Skip to content

fix(docker): prune the gateway's dev packages from the all-in-one image - #433

Merged
joszz merged 1 commit into
mainfrom
fix/gateway-dev-packages
Oct 5, 2026
Merged

joszz merged 1 commit into
mainfrom
fix/gateway-dev-packages

Conversation

@joszz

@joszz joszz commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Fixes code scanning alerts #592, #593, #594 and #595: virtualenv 21.3.1 in /opt/saic/app/.venv (CVE-2026-102925, CVE-2026-102930, CVE-2026-102937 high, CVE-2026-102938 medium).

Cause

The upstream saicismartapi/saic-python-mqtt-gateway image runs a plain poetry install, so the venv we copy into the all-in-one image also carries the gateway's dev group: pytest, mypy, pylint, ruff, pre-commit and their dependencies, 31 packages at 0.12.0 that never run. virtualenv comes in through pre-commit. 0.12.0 is still the newest stable gateway, so a tag bump doesn't help.

Fix

Bumping virtualenv would only move the alerts to the next dev package, so the image now drops the whole dev group:

  • docker/all-in-one/prune-venv.py walks the installed packages' dependency metadata from the gateway's six runtime dependencies and uninstalls everything they don't need. It fails the build if one of those six isn't installed, which flags an upstream dependency change.
  • The Dockerfile then runs import main from the gateway source. That loads 71 of its 72 modules (the 72nd, log_config, only uses the standard library), so a runtime package pruned by mistake fails the build instead of the gateway at startup.

The six names mirror [project].dependencies in the gateway's pyproject.toml and need comparing on every gateway bump. Upstream develop (0.13.0) already swaps gmqtt for aiomqtt; on that bump the prune step fails the build until the list is updated.

Testing

Local Docker was down, so CI built the image first. Before that I checked in a Python 3.14 venv holding every package from the gateway's 0.12.0 poetry.lock at its exact version, running the same steps as the Dockerfile:

  • Every dev-only package is removed (32 on Windows; 31 in the image, where colorama is never installed) and the runtime packages and pip stay
  • import main passes on the pruned venv
  • With gmqtt removed, the import check exits 1
  • Container build (all-in-one) passes in CI: "Pruning 31 packages", then import main succeeds
  • After merge and publish, Trivy closes #592 to #595

No .NET or frontend code changed, so the unit test suites aren't affected.

Upstream

SAIC-iSmart-API/saic-python-mqtt-gateway#469 fixes this at the source with poetry install --only main. Once a gateway release ships it, the prune step has nothing left to remove and can go.

🤖 Generated with Claude Code

The upstream saic-python-mqtt-gateway image runs a plain `poetry install`,
so the venv the all-in-one image copies also carries the dev group:
pytest, mypy, pylint, pre-commit and 28 more packages that never run.
virtualenv, via pre-commit, raised code scanning alerts #592-#595.

prune-venv.py keeps only what the gateway's six runtime dependencies
resolve to and uninstalls the rest. Importing main.py afterwards loads
every gateway module, so a runtime package pruned by mistake fails the
build instead of the gateway at startup.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@joszz
joszz merged commit 6eceaeb into main Oct 5, 2026
22 checks passed
@joszz
joszz deleted the fix/gateway-dev-packages branch October 5, 2026 08:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant