Conversation
| CXX: ${{ matrix.compiler[1] }} | ||
| run: | | ||
| conan create . -c tools.cmake.cmaketoolchain:generator=Ninja -b missing -o celix/*:build_all=True -o celix/*:enable_ccache=True -pr:b default -pr:h default -s:h build_type=${{ matrix.type }} -o celix/*:celix_cxx17=True -o celix/*:celix_install_deprecated_api=True -o mosquitto/*:broker=True -o *:shared=True | ||
| - name: Generate CycloneDX SBOM |
There was a problem hiding this comment.
I'm not sure whether conan_create.yml is the right place to add SBOM support, since a conan package is just a recipe to cook, not the final binary package and SBOM only makes sense for binary package.
For example, I can use --require-override conan option when building Celix to upgrade openssl to fix a security vulnerability without modifying either Celix or the Celix conan reciple. And in this case both SBOM and the final binary artifact will change
| conan install . -o celix/*:build_all=True --deployer=cyclone_1.6 --deployer-folder=sbom -b missing -o *:shared=True | ||
| - name: Upload CycloneDX SBOM | ||
| if: matrix.compiler[0] == 'gcc' | ||
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 |
There was a problem hiding this comment.
To my understanding, SBOM should be used with the final binary, thus uploading SBOM alone makes no sense.
There was a problem hiding this comment.
We can use the SBOM to scan the resolved dependencies for vulnerabilities, as described in a separate follow-up ticket: [#825](#825).
Then we at least know which vulnerabilities exist in the dependencies selected by the current default resolution. However, I am not sure how useful this is without a conan.lock file. With a lockfile, the Celix sources would include a reproducible, resolved dependency list.
Maybe we could generate the lockfile for a GCC Linux build on Ubuntu with build_all=True and use it as our canonical dependency reference. It could then serve as the basis for future vulnerability scans and help ensure more reproducible builds. (and we should document the intended use for a the lockfile and explain that celix is useable without a lockfile).
@PengZheng, maybe we should introduce such a lockfile. WDYT?
There was a problem hiding this comment.
We can use the SBOM to scan the resolved dependencies for vulnerabilities, as described in a separate follow-up ticket: [#825](#825).
This can be done with Conan Audit. We can use it to generate vulnerabilities reports so that we can update Celix dependencies promptly to provide our users with safe defaults.
maybe we should introduce such a lockfile. WDYT?
Both SBOM and lockfile are associated with a specific set of dependencies/options, and our users have freedom to change them at their will. IMHO, providing them a safe defaults should be enough for now.
There was a problem hiding this comment.
Both SBOM and lockfile are associated with a specific set of dependencies/options, and our users have freedom to change them at their will. IMHO, providing them a safe defaults should be enough for now.
To ensure we are the same page, do you mean that
a) we should not configure a lock file in our source control
or
b) we can provide a lock file and sbom, but we should communicate that this is a safe defaults, and users have to freedom to change the dependency versions when needed.
I think I prefer option b, but then also document this more clearly (lock file exists for safe defaults, and help in reproducible builds during development)
There was a problem hiding this comment.
I think I prefer option b, but then also document this more clearly (lock file exists for safe defaults, and help in reproducible builds during development)
I agree.
e87d52d to
e0107b1
Compare
|
Thanks, this makes sense. I’ve updated the PR so the SBOM is now tied to the concrete Conan binary package rather than generated independently from the recipe. The GCC job first creates celix/3.0.0, then consumes that package with the same settings/options and runs full_deploy and cyclone_1.6 in the same dependency-graph resolution. The publication step uses -b never so it cannot silently rebuild a different configuration. CI now uploads the deployed binary packages and the matching CycloneDX SBOM together as a single artifact. This should address the concern about dependency overrides changing the binary/SBOM relationship. Please let me know if you’d prefer a different packaging boundary. |
|
The action you modified is only for testing. We don't use it to release anything and SBOM generation should be added to the binary release process. And I just noticed that we do not make any binary release. |
What I have always understood is that ASF releases are primarily source releases, which is also what we do. Especially for Apache Celix, I expect a source release to be more useful because Celix is a framework rather than an end product. I personally see little value in installing a celix executable. The Celix libraries, bundles, and CMake files can of course be installed and used by downstream projects, but I am not sure whether we should provide and maintain an official binary distribution ourselves (small team). |
What I do see as a possibility - and we already do this a bit - is that we provide and push an Apache Celix dev container so that users can more quickly build applications using Apache Celix. |
| Apache Celix provides a committed `conan.lock` and a matching CycloneDX 1.6 | ||
| SBOM for one documented Conan configuration. Together they provide a | ||
| reproducible **safe-default dependency baseline** for development and | ||
| vulnerability review. | ||
|
|
||
| The lockfile is not a repository-wide dependency mandate. Celix users remain | ||
| free to build without the lockfile, override dependency versions, or maintain a | ||
| lockfile for their own application configuration. When those inputs change, | ||
| the resulting dependency graph and SBOM can change as well. |
pnoltes
left a comment
There was a problem hiding this comment.
Overall LGTM, only thing left - IMO - is applying the lockfile in the rest of the conan CI builds.
| run: | | ||
| rm -rf sbom | ||
| conan install . \ | ||
| --lockfile=conan/safe-defaults.lock \ |
There was a problem hiding this comment.
I think we also need to use the lockfile for the conan create command. To ensure that both commands use the same deps (and do not build libs twice).
I also think we should use the lock file in the rest of the conan builds. This ensures that the CI builds are reproducible, including upstream dependencies.
Apply the committed dependency baseline to every dependency-resolving Conan CI build. Expand the lockfile to cover CI-only test/build requirements and macOS-specific dependencies, while keeping the published SBOM scoped to the documented Linux/GCC/Release graph. Signed-off-by: Robert McConnell <robert@mcc0nnell.org>
|
Addressed the remaining lockfile request in All dependency-resolving Conan CI commands now use While validating this, I found the original Linux/GCC/Release lock was not sufficient for the full CI matrix: testing adds Validation covered Linux GCC, Linux Clang, Debug/RelWithDebInfo, fuzzing, and a macOS-resolved graph. YAML parses cleanly and every Conan |
pnoltes
left a comment
There was a problem hiding this comment.
sorry for the delayed review, I did not notice this PR was updated.
LGTM, if possible I want 2 approvals before I merge (so 1 approval left).
There was a problem hiding this comment.
I apologize for this very late -1
Ubuntu regularly provides safety upgrades so that our normal Ubuntu build (via apt) is generally safe. However, using lockfile this way prevents automatic software update, and we will be forced to update the lockfile frequently to provide safe defaults, which seems an unnecessary burden. Considering SBOM only takes one Conan command to generate, I think we'd better leave it to the downstream users.
I do think we can proactively audit our dependencies in our CI. After setting up an audit provider properly, a single command will provide very informative report like the following:
conan audit scan . -o celix/*:build_all=True
*****************
* autoconf/2.71 *
*****************
No vulnerabilities found.
*******************
* automake/1.16.5 *
*******************
No vulnerabilities found.
***************
* bzip2/1.0.8 *
***************
No vulnerabilities found.
*****************
* civetweb/1.16 *
*****************
2 vulnerabilities found:
- CVE-2025-55763 (Severity: High - 7.5)
Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows
a remote attacker to achieve remote code execution via a crafted HTTP request.
This vulnerability is triggered during request processing and may allow an
attack...
Published at: 2025-08-29T17:15:35.790Z
url: https://github.com/civetweb/civetweb
CVSS v3: 7.5
- CVE-2026-5789 (Severity: High - 7.8)
Vulnerability related to an unquoted search path in CivetWeb v1.16. This
vulnerability allows a local attacker to execute arbitrary code with elevated
privileges by placing a malicious executable in a directory that is scanned
before the in...
Published at: 2026-04-21T15:16:37.713Z
url: https://www.incibe.es/en/incibe-cert/notices/aviso/search-path-without-quotes-civetweb
CVSS v3: 7.8
CVSS v4: 8.5
****************
* cmake/3.31.5 *
****************
No vulnerabilities found.
***************
* cmake/4.2.3 *
***************
No vulnerabilities found.
***************************
* gnu-config/cci.20210814 *
***************************
No vulnerabilities found.
****************
* jansson/2.14 *
****************
No vulnerabilities found.
******************
* libcurl/8.18.0 *
******************
38 vulnerabilities found:
- CVE-2026-10536 (Severity: Critical - 9.8)
A use-after-free vulnerability exists in libcurl when an application configures
an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and
finally terminates th...
Published at: 2026-06-24T13:21:28.641Z
url: https://packages.mini.dev/advisories/osv/MINI-x888-fhwf-c2pr.json
CVSS v3: 9.8
- CVE-2026-11564 (Severity: Critical - 9.1)
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. An easy handle that first
uses default native CA trust can continue trusting the native platform store
after...
Published at: 2026-07-03T07:16:23.790Z
url: https://curl.se/docs/CVE-2026-11564.html
CVSS v3: 9.1
- CVE-2026-9079 (Severity: Critical - 9.8)
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Published at: 2026-07-03T07:16:25.620Z
url: https://curl.se/docs/CVE-2026-9079.html
CVSS v3: 9.8
- CVE-2026-11856 (Severity: Critical - 9.8)
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`)
with **Digest** authentication and then changing the origin to a different one
(`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly
p...
Published at: 2026-06-24T13:21:28.641Z
url: https://curl.se/docs/CVE-2026-11856.html
CVSS v3: 9.8
- CVE-2026-8924 (Severity: Critical - 9.1)
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
"super cookies" that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits t...
Published at: 2026-06-24T13:21:28.641Z
url: https://curl.se/docs/CVE-2026-8924.html
CVSS v3: 9.1
- CVE-2026-8925 (Severity: Critical - 9.8)
The curl logic that works with SASL authentication could end up cleaning up the
GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer twice.
Published at: 2026-07-03T00:28:26.379Z
url: https://packages.mini.dev/advisories/osv/MINI-jv59-c3j7-jf8g.json
CVSS v3: 9.8
- CVE-2026-8926 (Severity: Critical - 9.1)
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username (without a password), like
`https://user@example.com/`, curl could wrongly get and use the password for
*another* user set in ...
Published at: 2026-07-03T07:16:25.037Z
url: https://packages.mini.dev/advisories/osv/MINI-g2pr-94gx-xcqv.json
CVSS v3: 9.1
- CVE-2026-8927 (Severity: Critical - 9.1)
When reusing a libcurl handle for sequential transfers driven by
environment-variable proxy configuration, libcurl fails to clear the proxy
authentication state between requests. Specifically, if the initial transfer
authenticates against `...
Published at: 2026-06-24T13:21:28.641Z
url: https://packages.mini.dev/advisories/osv/MINI-vchr-vcfj-27qv.json
CVSS v3: 9.1
- CVE-2026-18924 (Severity: Critical - 9.1)
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Published at: 2026-09-02T12:59:06.983Z
url: https://packages.mini.dev/advisories/osv/MINI-7922-6q99-fj92.json
CVSS v3: 9.1
- CVE-2026-19931 (Severity: Critical - 9.8)
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done using
empty credentials. This can make user B's request get sent over user A's
previousl...
Published at: 2026-09-02T12:58:50.880Z
url: https://curl.se/docs/CVE-2026-19931.html
CVSS v3: 9.8
- CVE-2026-3805 (Severity: High - 7.5)
When doing a second SMB request to the same host again, curl would wrongly use
a data pointer pointing into already freed memory.
Published at: 2026-03-11T11:16:00.967Z
url: https://curl.se/docs/CVE-2026-3805.html
CVSS v3: 7.5
- CVE-2026-5773 (Severity: High - 7.5)
libcurl might in some circumstances reuse the wrong connection for SMB(S)
transfers. libcurl features a pool of recent connections so that subsequent
requests can reuse an existing connection to avoid overhead. When reusing a
connection a...
Published at: 2026-04-30T09:00:17.094Z
url: https://curl.se/docs/CVE-2026-5773.html
CVSS v3: 7.5
- CVE-2026-6276 (Severity: High - 7.5)
Using libcurl, when a custom `Host:` header is first set for an HTTP request
and a second request is subsequently done using the same *easy handle* but
without the custom `Host:` header set, the second request would use stale
information an...
Published at: 2026-04-30T09:00:14.630Z
url: https://curl.se/docs/CVE-2026-6276.html
CVSS v3: 7.5
- CVE-2026-9547 (Severity: High - 7.4)
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type ...
Published at: 2026-06-24T13:21:28.641Z
url: https://curl.se/docs/CVE-2026-9547.html
CVSS v3: 7.4
- CVE-2026-11352 (Severity: High - 7.5)
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client. Because
the helper function discards zero-length UDP datagrams before counting them
toward...
Published at: 2026-07-03T07:16:23.693Z
url: https://packages.mini.dev/advisories/osv/MINI-2gg7-7rv8-6535.json
CVSS v3: 7.5
- CVE-2026-11586 (Severity: High - 7.5)
By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential ...
Published at: 2026-07-03T07:16:23.883Z
url: https://curl.se/docs/CVE-2026-11586.html
CVSS v3: 7.5
- CVE-2026-9080 (Severity: High - 7.3)
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`
callback triggers a use-after-free vulnerability, where libcurl attempts to
store a flag using a dangling struct pointer immediately after that pointer's
memory ha...
Published at: 2026-07-03T07:16:25.713Z
url: https://curl.se/docs/CVE-2026-9080.html
CVSS v3: 7.3
- CVE-2026-9545 (Severity: High - 7.5)
In this scenario, libcurl first uses a proper HTTP/3 server for the initial
transfers, and when it makes a second transfer to the same site it has been
replaced by the attacker's impostor machine - without a valid certificate.
When libcurl...
Published at: 2026-07-03T07:16:25.807Z
url: https://curl.se/docs/CVE-2026-9545.html
CVSS v3: 7.5
- CVE-2026-9546 (Severity: High - 7.5)
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even
when explicitly cleared. While the documentation states that passing NULL to
`CURLOPT_REFERER` suppresses the header, the option failed to clear the
internal state...
Published at: 2026-07-03T07:16:25.893Z
url: https://packages.mini.dev/advisories/osv/MINI-5c4h-6rhr-fr3h.json
CVSS v3: 7.5
- CVE-2026-12064 (Severity: High - 7.5)
When a user invokes curl using a schemeless URL combined with `--proto-default`
sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool
layer incorrectly infers the URL scheme, which erroneously bypasses the
initiali...
Published at: 2026-06-24T13:21:28.641Z
url: https://packages.mini.dev/advisories/osv/MINI-57vg-25pp-5hq8.json
CVSS v3: 7.5
- CVE-2026-8932 (Severity: High - 7.5)
libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse. libcurl
keeps previously used connections in a connection pool for subsequent transfers
to re...
Published at: 2026-06-24T13:21:28.641Z
url: https://packages.mini.dev/advisories/osv/MINI-h432-768q-x77g.json
CVSS v3: 7.5
- CVE-2026-8286 (Severity: High - 8.1)
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.
Published at: 2026-06-24T13:21:28.641Z
url: https://curl.se/docs/CVE-2026-8286.html
CVSS v3: 8.1
- CVE-2026-80229 (Severity: High - 7.5)
When performing transfers via libcurl’s multi interface, pooled TLS connections
can outlive their originating easy handles. In OpenSSL 3 provider
configurations, libcurl attaches an allocated library context to the easy
handle's state and p...
Published at: 2026-09-06T18:17:22.217Z
url: https://packages.mini.dev/advisories/osv/MINI-v8f5-wmg2-5c7w.json
CVSS v3: 7.5
- CVE-2026-80230 (Severity: High - 7.5)
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established w...
Published at: 2026-09-02T12:58:26.025Z
url: https://packages.mini.dev/advisories/osv/MINI-m5pm-rhcc-h328.json
CVSS v3: 7.5
- CVE-2026-80231 (Severity: High - 7.5)
A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for
a given hostname even when using a different Native CA Store setting
(`CURLSSLOPT_NATIVE_CA`) than when the connection was created.
Published at: 2026-09-06T18:17:22.500Z
url: https://curl.se/docs/CVE-2026-80231.html
CVSS v3: 7.5
- CVE-2026-80255 (Severity: High - 7.5)
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of
space (ascii code 32) immediately before the `Secure` attribute causes curl to
store the cookie without its Secure flag. The cookie might then wrongfully be
sent ove...
Published at: 2026-09-06T18:17:22.623Z
url: https://packages.mini.dev/advisories/osv/MINI-xg5x-26hr-hmrw.json
CVSS v3: 7.5
- CVE-2026-82208 (Severity: High - 7.5)
With the wolfSSL backend, when CA caching is enabled and an
`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can
silently reinstall the cached store after the callback returns. A certificate
trusted by the cached store ...
Published at: 2026-09-06T18:17:22.733Z
url: https://packages.mini.dev/advisories/osv/MINI-f22w-p2ff-926p.json
CVSS v3: 7.5
- CVE-2026-82209 (Severity: High - 8.2)
When libpsl support is enabled, libcurl fails to enforce the Public Suffix List
boundary check when processing a `Set-Cookie` header where the `Domain`
attribute explicitly matches an origin host that is itself a public suffix
(e.g., `Domai...
Published at: 2026-09-02T12:58:44.938Z
url: https://curl.se/docs/CVE-2026-82209.html
CVSS v3: 8.2
- CVE-2026-13608 (Severity: High - 7.4)
A flaw in the libcurl SASL negotiation for LDAP authentication allows an
incomplete handshake sequence to be misinterpreted as a successful
cryptographic verification. An attacker executing a Man-in-the-Middle (MITM)
attack can inject a pre...
Published at: 2026-09-02T10:09:44.382Z
url: https://packages.mini.dev/advisories/osv/MINI-9p79-634m-v44m.json
CVSS v3: 7.4
- CVE-2026-3783 (Severity: Medium - 5.3)
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a redirect to a second URL, curl could leak that token to the second
hostname under some circumstances. If the hostname that the first request is
redir...
Published at: 2026-03-11T11:16:00.080Z
url: https://curl.se/docs/CVE-2026-3783.html
CVSS v3: 5.3
- CVE-2026-1965 (Severity: Medium - 6.5)
libcurl can in some circumstances reuse the wrong connection when asked to do
an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of
recent connections so that subsequent requests can reuse an existing connection
to a...
Published at: 2026-03-11T11:15:59.177Z
url: https://curl.se/docs/CVE-2026-1965.html
CVSS v3: 6.5
- CVE-2026-5545 (Severity: Medium - 6.5)
libcurl might in some circumstances reuse the wrong connection when asked to do
an authenticated HTTP(S) request after a Negotiate-authenticated one, when both
use the same host. libcurl features a pool of recent connections so that
subseq...
Published at: 2026-04-30T09:00:30.550Z
url: https://curl.se/docs/CVE-2026-5545.html
CVSS v3: 6.5
- CVE-2026-4873 (Severity: Medium - 5.9)
A vulnerability exists where a connection requiring TLS incorrectly reuses an
existing unencrypted connection from the same connection pool. If an initial
transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request
to tha...
Published at: 2026-04-30T09:00:23.009Z
url: https://packages.mini.dev/advisories/osv/MINI-749q-8cfx-fw4g.json
CVSS v3: 5.9
- CVE-2026-7009 (Severity: Medium - 5.3)
When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is valid,
it fails to detect OCSP problems and instead wrongly consider the response as
fine.
Published at: 2026-05-13T13:01:57.100Z
url: https://packages.mini.dev/advisories/osv/MINI-fwf3-39q9-6r2m.json
CVSS v3: 5.3
- CVE-2026-7168 (Severity: Medium - 5.3)
Successfully using libcurl to do a transfer over a specific HTTP proxy
(`proxyA`) with **Digest** authentication and then changing the proxy host to a
second one (`proxyB`) for a second transfer, reusing the same handle, makes
libcurl wrong...
Published at: 2026-04-30T09:00:37.280Z
url: https://curl.se/docs/CVE-2026-7168.html
CVSS v3: 5.3
- CVE-2026-6253 (Severity: Medium - 5.9)
curl might erroneously pass on credentials for a first proxy to a second proxy.
This can happen when the following conditions are true: 1. curl is setup to
use specific different proxies for different URL schemes 2. the first proxy
needs ...
Published at: 2026-04-30T09:00:08.995Z
url: https://curl.se/docs/CVE-2026-6253.html
CVSS v3: 5.9
- CVE-2026-6429 (Severity: Medium - 5.3)
When asked to both use a `.netrc` file for credentials and to follow HTTP
redirects, libcurl could leak the password used for the first host to the
followed-to host under certain circumstances.
Published at: 2026-04-30T09:00:05.746Z
url: https://curl.se/docs/CVE-2026-6429.html
CVSS v3: 5.3
- CVE-2026-8458 (Severity: Medium - 6.5)
libcurl might in some circumstances reuse the wrong connection when asked to do
Negotiate-authenticated ones, even when they are set to use different
"services". libcurl features a pool of recent connections so that subsequent
requests can...
Published at: 2026-06-24T13:21:28.641Z
url: https://packages.mini.dev/advisories/osv/MINI-93g8-4h65-f27c.json
CVSS v3: 6.5
****************
* libffi/3.4.8 *
****************
No vulnerabilities found.
*****************
* libiconv/1.17 *
*****************
No vulnerabilities found.
*****************
* libtool/2.4.7 *
*****************
No vulnerabilities found.
****************
* libuv/1.51.0 *
****************
No vulnerabilities found.
******************
* libxml2/2.15.1 *
******************
No vulnerabilities found.
*****************
* libzip/1.11.4 *
*****************
No vulnerabilities found.
*************
* m4/1.4.19 *
*************
No vulnerabilities found.
****************************
* mdnsresponder/1310.140.1 *
****************************
No vulnerabilities found.
****************
* meson/1.10.1 *
****************
No vulnerabilities found.
********************
* mosquitto/2.0.22 *
********************
No vulnerabilities found.
****************
* ninja/1.13.2 *
****************
No vulnerabilities found.
*****************
* openssl/3.6.3 *
*****************
11 vulnerabilities found:
- CVE-2026-75803 (Severity: Critical - 9.1)
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty
ciphertext can report success without verifying the supplied authentication tag
when the operation is finalized by calling the EVP_Cipher() function. Impact
summary: App...
Published at: 2026-08-20T16:06:08.983Z
url: https://packages.mini.dev/advisories/osv/MINI-44jf-8phr-j393.json
CVSS v3: 9.1
- CVE-2026-63073 (Severity: Critical - 9.8)
Issue summary: OpenSSL CMP response validation passed an unexpected response
sender distinguished name directly as the format string to `ERR_raise_data()`.
Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client
that...
Published at: 2026-08-25T11:36:16.000Z
url: https://packages.mini.dev/advisories/osv/MINI-f4vr-f483-hr9j.json
CVSS v3: 9.8
- CVE-2026-54876 (Severity: High - 7.5)
Issue summary: A malicious TLS server can cause a memory leak in a TLS client
that has enabled OCSP response checking by sending an OCSP response that
contains no single response entries. Impact summary: An attacker can leak an
attacker-tu...
Published at: 2026-08-05T11:43:00.000Z
url: https://github.com/openssl/openssl/commit/155b5fe0f93365e6df1c56ee3606b121080c6c12
CVSS v3: 7.5
- CVE-2026-14456 (Severity: High - 7.5)
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes
valid QUIC Initial packets for unknown destination connection IDs, it can
allocate and queue new incoming channels without enforcing any limit. Impact
summary: A re...
Published at: 2026-08-13T07:00:13.000Z
url: https://advisory.echohq.com/cve/CVE-2026-14456
CVSS v3: 7.5
- CVE-2026-14457 (Severity: High - 7.5)
Issue summary: In a server or client configuration with RFC7250 Raw Public Keys
(RPKs) enabled, and only the private key (with no associated certificate)
configured locally, a NULL pointer dereference may occur when the remote peer
solicits...
Published at: 2026-08-25T11:36:16.000Z
url: https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76
CVSS v3: 7.5
- CVE-2026-63075 (Severity: High - 7.5)
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly
sends ack-eliciting packets while not acknowledging ACK-only responses, the
QUIC stack can retain ACK-only packet metadata for the lifetime of the
connection. I...
Published at: 2026-08-25T11:36:16.000Z
url: https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc
CVSS v3: 7.5
- CVE-2026-63076 (Severity: High - 7.5)
Issue summary: OpenSSL CMP password based protection verification only checks
whether the protectionAlg parameter was not NULL and not its ASN.1 type, before
treating it as a PBMParameter. A crafted message can contain a parameter of a
diff...
Published at: 2026-08-25T11:36:16.000Z
url: https://packages.mini.dev/advisories/osv/MINI-75v6-2r53-m3x8.json
CVSS v3: 7.5
- CVE-2026-18798 (Severity: High - 7.5)
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation fails for initial packet. Impact summary: Double free
leads to heap corruption, which typically results in termination of QUIC
server proce...
Published at: 2026-08-25T11:36:16.000Z
url: https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af
CVSS v3: 7.5
- CVE-2026-54874 (Severity: High - 7.5)
Issue summary: Receiving a DTLS record for a future epoch while a handshake is
in progress causes OpenSSL to buffer far more memory than the record itself
requires. Impact summary: A peer can use a small amount of network traffic to
make a...
Published at: 2026-08-25T11:36:16.000Z
url: https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40
CVSS v3: 7.5
- CVE-2026-63072 (Severity: High - 7.5)
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based
on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can
write and cleanse more bytes than that query reports, causing an 8-byte
out-of-boun...
Published at: 2026-08-25T11:36:16.000Z
url: https://advisory.echohq.com/cve/CVE-2026-63072
CVSS v3: 7.5
- CVE-2026-63074 (Severity: Medium - 5.9)
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches
additional certificates (extraCerts) sent in a CMP message, but never expunges
them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX
frequently, ...
Published at: 2026-08-25T11:36:16.000Z
url: https://advisory.echohq.com/cve/CVE-2026-63074
CVSS v3: 5.9
*****************
* pkgconf/2.5.1 *
*****************
No vulnerabilities found.
**************************
* rapidjson/cci.20250205 *
**************************
No vulnerabilities found.
*****************************
* util-linux-libuuid/2.41.2 *
*****************************
2 vulnerabilities found:
- CVE-2026-27456 (Severity: Medium - 4.7)
A TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been
identified in the SUID binary /usr/bin/mount from util-linux. This finding was
The mounted by researcher Julio Ángel Ferrari Medina (Aka. T0X1Cx).
binary, w...
Published at: 2026-04-01T09:43:13.000Z
url: https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4
CVSS v3: 4.7
- CVE-2026-13595 (Severity: Medium - 5.3)
A flaw was found in the libblkid library of util-linux. During nested partition
probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a
raw pointer to a parent partition entry in a dynamically allocated array. When
subs...
Published at: 2026-05-07T00:00:00.000Z
url: https://access.redhat.com/errata/RHSA-2026:26573
CVSS v3: 5.3
******************
* xz_utils/5.8.1 *
******************
1 vulnerability found:
- CVE-2026-34743 (Severity: Medium - 5.3)
If lzma_index_decoder() was used to decode an Index that contained no Records,
the resulting lzma_index was left in a state where where a subsequent
lzma_index_append() would allocate too little memory, and a buffer overflow
...ould occur.
Published at: 2026-03-31T16:46:31.000Z
url: https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87
CVSS v3: 5.3
CVSS v4: 1.7
**************
* zlib/1.3.1 *
**************
3 vulnerabilities found:
- CVE-2026-22184 (Severity: High - 7.8)
zlib versions up to and including 1.3.1.2 include a global buffer overflow in
the untgz utility located under contrib/untgz. The vulnerability is limited to
the standalone demonstration utility and does not affect the core zlib
compression ...
Published at: 2026-01-07T21:16:01.563Z
url: https://github.com/madler/zlib
CVSS v3: 7.8
CVSS v4: 4.6
- CVE-2026-85091 (Severity: High - 7.4)
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow
vulnerability in the gz_vacate() function when processing non-blocking
gzwrite() operations with stale external buffer pointers. Attackers can trigger
the overflow by callin...
Published at: 2026-09-02T00:00:00.000Z
url: https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490
CVSS v3: 7.4
CVSS v4: 8.3
- CVE-2026-27171 (Severity: Medium - 5.5)
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and
crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has
no termination condition.
Published at: 2026-02-18T04:16:01.263Z
url: https://packages.mini.dev/advisories/osv/MINI-hwjj-mj9h-qh5g.json
CVSS v3: 5.5
**************
* zstd/1.5.7 *
**************
No vulnerabilities found.
