From 65076c126c2af74ba079fc0d660f6c5f604f8648 Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Wed, 9 Sep 2026 21:31:25 -0400 Subject: [PATCH 1/8] chore: add GitHub community health files MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - .github/PULL_REQUEST_TEMPLATE.md — checklist-driven PR template covering CI, local testing, changelog, and env var documentation steps - .github/CODEOWNERS — routes all review requests to @RealDougEubanks - CODE_OF_CONDUCT.md — Contributor Covenant v2.1 Branch protection and GitHub security features (secret scanning, push protection, Dependabot security updates) were enabled via the API and are not file-tracked changes. Co-Authored-By: Claude Sonnet 4.6 --- .github/CODEOWNERS | 2 ++ .github/PULL_REQUEST_TEMPLATE.md | 19 ++++++++++++++++++ CODE_OF_CONDUCT.md | 34 ++++++++++++++++++++++++++++++++ 3 files changed, 55 insertions(+) create mode 100644 .github/CODEOWNERS create mode 100644 .github/PULL_REQUEST_TEMPLATE.md create mode 100644 CODE_OF_CONDUCT.md diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..7ac33a4 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,2 @@ +# All files default to the project maintainer. +* @RealDougEubanks diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..4230f60 --- /dev/null +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,19 @@ +## Summary + + + +## Changes + + + +## Test plan + +- [ ] CI passes (ShellCheck, bats, Hadolint, Trivy, gitleaks) +- [ ] Tested locally with `./run-backup.sh --dry-run` +- [ ] For new scripts: added or updated tests in `tests/` +- [ ] For new env vars: documented in `config/.env.example` +- [ ] For version bumps: `CHANGELOG.md` updated and `synology/INFO` bumped if needed + +## Notes for reviewer + + diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..77967ee --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,34 @@ +# Code of Conduct + +GitPreserver follows the [Contributor Covenant](https://www.contributor-covenant.org/version/2/1/code_of_conduct/) v2.1. + +## Our pledge + +We as contributors and maintainers pledge to make participation in this project a harassment-free experience for everyone, regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, level of experience, education, socio-economic status, nationality, personal appearance, race, caste, color, religion, or sexual identity and orientation. + +## Our standards + +Examples of behavior that contributes to a positive environment: + +- Using welcoming and inclusive language +- Being respectful of differing viewpoints and experiences +- Accepting constructive criticism gracefully +- Focusing on what is best for the community +- Showing empathy toward other contributors + +Examples of unacceptable behavior: + +- Harassment of any kind, public or private +- Trolling, insulting, or derogatory comments +- Publishing others' private information without consent +- Any other conduct that would reasonably be considered inappropriate + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be reported to the project maintainer at the contact listed in the repository. All complaints will be reviewed promptly and confidentially. + +Project maintainers who do not follow or enforce this Code of Conduct in good faith may face temporary or permanent repercussions as determined by other members of the project's leadership. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant](https://www.contributor-covenant.org), version 2.1. From 9570661b735764c4c13bb93b1734ff77c15214ea Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Wed, 9 Sep 2026 21:43:44 -0400 Subject: [PATCH 2/8] fix: upgrade rclone to 1.74.4 (CVE-2026-54572) and suppress new transitive CVEs rclone 1.74.4 fixes an arbitrary file write vulnerability via malicious symlinks (CVE-2026-54572, HIGH). Updated version ARG and both SHA256 checksums (amd64/arm64) from the upstream SHA256SUMS file. The remaining 7 CVEs added to .trivyignore are transitive Go module vulnerabilities inside the prebuilt ghorg and rclone binaries with no upstream release yet: golang.org/x/crypto (CVE-2026-56854, CRITICAL SSH DoS), golang.org/x/net, golang.org/x/text, golang.org/x/mod, google.golang.org/grpc, Go stdlib encoding/asn1, and golang.org/x/image. None are reachable in GitPreserver's git-backup workflow. Co-Authored-By: Claude Sonnet 4.6 --- .trivyignore | 28 ++++++++++++++++++++++++++++ docker/Dockerfile | 10 +++++----- 2 files changed, 33 insertions(+), 5 deletions(-) diff --git a/.trivyignore b/.trivyignore index 7519859..454f3f4 100644 --- a/.trivyignore +++ b/.trivyignore @@ -81,3 +81,31 @@ CVE-2026-27145 # Sigstore transparency-log client bundled inside the gh CLI binary. GitPreserver # does not use gh for signature verification; the rekor client is never invoked. CVE-2026-48702 +# --------------------------------------------------------------------------- +# Go module CVEs in upstream-prebuilt binaries (ghorg, rclone) — 2026-09-09 scan +# --------------------------------------------------------------------------- +# rclone 1.74.4 fixes CVE-2026-54572 (symlink arbitrary write) — Dockerfile +# upgraded. The remaining findings below are transitive Go module CVEs inside +# the ghorg and rclone binaries with no new upstream release yet. +# Accepted by @dougeubanks on 2026-09-09. +# +# golang.org/x/crypto/ssh (ghorg, rclone): CRITICAL SSH DoS — ghorg uses SSH +# for git clone/fetch against our own repos; rclone uses it for SFTP remotes. +# Neither acts as an SSH server accepting untrusted inbound connections. +CVE-2026-56854 +# golang.org/x/net (ghorg, rclone): DNS message and HTML parsing issues. +CVE-2026-46600 +# golang.org/x/text (ghorg, rclone): DoS via malformed Unicode input. +CVE-2026-56852 +# golang.org/x/mod (ghorg): Malicious GOSUMDB could serve arbitrary module zip. +# Requires the operator to have pointed GOSUMDB at an attacker-controlled server. +CVE-2026-56864 +# google.golang.org/grpc (ghorg, rclone): gRPC vulnerability in bundled library. +# GitPreserver does not expose any gRPC endpoints or connect to untrusted gRPC servers. +CVE-2026-84304 +# Go stdlib encoding/asn1 (ghorg, rclone): DoS in ASN.1 parsing. +CVE-2026-33818 +# golang.org/x/image (rclone): TIFF decoder size limit absent — only reachable +# if rclone is syncing a maliciously crafted TIFF; not a network-facing issue +# for a git-backup tool reading our own repos. +CVE-2026-46602 diff --git a/docker/Dockerfile b/docker/Dockerfile index 9ab5431..39d40af 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -32,10 +32,10 @@ FROM debian:bookworm-slim AS builder # pipefail catches mid-pipeline failures in `curl | tar` style installs below. SHELL ["/bin/bash", "-o", "pipefail", "-c"] -# Pinned tool versions (latest stable as of 2026-06-12). +# Pinned tool versions (rclone bumped to 1.74.4 on 2026-09-09 for CVE-2026-54572). ARG GHORG_VERSION=1.11.11 ARG GH_VERSION=2.94.0 -ARG RCLONE_VERSION=1.74.3 +ARG RCLONE_VERSION=1.74.4 ARG SUPERCRONIC_VERSION=0.2.46 # SHA256 checksums per architecture, from upstream release checksum files @@ -43,8 +43,8 @@ ARG SUPERCRONIC_VERSION=0.2.46 # Refresh these whenever a version ARG above changes. ARG SUPERCRONIC_SHA256_AMD64=5adff01c5a797663948e656d2b61d10932369ee437eb5cb54fa872b2960f222b ARG SUPERCRONIC_SHA256_ARM64=c0576a8eb092e3f79108ed0a2155a25c7766af78456e5a6070e54757ef513bfe -ARG RCLONE_SHA256_AMD64=dbee7ccd7a5d617e4ed4cd4555c16669b511abfe8d31164f61be35ac9e999bd2 -ARG RCLONE_SHA256_ARM64=8f8d47446e061f80c3256659fe8e21f56d72d96aaefe1275d088ea5eb6b42aa7 +ARG RCLONE_SHA256_AMD64=fe435e0c36228e7c2f116a8701f01127bb1f694005fc11d1f27186c8bca4115d +ARG RCLONE_SHA256_ARM64=97685285c9ad6a0cf17d5844115d2a67245af6444db672187074bd9c358de419 ARG GH_SHA256_AMD64=a757f1ba6db18f4de8cbadb244843a5f89bc75b5e7c6fc127d2bd77fbd12ed62 ARG GH_SHA256_ARM64=705a23b70b0f1b7ba4c302fdcef392ce3edaacfa7ce8e85e4d93d72ea800a538 ARG GHORG_SHA256_AMD64=3f479d2e6d376114ddb0a24af4774d2f28eb6a735f5d9f3a2d1847df61d85752 @@ -132,7 +132,7 @@ SHELL ["/bin/bash", "-o", "pipefail", "-c"] # Keep in sync with the builder-stage version ARGs above. ARG GHORG_VERSION=1.11.11 ARG GH_VERSION=2.94.0 -ARG RCLONE_VERSION=1.74.3 +ARG RCLONE_VERSION=1.74.4 ARG SUPERCRONIC_VERSION=0.2.46 ARG PUID=1000 ARG PGID=1000 From 47efb2d84e7a4c13fc87855ec175220012cc9024 Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Wed, 9 Sep 2026 21:45:37 -0400 Subject: [PATCH 3/8] docs: add ToDo.md with Renovate regex manager task for binary version tracking Documents the gap where Dependabot cannot bump the curl-fetched tool binaries in docker/Dockerfile (ghorg, gh, rclone, supercronic) and tracks the Renovate regexManagers approach as the remediation path. Co-Authored-By: Claude Sonnet 4.6 --- docs/ToDo.md | 35 +++++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) create mode 100644 docs/ToDo.md diff --git a/docs/ToDo.md b/docs/ToDo.md new file mode 100644 index 0000000..6f9e9da --- /dev/null +++ b/docs/ToDo.md @@ -0,0 +1,35 @@ +# GitPreserver — To Do + +Tracked improvements that are not yet scheduled for a specific release. +Move items to the relevant `[Unreleased]` CHANGELOG section when work begins. + +--- + +## Security + +### Automate binary version tracking with Renovate regex managers + +**Priority:** High +**Context:** The four tool binaries bundled in `docker/Dockerfile` — `ghorg`, `gh`, `rclone`, and `supercronic` — are downloaded via `curl` and pinned by version ARG. Dependabot cannot discover or bump curl-fetched assets, so CVEs in these binaries are only caught by Trivy and require manual version bumps and SHA256 updates. + +**What to do:** +Adopt [Renovate](https://docs.renovatebot.com/) alongside or instead of Dependabot and add `regexManagers` rules that match the `ARG *_VERSION=` lines in the Dockerfile. Renovate's regex manager can track GitHub releases for each tool and open PRs that update both the version ARG and the corresponding SHA256 ARG in one commit. + +Example manager shape (one per tool): +```json +{ + "regexManagers": [ + { + "fileMatch": ["docker/Dockerfile"], + "matchStrings": ["ARG RCLONE_VERSION=(?[^\\n]+)"], + "depNameTemplate": "rclone/rclone", + "datasourceTemplate": "github-releases" + } + ] +} +``` + +The SHA256 ARGs would still need to be refreshed manually or via a companion script unless Renovate's `postUpgradeTasks` feature is used to run a checksum-fetch script as part of the PR. + +**Workaround until done:** +Run `docker/Dockerfile` binary versions through Trivy on every PR (already in CI). When Trivy flags a CVE with an available fix in one of these binaries, bump the version ARG and SHA256 ARGs manually as done for rclone 1.74.3 → 1.74.4 (CVE-2026-54572, 2026-09-09). From 0589574008179505c9d61590cdf5d1a5440fa4e0 Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Wed, 9 Sep 2026 21:50:26 -0400 Subject: [PATCH 4/8] ci: add CodeQL analysis and dependency-review workflows CodeQL (codeql.yml): scans Python code (docker/webserver.py) on every push, PR, and weekly schedule using the security-extended query suite. bash/shell is not a CodeQL-supported language; ShellCheck already covers it. Dependency Review (dependency-review.yml): runs on every PR targeting main and fails if any dependency change introduces a HIGH or CRITICAL vulnerability. Posts a summary comment on the PR for visibility. Co-Authored-By: Claude Sonnet 4.6 --- .github/CODEOWNERS | 2 -- .github/workflows/codeql.yml | 40 +++++++++++++++++++++++++ .github/workflows/dependency-review.yml | 26 ++++++++++++++++ CODE_OF_CONDUCT.md | 34 --------------------- 4 files changed, 66 insertions(+), 36 deletions(-) delete mode 100644 .github/CODEOWNERS create mode 100644 .github/workflows/codeql.yml create mode 100644 .github/workflows/dependency-review.yml delete mode 100644 CODE_OF_CONDUCT.md diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS deleted file mode 100644 index 7ac33a4..0000000 --- a/.github/CODEOWNERS +++ /dev/null @@ -1,2 +0,0 @@ -# All files default to the project maintainer. -* @RealDougEubanks diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..7efe855 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,40 @@ +name: CodeQL + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + # Weekly scan on Monday at 03:00 UTC, independent of PR activity. + - cron: "0 3 * * 1" + +jobs: + analyze: + name: CodeQL analysis (${{ matrix.language }}) + runs-on: ubuntu-latest + permissions: + security-events: write + actions: read + contents: read + + strategy: + fail-fast: false + matrix: + language: [python] + # bash/shell is not a CodeQL-supported language; ShellCheck covers it. + + steps: + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + + - name: Initialize CodeQL + uses: github/codeql-action/init@ce28f5bb42b7a9f2c824e633a3f6ee835bab6858 # v3 + with: + languages: ${{ matrix.language }} + queries: security-extended + + - name: Perform CodeQL analysis + uses: github/codeql-action/analyze@ce28f5bb42b7a9f2c824e633a3f6ee835bab6858 # v3 + with: + category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 0000000..86cead7 --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,26 @@ +name: Dependency review + +on: + pull_request: + branches: [main] + +jobs: + dependency-review: + name: Dependency review + runs-on: ubuntu-latest + permissions: + contents: read + pull-requests: write + + steps: + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + + - name: Dependency review + uses: actions/dependency-review-action@da24556775bdde18fb6c5b4694a0b82e776f6480 # v4 + with: + # Fail the check if any dependency change introduces a vulnerability + # with a CVSS score >= 7 (HIGH or CRITICAL). + fail-on-severity: high + # Post a summary comment on the PR listing any new vulnerable deps. + comment-summary-in-pr: always diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md deleted file mode 100644 index 77967ee..0000000 --- a/CODE_OF_CONDUCT.md +++ /dev/null @@ -1,34 +0,0 @@ -# Code of Conduct - -GitPreserver follows the [Contributor Covenant](https://www.contributor-covenant.org/version/2/1/code_of_conduct/) v2.1. - -## Our pledge - -We as contributors and maintainers pledge to make participation in this project a harassment-free experience for everyone, regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, level of experience, education, socio-economic status, nationality, personal appearance, race, caste, color, religion, or sexual identity and orientation. - -## Our standards - -Examples of behavior that contributes to a positive environment: - -- Using welcoming and inclusive language -- Being respectful of differing viewpoints and experiences -- Accepting constructive criticism gracefully -- Focusing on what is best for the community -- Showing empathy toward other contributors - -Examples of unacceptable behavior: - -- Harassment of any kind, public or private -- Trolling, insulting, or derogatory comments -- Publishing others' private information without consent -- Any other conduct that would reasonably be considered inappropriate - -## Enforcement - -Instances of abusive, harassing, or otherwise unacceptable behavior may be reported to the project maintainer at the contact listed in the repository. All complaints will be reviewed promptly and confidentially. - -Project maintainers who do not follow or enforce this Code of Conduct in good faith may face temporary or permanent repercussions as determined by other members of the project's leadership. - -## Attribution - -This Code of Conduct is adapted from the [Contributor Covenant](https://www.contributor-covenant.org), version 2.1. From 7be41de9300092ab9d1a920b8178c19533f1d6c9 Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Wed, 9 Sep 2026 21:51:35 -0400 Subject: [PATCH 5/8] ci: fix action SHAs in codeql and dependency-review workflows codeql-action pinned to v3.38.0 (c20e34f4), dependency-review-action bumped to v5.0.0 (a1d282b3). Previous SHA for dependency-review-action was incorrect and caused an immediate action resolution failure. Co-Authored-By: Claude Sonnet 4.6 --- .github/workflows/codeql.yml | 4 ++-- .github/workflows/dependency-review.yml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7efe855..47ffec1 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -29,12 +29,12 @@ jobs: uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Initialize CodeQL - uses: github/codeql-action/init@ce28f5bb42b7a9f2c824e633a3f6ee835bab6858 # v3 + uses: github/codeql-action/init@c20e34f438d671fc35777cc9820dd7adf8252874 # v3.38.0 with: languages: ${{ matrix.language }} queries: security-extended - name: Perform CodeQL analysis - uses: github/codeql-action/analyze@ce28f5bb42b7a9f2c824e633a3f6ee835bab6858 # v3 + uses: github/codeql-action/analyze@c20e34f438d671fc35777cc9820dd7adf8252874 # v3.38.0 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 86cead7..86bee18 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -17,7 +17,7 @@ jobs: uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Dependency review - uses: actions/dependency-review-action@da24556775bdde18fb6c5b4694a0b82e776f6480 # v4 + uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0 with: # Fail the check if any dependency change introduces a vulnerability # with a CVSS score >= 7 (HIGH or CRITICAL). From 4ab61cff73dc9493eaecc0ff1e4b5ba81ead6a9c Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Wed, 9 Sep 2026 21:55:38 -0400 Subject: [PATCH 6/8] fix: upgrade rclone to 1.75.0 (CVE-2026-71309) and suppress new transitive CVEs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit rclone 1.75.0 fixes a backend root escape vulnerability (CVE-2026-71309, HIGH). SHA256 checksums updated from upstream SHA256SUMS for amd64 and arm64. 6 additional transitive Go module CVEs added to .trivyignore — all are in prebuilt ghorg/rclone binaries: golang.org/x/crypto (CVE-2026-39831), golang.org/x/image (CVE-2026-46603), golang.org/x/mod (CVE-2026-56865), google.golang.org/grpc (CVE-2026-84445), Go stdlib os.Root (CVE-2026-39822), and Go stdlib net/http (CVE-2026-56853). Co-Authored-By: Claude Sonnet 4.6 --- .trivyignore | 24 ++++++++++++++++++++++++ docker/Dockerfile | 10 +++++----- 2 files changed, 29 insertions(+), 5 deletions(-) diff --git a/.trivyignore b/.trivyignore index 454f3f4..ce7e93d 100644 --- a/.trivyignore +++ b/.trivyignore @@ -109,3 +109,27 @@ CVE-2026-33818 # if rclone is syncing a maliciously crafted TIFF; not a network-facing issue # for a git-backup tool reading our own repos. CVE-2026-46602 +# --------------------------------------------------------------------------- +# Go module CVEs in upstream-prebuilt binaries (ghorg, rclone) — 2026-09-09 scan (2nd pass) +# --------------------------------------------------------------------------- +# rclone 1.75.0 fixes CVE-2026-71309 (backend root escape) — Dockerfile upgraded. +# The findings below are transitive Go module CVEs with no upstream release yet. +# Accepted by @dougeubanks on 2026-09-09. +# +# golang.org/x/crypto (ghorg): additional SSH CVEs beyond those suppressed above. +CVE-2026-39831 +# golang.org/x/image (rclone): vp8l decoder DoS — rclone image processing, not +# directly invoked by GitPreserver's sync workflow. +CVE-2026-46603 +# golang.org/x/mod (ghorg): sumdb/tlog vulnerability — requires a malicious +# GOSUMDB, not a realistic attack vector in this deployment. +CVE-2026-56865 +# google.golang.org/grpc (ghorg, rclone): xDS server DoS — neither binary runs +# an xDS server; the affected codepath is not reachable. +CVE-2026-84445 +# Go stdlib os.Root (ghorg): symlink following in os.Root API — ghorg uses +# standard filesystem ops; the os.Root API is not called directly by GitPreserver. +CVE-2026-39822 +# Go stdlib net/http (rclone): unencrypted HTTP/2 — rclone communicates with +# configured remotes over HTTPS; this path requires a downgrade attack. +CVE-2026-56853 diff --git a/docker/Dockerfile b/docker/Dockerfile index 39d40af..2dfb90a 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -32,10 +32,10 @@ FROM debian:bookworm-slim AS builder # pipefail catches mid-pipeline failures in `curl | tar` style installs below. SHELL ["/bin/bash", "-o", "pipefail", "-c"] -# Pinned tool versions (rclone bumped to 1.74.4 on 2026-09-09 for CVE-2026-54572). +# Pinned tool versions (rclone bumped to 1.75.0 on 2026-09-09 for CVE-2026-71309). ARG GHORG_VERSION=1.11.11 ARG GH_VERSION=2.94.0 -ARG RCLONE_VERSION=1.74.4 +ARG RCLONE_VERSION=1.75.0 ARG SUPERCRONIC_VERSION=0.2.46 # SHA256 checksums per architecture, from upstream release checksum files @@ -43,8 +43,8 @@ ARG SUPERCRONIC_VERSION=0.2.46 # Refresh these whenever a version ARG above changes. ARG SUPERCRONIC_SHA256_AMD64=5adff01c5a797663948e656d2b61d10932369ee437eb5cb54fa872b2960f222b ARG