Skip to content

fix(security): remove pip from backend runtime - #42

Merged
tarantila merged 1 commit into
mainfrom
hardening/backend-runtime-pip-removal
Aug 28, 2026
Merged

tarantila merged 1 commit into
mainfrom
hardening/backend-runtime-pip-removal

Conversation

@tarantila

Copy link
Copy Markdown
Owner

Removes the unused system pip/ensurepip tooling from the final
backend runtime image while leaving the production virtualenv under
/opt/venv untouched.

Motivation:

  • removes pip-vendored vulnerable artifacts from the runtime image
  • fixes the Trivy HIGH findings for msgpack GHSA-6v7p-g79w-8964
    and setuptools CVE-2025-47273
  • keeps pip and uv available in build/development stages
  • does not suppress or ignore scanner findings

Validation performed locally:

  • backend runtime build and /health/live successful
  • Trivy 0.70.0 HIGH/CRITICAL gate: 0 findings
  • 368 backend tests passed, 22 skipped
  • PostgreSQL test suite: 22 passed
  • Alembic upgrade/check successful
  • E2E completed successfully with the existing Playwright retry
    behavior
  • production smoke including backup/restore successful
  • synthetic combination with PR build(deps): bump the container-bases group across 1 directory with 3 updates #35 also produced 0
    HIGH/CRITICAL Trivy findings

This is intentionally separate from the container-base dependency
update in PR #35.

Refs #35

@tarantila
tarantila merged commit 54b441f into main Aug 28, 2026
6 checks passed
@tarantila
tarantila deleted the hardening/backend-runtime-pip-removal branch August 31, 2026 11:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant