilities found:

- CVE-2026-10536 (Severity: Critical - 9.8)

  A use-after-free vulnerability exists in libcurl when an application configures
  an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
  `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and
  finally terminates th...
  Published at: 2026-06-24T13:21:28.641Z
  url: https://packages.mini.dev/advisories/osv/MINI-x888-fhwf-c2pr.json
  CVSS v3: 9.8

- CVE-2026-11564 (Severity: Critical - 9.1)

  libcurl keeps previously used connections in a connection pool for subsequent
  transfers to reuse if one of them matches the setup.  An easy handle that first
  uses default native CA trust can continue trusting the native platform store
  after...
  Published at: 2026-07-03T07:16:23.790Z
  url: https://curl.se/docs/CVE-2026-11564.html
  CVSS v3: 9.1

- CVE-2026-9079 (Severity: Critical - 9.8)

  libcurl had a flaw that when instructed to clear proxy authentication
  credentials which made it not do so, leaving the old credentials around to get
  used for subsequent transfers that should not know nor use them.
  Published at: 2026-07-03T07:16:25.620Z
  url: https://curl.se/docs/CVE-2026-9079.html
  CVSS v3: 9.8

- CVE-2026-11856 (Severity: Critical - 9.8)

  Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`)
  with **Digest** authentication and then changing the origin to a different one
  (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly
  p...
  Published at: 2026-06-24T13:21:28.641Z
  url: https://curl.se/docs/CVE-2026-11856.html
  CVSS v3: 9.8

- CVE-2026-8924 (Severity: Critical - 9.1)

  A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
  "super cookies" that bypass the Public Suffix List check. This enables an
  attacker-controlled origin to inject cookies that curl subsequently scopes and
  transmits t...
  Published at: 2026-06-24T13:21:28.641Z
  url: https://curl.se/docs/CVE-2026-8924.html
  CVSS v3: 9.1

- CVE-2026-8925 (Severity: Critical - 9.8)

  The curl logic that works with SASL authentication could end up cleaning up the
  GSASL context *twice* without clearing the pointer in between, making it
  `free()` the same pointer twice.
  Published at: 2026-07-03T00:28:26.379Z
  url: https://packages.mini.dev/advisories/osv/MINI-jv59-c3j7-jf8g.json
  CVSS v3: 9.8

- CVE-2026-8926 (Severity: Critical - 9.1)

  When asking curl to use a `.netrc` file to find credentials and at the same
  time specifying a URL with a username (without a password), like
  `https://user@example.com/`, curl could wrongly get and use the password for
  *another* user set in ...
  Published at: 2026-07-03T07:16:25.037Z
  url: https://packages.mini.dev/advisories/osv/MINI-g2pr-94gx-xcqv.json
  CVSS v3: 9.1

- CVE-2026-8927 (Severity: Critical - 9.1)

  When reusing a libcurl handle for sequential transfers driven by
  environment-variable proxy configuration, libcurl fails to clear the proxy
  authentication state between requests. Specifically, if the initial transfer
  authenticates against `...
  Published at: 2026-06-24T13:21:28.641Z
  url: https://packages.mini.dev/advisories/osv/MINI-vchr-vcfj-27qv.json
  CVSS v3: 9.1

- CVE-2026-18924 (Severity: Critical - 9.1)

  A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
  handle is set to share connections with other handles, can lead to
  use-after-free in the cleanup process.
  Published at: 2026-09-02T12:59:06.983Z
  url: https://packages.mini.dev/advisories/osv/MINI-7922-6q99-fj92.json
  CVSS v3: 9.1

- CVE-2026-19931 (Severity: Critical - 9.8)

  A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
  hostname using Negotiate authentication, when the initial request is done using
  empty credentials. This can make user B's request get sent over user A's
  previousl...
  Published at: 2026-09-02T12:58:50.880Z
  url: https://curl.se/docs/CVE-2026-19931.html
  CVSS v3: 9.8

- CVE-2026-3805 (Severity: High - 7.5)

  When doing a second SMB request to the same host again, curl would wrongly use
  a data pointer pointing into already freed memory.
  Published at: 2026-03-11T11:16:00.967Z
  url: https://curl.se/docs/CVE-2026-3805.html
  CVSS v3: 7.5

- CVE-2026-5773 (Severity: High - 7.5)

  libcurl might in some circumstances reuse the wrong connection for SMB(S)
  transfers.  libcurl features a pool of recent connections so that subsequent
  requests can reuse an existing connection to avoid overhead.  When reusing a
  connection a...
  Published at: 2026-04-30T09:00:17.094Z
  url: https://curl.se/docs/CVE-2026-5773.html
  CVSS v3: 7.5

- CVE-2026-6276 (Severity: High - 7.5)

  Using libcurl, when a custom `Host:` header is first set for an HTTP request
  and a second request is subsequently done using the same *easy handle* but
  without the custom `Host:` header set, the second request would use stale
  information an...
  Published at: 2026-04-30T09:00:14.630Z
  url: https://curl.se/docs/CVE-2026-6276.html
  CVSS v3: 7.5

- CVE-2026-9547 (Severity: High - 7.4)

  When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
  and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
  untrusted server. This vulnerability occurs when a server presents a host key
  type ...
  Published at: 2026-06-24T13:21:28.641Z
  url: https://curl.se/docs/CVE-2026-9547.html
  CVSS v3: 7.4

- CVE-2026-11352 (Severity: High - 7.5)

  An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
  to trigger a remote denial of service against a curl or libcurl client. Because
  the helper function discards zero-length UDP datagrams before counting them
  toward...
  Published at: 2026-07-03T07:16:23.693Z
  url: https://packages.mini.dev/advisories/osv/MINI-2gg7-7rv8-6535.json
  CVSS v3: 7.5

- CVE-2026-11586 (Severity: High - 7.5)

  By default, curl automatically responds to WebSocket PING frames. Because curl
  lacks an upper bound on memory allocation for unacknowledged frames, a
  malicious server can exhaust all available memory by flooding curl with rapid,
  sequential ...
  Published at: 2026-07-03T07:16:23.883Z
  url: https://curl.se/docs/CVE-2026-11586.html
  CVSS v3: 7.5

- CVE-2026-9080 (Severity: High - 7.3)

  Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`
  callback triggers a use-after-free vulnerability, where libcurl attempts to
  store a flag using a dangling struct pointer immediately after that pointer's
  memory ha...
  Published at: 2026-07-03T07:16:25.713Z
  url: https://curl.se/docs/CVE-2026-9080.html
  CVSS v3: 7.3

- CVE-2026-9545 (Severity: High - 7.5)

  In this scenario, libcurl first uses a proper HTTP/3 server for the initial
  transfers, and when it makes a second transfer to the same site it has been
  replaced by the attacker's impostor machine - without a valid certificate.
  When libcurl...
  Published at: 2026-07-03T07:16:25.807Z
  url: https://curl.se/docs/CVE-2026-9545.html
  CVSS v3: 7.5

- CVE-2026-9546 (Severity: High - 7.5)

  A vulnerability in libcurl caused the HTTP `Referer:` header to persist even
  when explicitly cleared. While the documentation states that passing NULL to
  `CURLOPT_REFERER` suppresses the header, the option failed to clear the
  internal state...
  Published at: 2026-07-03T07:16:25.893Z
  url: https://packages.mini.dev/advisories/osv/MINI-5c4h-6rhr-fr3h.json
  CVSS v3: 7.5

- CVE-2026-12064 (Severity: High - 7.5)

  When a user invokes curl using a schemeless URL combined with `--proto-default`
  sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool
  layer incorrectly infers the URL scheme, which erroneously bypasses the
  initiali...
  Published at: 2026-06-24T13:21:28.641Z
  url: https://packages.mini.dev/advisories/osv/MINI-57vg-25pp-5hq8.json
  CVSS v3: 7.5

- CVE-2026-8932 (Severity: High - 7.5)

  libcurl would reuse a previously created connection even when some mTLS config
  related option had been changed that should have prohibited reuse.  libcurl
  keeps previously used connections in a connection pool for subsequent transfers
  to re...
  Published at: 2026-06-24T13:21:28.641Z
  url: https://packages.mini.dev/advisories/osv/MINI-h432-768q-x77g.json
  CVSS v3: 7.5

- CVE-2026-8286 (Severity: High - 8.1)

  A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
  connection might reuse an existing live connection even though the TLS
  configuration mismatches so it should not.
  Published at: 2026-06-24T13:21:28.641Z
  url: https://curl.se/docs/CVE-2026-8286.html
  CVSS v3: 8.1

- CVE-2026-80229 (Severity: High - 7.5)

  When performing transfers via libcurl’s multi interface, pooled TLS connections
  can outlive their originating easy handles. In OpenSSL 3 provider
  configurations, libcurl attaches an allocated library context to the easy
  handle's state and p...
  Published at: 2026-09-06T18:17:22.217Z
  url: https://packages.mini.dev/advisories/osv/MINI-v8f5-wmg2-5c7w.json
  CVSS v3: 7.5

- CVE-2026-80230 (Severity: High - 7.5)

  When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
  standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
  `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
  connections established w...
  Published at: 2026-09-02T12:58:26.025Z
  url: https://packages.mini.dev/advisories/osv/MINI-m5pm-rhcc-h328.json
  CVSS v3: 7.5

- CVE-2026-80231 (Severity: High - 7.5)

  A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for
  a given hostname even when using a different Native CA Store setting
  (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.
  Published at: 2026-09-06T18:17:22.500Z
  url: https://curl.se/docs/CVE-2026-80231.html
  CVSS v3: 7.5

- CVE-2026-80255 (Severity: High - 7.5)

  A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of
  space (ascii code 32) immediately before the `Secure` attribute causes curl to
  store the cookie without its Secure flag. The cookie might then wrongfully be
  sent ove...
  Published at: 2026-09-06T18:17:22.623Z
  url: https://packages.mini.dev/advisories/osv/MINI-xg5x-26hr-hmrw.json
  CVSS v3: 7.5

- CVE-2026-82208 (Severity: High - 7.5)

  With the wolfSSL backend, when CA caching is enabled and an
  `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can
  silently reinstall the cached store after the callback returns. A certificate
  trusted by the cached store ...
  Published at: 2026-09-06T18:17:22.733Z
  url: https://packages.mini.dev/advisories/osv/MINI-f22w-p2ff-926p.json
  CVSS v3: 7.5

- CVE-2026-82209 (Severity: High - 8.2)

  When libpsl support is enabled, libcurl fails to enforce the Public Suffix List
  boundary check when processing a `Set-Cookie` header where the `Domain`
  attribute explicitly matches an origin host that is itself a public suffix
  (e.g., `Domai...
  Published at: 2026-09-02T12:58:44.938Z
  url: https://curl.se/docs/CVE-2026-82209.html
  CVSS v3: 8.2

- CVE-2026-13608 (Severity: High - 7.4)

  A flaw in the libcurl SASL negotiation for LDAP authentication allows an
  incomplete handshake sequence to be misinterpreted as a successful
  cryptographic verification. An attacker executing a Man-in-the-Middle (MITM)
  attack can inject a pre...
  Published at: 2026-09-02T10:09:44.382Z
  url: https://packages.mini.dev/advisories/osv/MINI-9p79-634m-v44m.json
  CVSS v3: 7.4

- CVE-2026-3783 (Severity: Medium - 5.3)

  When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
  performs a redirect to a second URL, curl could leak that token to the second
  hostname under some circumstances.  If the hostname that the first request is
  redir...
  Published at: 2026-03-11T11:16:00.080Z
  url: https://curl.se/docs/CVE-2026-3783.html
  CVSS v3: 5.3

- CVE-2026-1965 (Severity: Medium - 6.5)

  libcurl can in some circumstances reuse the wrong connection when asked to do
  an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of
  recent connections so that subsequent requests can reuse an existing connection
  to a...
  Published at: 2026-03-11T11:15:59.177Z
  url: https://curl.se/docs/CVE-2026-1965.html
  CVSS v3: 6.5

- CVE-2026-5545 (Severity: Medium - 6.5)

  libcurl might in some circumstances reuse the wrong connection when asked to do
  an authenticated HTTP(S) request after a Negotiate-authenticated one, when both
  use the same host.  libcurl features a pool of recent connections so that
  subseq...
  Published at: 2026-04-30T09:00:30.550Z
  url: https://curl.se/docs/CVE-2026-5545.html
  CVSS v3: 6.5

- CVE-2026-4873 (Severity: Medium - 5.9)

  A vulnerability exists where a connection requiring TLS incorrectly reuses an
  existing unencrypted connection from the same connection pool. If an initial
  transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request
  to tha...
  Published at: 2026-04-30T09:00:23.009Z
  url: https://packages.mini.dev/advisories/osv/MINI-749q-8cfx-fw4g.json
  CVSS v3: 5.9

- CVE-2026-7009 (Severity: Medium - 5.3)

  When curl is told to use the Certificate Status Request TLS extension, often
  referred to as *OCSP stapling*, to verify that the server certificate is valid,
  it fails to detect OCSP problems and instead wrongly consider the response as
  fine.
  Published at: 2026-05-13T13:01:57.100Z
  url: https://packages.mini.dev/advisories/osv/MINI-fwf3-39q9-6r2m.json
  CVSS v3: 5.3

- CVE-2026-7168 (Severity: Medium - 5.3)

  Successfully using libcurl to do a transfer over a specific HTTP proxy
  (`proxyA`) with **Digest** authentication and then changing the proxy host to a
  second one (`proxyB`) for a second transfer, reusing the same handle, makes
  libcurl wrong...
  Published at: 2026-04-30T09:00:37.280Z
  url: https://curl.se/docs/CVE-2026-7168.html
  CVSS v3: 5.3

- CVE-2026-6253 (Severity: Medium - 5.9)

  curl might erroneously pass on credentials for a first proxy to a second proxy.
  This can happen when the following conditions are true:  1. curl is setup to
  use specific different proxies for different URL schemes 2. the first proxy
  needs ...
  Published at: 2026-04-30T09:00:08.995Z
  url: https://curl.se/docs/CVE-2026-6253.html
  CVSS v3: 5.9

- CVE-2026-6429 (Severity: Medium - 5.3)

  When asked to both use a `.netrc` file for credentials and to follow HTTP
  redirects, libcurl could leak the password used for the first host to the
  followed-to host under certain circumstances.
  Published at: 2026-04-30T09:00:05.746Z
  url: https://curl.se/docs/CVE-2026-6429.html
  CVSS v3: 5.3

- CVE-2026-8458 (Severity: Medium - 6.5)

  libcurl might in some circumstances reuse the wrong connection when asked to do
  Negotiate-authenticated ones, even when they are set to use different
  "services".  libcurl features a pool of recent connections so that subsequent
  requests can...
  Published at: 2026-06-24T13:21:28.641Z
  url: https://packages.mini.dev/advisories/osv/MINI-93g8-4h65-f27c.json
  CVSS v3: 6.5


****************
* libffi/3.4.8 *
****************

No vulnerabilities found.


*****************
* libiconv/1.17 *
*****************

No vulnerabilities found.


*****************
* libtool/2.4.7 *
*****************

No vulnerabilities found.


****************
* libuv/1.51.0 *
****************

No vulnerabilities found.


******************
* libxml2/2.15.1 *
******************

No vulnerabilities found.


*****************
* libzip/1.11.4 *
*****************

No vulnerabilities found.


*************
* m4/1.4.19 *
*************

No vulnerabilities found.


****************************
* mdnsresponder/1310.140.1 *
****************************

No vulnerabilities found.


****************
* meson/1.10.1 *
****************

No vulnerabilities found.


********************
* mosquitto/2.0.22 *
********************

No vulnerabilities found.


****************
* ninja/1.13.2 *
****************

No vulnerabilities found.


*****************
* openssl/3.6.3 *
*****************

11 vulnerabilities found:

- CVE-2026-75803 (Severity: Critical - 9.1)

  Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty
  ciphertext can report success without verifying the supplied authentication tag
  when the operation is finalized by calling the EVP_Cipher() function.  Impact
  summary: App...
  Published at: 2026-08-20T16:06:08.983Z
  url: https://packages.mini.dev/advisories/osv/MINI-44jf-8phr-j393.json
  CVSS v3: 9.1

- CVE-2026-63073 (Severity: Critical - 9.8)

  Issue summary: OpenSSL CMP response validation passed an unexpected response
  sender distinguished name directly as the format string to `ERR_raise_data()`.
  Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client
  that...
  Published at: 2026-08-25T11:36:16.000Z
  url: https://packages.mini.dev/advisories/osv/MINI-f4vr-f483-hr9j.json
  CVSS v3: 9.8

- CVE-2026-54876 (Severity: High - 7.5)

  Issue summary: A malicious TLS server can cause a memory leak in a TLS client
  that has enabled OCSP response checking by sending an OCSP response that
  contains no single response entries.  Impact summary: An attacker can leak an
  attacker-tu...
  Published at: 2026-08-05T11:43:00.000Z
  url: https://github.com/openssl/openssl/commit/155b5fe0f93365e6df1c56ee3606b121080c6c12
  CVSS v3: 7.5

- CVE-2026-14456 (Severity: High - 7.5)

  Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes
  valid QUIC Initial packets for unknown destination connection IDs, it can
  allocate and queue new incoming channels without enforcing any limit.  Impact
  summary: A re...
  Published at: 2026-08-13T07:00:13.000Z
  url: https://advisory.echohq.com/cve/CVE-2026-14456
  CVSS v3: 7.5

- CVE-2026-14457 (Severity: High - 7.5)

  Issue summary: In a server or client configuration with RFC7250 Raw Public Keys
  (RPKs) enabled, and only the private key (with no associated certificate)
  configured locally, a NULL pointer dereference may occur when the remote peer
  solicits...
  Published at: 2026-08-25T11:36:16.000Z
  url: https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76
  CVSS v3: 7.5

- CVE-2026-63075 (Severity: High - 7.5)

  Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly
  sends ack-eliciting packets while not acknowledging ACK-only responses, the
  QUIC stack can retain ACK-only packet metadata for the lifetime of the
  connection.  I...
  Published at: 2026-08-25T11:36:16.000Z
  url: https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc
  CVSS v3: 7.5

- CVE-2026-63076 (Severity: High - 7.5)

  Issue summary: OpenSSL CMP password based protection verification only checks
  whether the protectionAlg parameter was not NULL and not its ASN.1 type, before
  treating it as a PBMParameter. A crafted message can contain a parameter of a
  diff...
  Published at: 2026-08-25T11:36:16.000Z
  url: https://packages.mini.dev/advisories/osv/MINI-75v6-2r53-m3x8.json
  CVSS v3: 7.5

- CVE-2026-18798 (Severity: High - 7.5)

  Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
  when channel creation fails for initial packet.  Impact summary: Double free
  leads to heap corruption, which typically results in  termination of QUIC
  server proce...
  Published at: 2026-08-25T11:36:16.000Z
  url: https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af
  CVSS v3: 7.5

- CVE-2026-54874 (Severity: High - 7.5)

  Issue summary: Receiving a DTLS record for a future epoch while a handshake is
  in progress causes OpenSSL to buffer far more memory than the record itself
  requires.  Impact summary: A peer can use a small amount of network traffic to
  make a...
  Published at: 2026-08-25T11:36:16.000Z
  url: https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40
  CVSS v3: 7.5

- CVE-2026-63072 (Severity: High - 7.5)

  Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based
  on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can
  write and cleanse more bytes than that query reports, causing an 8-byte
  out-of-boun...
  Published at: 2026-08-25T11:36:16.000Z
  url: https://advisory.echohq.com/cve/CVE-2026-63072
  CVSS v3: 7.5

- CVE-2026-63074 (Severity: Medium - 5.9)

  Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches
  additional certificates (extraCerts) sent in a CMP message, but never expunges
  them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX
  frequently, ...
  Published at: 2026-08-25T11:36:16.000Z
  url: https://advisory.echohq.com/cve/CVE-2026-63074
  CVSS v3: 5.9


*****************
* pkgconf/2.5.1 *
*****************

No vulnerabilities found.