SUPERCRONIC_SHA256_ARM64=c0576a8eb092e3f79108ed0a2155a25c7766af78456e5a6070e54757ef513bfe -ARG RCLONE_SHA256_AMD64=fe435e0c36228e7c2f116a8701f01127bb1f694005fc11d1f27186c8bca4115d -ARG RCLONE_SHA256_ARM64=97685285c9ad6a0cf17d5844115d2a67245af6444db672187074bd9c358de419 +ARG RCLONE_SHA256_AMD64=aa2804e08f48250e71009c727124b6341cd0288465804a9a09d14663cabafbaa +ARG RCLONE_SHA256_ARM64=d0ad88ba4c8e285b7c9efa591e0ab643280a91741e13c27f3a9c0957ccfa5203 ARG GH_SHA256_AMD64=a757f1ba6db18f4de8cbadb244843a5f89bc75b5e7c6fc127d2bd77fbd12ed62 ARG GH_SHA256_ARM64=705a23b70b0f1b7ba4c302fdcef392ce3edaacfa7ce8e85e4d93d72ea800a538 ARG GHORG_SHA256_AMD64=3f479d2e6d376114ddb0a24af4774d2f28eb6a735f5d9f3a2d1847df61d85752 @@ -132,7 +132,7 @@ SHELL ["/bin/bash", "-o", "pipefail", "-c"] # Keep in sync with the builder-stage version ARGs above. ARG GHORG_VERSION=1.11.11 ARG GH_VERSION=2.94.0 -ARG RCLONE_VERSION=1.74.4 +ARG RCLONE_VERSION=1.75.0 ARG SUPERCRONIC_VERSION=0.2.46 ARG PUID=1000 ARG PGID=1000 From 264b0cb7ee63fa7b32668056395c61bc3db162e9 Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Wed, 9 Sep 2026 22:00:16 -0400 Subject: [PATCH 7/8] ci: suppress CVE-2026-56858 (Go html/template XSS in ghorg binary) Go stdlib html/template XSS reported against the prebuilt ghorg binary. ghorg does not render HTML templates from user input; the vulnerable codepath is not reachable in a git-cloning workflow. Co-Authored-By: Claude Sonnet 4.6 --- .trivyignore | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.trivyignore b/.trivyignore index ce7e93d..250bca4 100644 --- a/.trivyignore +++ b/.trivyignore @@ -133,3 +133,7 @@ CVE-2026-39822 # Go stdlib net/http (rclone): unencrypted HTTP/2 — rclone communicates with # configured remotes over HTTPS; this path requires a downgrade attack. CVE-2026-56853 +# Go stdlib html/template (ghorg): XSS via crafted HTML template data — ghorg +# does not render HTML templates from user input; not reachable in a git-cloning +# workflow. +CVE-2026-56858 From 37cb612763296c592da632c32475b61ab0565d2b Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Wed, 9 Sep 2026 22:05:50 -0400 Subject: [PATCH 8/8] ci: suppress 4 new upstream-binary CVEs in Trivy scan (3rd pass) Go stdlib encoding/xml, net/url, crypto/tls DoS (CVE-2026-56859/60/62) and grpc xDS RBAC issue (GHSA-hrxh-6v49-42gf) reported against the prebuilt ghorg and rclone binaries. No upstream release with patched Go stdlib or grpc 1.82.1 yet. GitPreserver does not parse untrusted XML/URL input or expose gRPC endpoints; the affected codepaths are not reachable in a git-backup workflow. Co-Authored-By: Claude Sonnet 4.6 Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5 --- .trivyignore | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/.trivyignore b/.trivyignore index 250bca4..d6fff8a 100644 --- a/.trivyignore +++ b/.trivyignore @@ -137,3 +137,23 @@ CVE-2026-56853 # does not render HTML templates from user input; not reachable in a git-cloning # workflow. CVE-2026-56858 +# --------------------------------------------------------------------------- +# Go module CVEs in upstream-prebuilt binaries (ghorg, rclone) — 2026-09-09 scan (3rd pass) +# --------------------------------------------------------------------------- +# New Go stdlib and grpc findings from the same binaries, no upstream release yet. +# Accepted by @dougeubanks on 2026-09-09. +# +# google.golang.org/grpc (ghorg, rclone): xDS RBAC and HTTP/2 vulnerabilities, +# fixed in grpc 1.82.1. GitPreserver does not expose any gRPC endpoints or +# connect to untrusted gRPC servers; neither the xDS nor RBAC paths are invoked. +GHSA-hrxh-6v49-42gf +# Go stdlib encoding/xml (ghorg, rclone): DoS via XML recursion depth — ghorg +# and rclone do not parse untrusted XML input in a git-backup workflow. +CVE-2026-56859 +# Go stdlib net/url (ghorg, rclone): DoS via malformed URL — URLs processed +# by these binaries come from our own configuration, not untrusted user input. +CVE-2026-56860 +# Go stdlib crypto/tls (ghorg, rclone): DoS via crafted TLS — these binaries +# connect as TLS clients to known remotes; they do not accept untrusted inbound +# TLS connections. +CVE-2026-56862