Total vulnerabilities found: 57
Summary:
- civetweb/1.16 2 vulnerabilities found
- libcurl/8.18.0 38 vulnerabilities found
- openssl/3.6.3 11 vulnerabilities found
- util-linux-libuuid/2.41.2 2 vulnerabilities found
- xz_utils/5.8.1 1 vulnerability found
- zlib/1.3.1 3 vulnerabilities found
If you are using packages from Conan Center, some vulnerabilities may have already been mitigated through patches applied in the recipe.
To verify if a patch has been applied, check the recipe in Conan Center.
Vulnerability information provided by JFrog Catalog. Check https://conan.io/audit/jfrogcuration for more information.
You can send questions and report issues about the returned vulnerabilities to conan-research@jfrog.com.
ERROR: The package openssl/3.6.3 has a CVSS score 9.1 and exceeded the threshold severity level 9.0.
I am struggling a bit with this. With our current setup, we do provide a conanfile.py (which also includes some version/version-range restrictions), and you can build Celix with Ubuntu packages. I can understand that we say/document something like: "The latest Ubuntu packages from the LTS used in Apache Celix are our reference for monitoring upstream vulnerabilities. Usage of Conan is also possible, but it is up to the user to resolve/select the final dependency versions." And maybe document how you can run a conan audit scan. In this case, I would expect that, if we do something with SBOM generation and vulnerability scanning, we do it based on the APT-based CI builds. Alternatively, we could make Conan and Conan package version resolution our reference and use a lockfile. I think it is also Ok to update the lockfile more frequently, and at the same time a lockfile could help during heavy development to prevent too many dependency changes between builds. I am a bit worried about the maintenance burden once we have more insight into upstream vulnerabilities. So I am not sure what the best approach is. From a "minimize the burden" perspective, I think it would be better to follow the APT package approach and rely on Canonical LTS security maintenance, instead of depending on multiple Conan Center recipes and therefore multiple maintainers. Maybe something with For me, the main question is therefore which dependency ecosystem we want to treat as the reference security baseline for Apache Celix. |
So am I.
We can do it for both Ubuntu and Conan builds, which provides our users clearer security status of these builds.
A clickable link to these audit reports in README.md (as the codecov) will be very helpful.
This is the classic usage of lockfile within any package management system. I think the security status when building with the latest available/usable version of dependencies will be more helpful to our users.
When dealing with CRA requirements, Conan is a very powerful tool. In my day job, we have a private Conan deployment within the enterprise. It is not always possible to update to the latest upstream open source component to fix security issues. For example, projects as Civetweb are not actively maintained, or we must stick to a very old version like libcurl 7.x. We can rely on Ubuntu LTS or other Linux distributions' security patches to generate patched revision of such conan package. Then an ultimate downstream You can see when deploying Conan privately, both the upstream conan center and Ubuntu LTS are used as security references.
We can spend most of efforts to get SBOM/audit work on Ubuntu LTS, and then provide easy access to audit reports for both Ubuntu and Conan build. |
Fixes #824.
This supersedes #844 and incorporates the review feedback from @PengZheng and @pnoltes.
The change keeps SBOM generation in the existing Conan CI and uses Conan’s built-in cyclone_1.6 deployer. It also adds a committed Conan lockfile as a reproducible safe-default dependency baseline, while preserving the ability for downstream Celix users to select or override their own dependencies.
The safe-default lockfile is intentionally stored at:
conan/safe-defaults.lock
rather than as a root-level conan.lock. Conan automatically discovers a root conan.lock, which would implicitly constrain unrelated Celix builds. Keeping it at an explicit path makes use of the baseline opt-in.
For the Linux/GCC/Release configuration, CI generates the CycloneDX 1.6 SBOM with:
conan install .
--lockfile=conan/safe-defaults.lock
--deployer=cyclone_1.6
--deployer-folder=sbom
-b missing
-pr:b default
-pr:h default
-s:h build_type=Release
-o celix/:build_all=True
-o celix/:celix_cxx17=True
-o mosquitto/*:broker=True
-o *:shared=True
CI publishes both:
together as the celix-conan-safe-defaults artifact.
The lockfile records the exact Conan recipe revisions used for this documented baseline. It is not intended to be repository-wide dependency policy: applications remain free to build without it, override dependency versions, or maintain their own lockfile and matching SBOM.
Documentation has also been added explaining the baseline, its scope, how CI generates the SBOM, and how users can opt into the same dependency graph locally.
Validation