**************************
* rapidjson/cci.20250205 *
**************************

No vulnerabilities found.


*****************************
* util-linux-libuuid/2.41.2 *
*****************************

2 vulnerabilities found:

- CVE-2026-27456 (Severity: Medium - 4.7)

 A TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been
  identified in the SUID binary /usr/bin/mount from util-linux. This finding was
 The mounted by researcher Julio Ángel Ferrari Medina (Aka. T0X1Cx).
  binary, w...
  Published at: 2026-04-01T09:43:13.000Z
  url: https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4
  CVSS v3: 4.7

- CVE-2026-13595 (Severity: Medium - 5.3)

  A flaw was found in the libblkid library of util-linux. During nested partition
  probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a
  raw pointer to a parent partition entry in a dynamically allocated array. When
  subs...
  Published at: 2026-05-07T00:00:00.000Z
  url: https://access.redhat.com/errata/RHSA-2026:26573
  CVSS v3: 5.3


******************
* xz_utils/5.8.1 *
******************

1 vulnerability found:

- CVE-2026-34743 (Severity: Medium - 5.3)

  If lzma_index_decoder() was used to decode an Index that contained no Records,
  the resulting lzma_index was left in a state where where a subsequent
  lzma_index_append() would allocate too little memory, and a buffer overflow
...ould occur.
  Published at: 2026-03-31T16:46:31.000Z
  url: https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87
  CVSS v3: 5.3
  CVSS v4: 1.7


**************
* zlib/1.3.1 *
**************

3 vulnerabilities found:

- CVE-2026-22184 (Severity: High - 7.8)

  zlib versions up to and including 1.3.1.2 include a global buffer overflow in
  the untgz utility located under contrib/untgz. The vulnerability is limited to
  the standalone demonstration utility and does not affect the core zlib
  compression ...
  Published at: 2026-01-07T21:16:01.563Z
  url: https://github.com/madler/zlib
  CVSS v3: 7.8
  CVSS v4: 4.6

- CVE-2026-85091 (Severity: High - 7.4)

  zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow
  vulnerability in the gz_vacate() function when processing non-blocking
  gzwrite() operations with stale external buffer pointers. Attackers can trigger
  the overflow by callin...
  Published at: 2026-09-02T00:00:00.000Z
  url: https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490
  CVSS v3: 7.4
  CVSS v4: 8.3

- CVE-2026-27171 (Severity: Medium - 5.5)

  zlib before 1.3.2 allows CPU consumption via crc32_combine64 and
  crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has
  no termination condition.
  Published at: 2026-02-18T04:16:01.263Z
  url: https://packages.mini.dev/advisories/osv/MINI-hwjj-mj9h-qh5g.json
  CVSS v3: 5.5


**************
* zstd/1.5.7 *
**************

No vulnerabilities found.

Total vulnerabilities found: 57


Summary:

- civetweb/1.16 2 vulnerabilities found
- libcurl/8.18.0 38 vulnerabilities found
- openssl/3.6.3 11 vulnerabilities found
- util-linux-libuuid/2.41.2 2 vulnerabilities found
- xz_utils/5.8.1 1 vulnerability found
- zlib/1.3.1 3 vulnerabilities found

If you are using packages from Conan Center, some vulnerabilities may have already been mitigated through patches applied in the recipe.
To verify if a patch has been applied, check the recipe in Conan Center.


Vulnerability information provided by JFrog Catalog. Check https://conan.io/audit/jfrogcuration for more information.

You can send questions and report issues about the returned vulnerabilities to conan-research@jfrog.com.

ERROR: The package openssl/3.6.3 has a CVSS score 9.1 and exceeded the threshold severity level 9.0.

@pnoltes

pnoltes commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Ubuntu regularly provides safety upgrades so that our normal Ubuntu build (via apt) is generally safe. However, using lockfile this way prevents automatic software update, and we will be forced to update the lockfile frequently to provide safe defaults, which seems an unnecessary burden. Considering SBOM only takes one Conan command to generate, I think we'd better leave it to the downstream users.

I do think we can proactively audit our dependencies in our CI. After setting up an audit provider properly, a single command will provide very informative report like the following:

I am struggling a bit with this. With our current setup, we do provide a conanfile.py (which also includes some version/version-range restrictions), and you can build Celix with Ubuntu packages.

I can understand that we say/document something like: "The latest Ubuntu packages from the LTS used in Apache Celix are our reference for monitoring upstream vulnerabilities. Usage of Conan is also possible, but it is up to the user to resolve/select the final dependency versions." And maybe document how you can run a conan audit scan. In this case, I would expect that, if we do something with SBOM generation and vulnerability scanning, we do it based on the APT-based CI builds.

Alternatively, we could make Conan and Conan package version resolution our reference and use a lockfile. I think it is also Ok to update the lockfile more frequently, and at the same time a lockfile could help during heavy development to prevent too many dependency changes between builds.

I am a bit worried about the maintenance burden once we have more insight into upstream vulnerabilities. So I am not sure what the best approach is. From a "minimize the burden" perspective, I think it would be better to follow the APT package approach and rely on Canonical LTS security maintenance, instead of depending on multiple Conan Center recipes and therefore multiple maintainers. Maybe something with syft is possible and then scanning the CI build dir.

For me, the main question is therefore which dependency ecosystem we want to treat as the reference security baseline for Apache Celix.

@PengZheng

PengZheng commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

I am struggling a bit with this.

So am I.

I can understand that we say/document something like: "The latest Ubuntu packages from the LTS used in Apache Celix are our reference for monitoring upstream vulnerabilities. Usage of Conan is also possible, but it is up to the user to resolve/select the final dependency versions." And maybe document how you can run a conan audit scan. In this case, I would expect that, if we do something with SBOM generation and vulnerability scanning, we do it based on the APT-based CI builds.

We can do it for both Ubuntu and Conan builds, which provides our users clearer security status of these builds.
Except:

  • For Conan build, it is just a single command to generate SBOM and get audit report.
  • For Ubuntu build, some work is needed to generate SBOM, and more work for audit report.

A clickable link to these audit reports in README.md (as the codecov) will be very helpful.

Alternatively, we could make Conan and Conan package version resolution our reference and use a lockfile. I think it is also Ok to update the lockfile more frequently, and at the same time a lockfile could help during heavy development to prevent too many dependency changes between builds.

This is the classic usage of lockfile within any package management system. I think the security status when building with the latest available/usable version of dependencies will be more helpful to our users.

I am a bit worried about the maintenance burden once we have more insight into upstream vulnerabilities. So I am not sure what the best approach is. From a "minimize the burden" perspective, I think it would be better to follow the APT package approach and rely on Canonical LTS security maintenance, instead of depending on multiple Conan Center recipes and therefore multiple maintainers. Maybe something with syft is possible and then scanning the CI build dir.

When dealing with CRA requirements, Conan is a very powerful tool. In my day job, we have a private Conan deployment within the enterprise. It is not always possible to update to the latest upstream open source component to fix security issues. For example, projects as Civetweb are not actively maintained, or we must stick to a very old version like libcurl 7.x. We can rely on Ubuntu LTS or other Linux distributions' security patches to generate patched revision of such conan package. Then an ultimate downstream --require-override will fix security issues without touching any other components.

You can see when deploying Conan privately, both the upstream conan center and Ubuntu LTS are used as security references.

For me, the main question is therefore which dependency ecosystem we want to treat as the reference security baseline for Apache Celix.

We can spend most of efforts to get SBOM/audit work on Ubuntu LTS, and then provide easy access to audit reports for both Ubuntu and Conan build.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Generate an SBOM

3 participants