Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
49 changes: 49 additions & 0 deletions .inspector-ignore
Original file line number Diff line number Diff line change
Expand Up @@ -31,3 +31,52 @@ GHSA-3fxj-6jh8-hvhx # IP spoofing in middleware.RealIP — RIE only, localhost,

# golang.org/x/sys v0.21.0 → v0.44.0 required
CVE-2026-39824 # Windows-only integer overflow — Linux runtime, code path never executed

# Accepted risk: unpatched AL2023 OS packages in public.ecr.aws/lambda/python:3.14
# that are not reachable from the drillapi Lambda handler at runtime.
#
# As of 2026-10-07, `dnf upgrade -y --refresh` (already run in Dockerfile.lambda)
# reports "Nothing to do" for all of these — the patched RPMs have not yet been
# published by AWS to the AL2023 repo. We cannot fix these ourselves; they will
# clear automatically once AWS ships the updated packages and the image is rebuilt.
# Re-verify with `dnf upgrade --refresh` on each dependency update and remove the
# corresponding entries below once patched versions are actually installed.
#
# Verified unreachable, package by package:
#
# - libxml2 2.10.4-1.amzn2023.0.20 (fix: .0.21): `rpm -q --whatrequires libxml2`
# returns no results — no other installed package depends on it. The app's only
# XML/GML parsing (src/drillapi/services/processing.py) goes through `lxml`,
# which bundles its own statically-linked libxml2 2.14.6 and never calls into
# the system library. Confirmed via `lxml.etree.LIBXML_COMPILED_VERSION`.
#
# - rpm / rpm-libs 4.16.1.3-29.amzn2023.0.7 (fix: .0.8): only used by the `rpm`/
# `dnf` package managers during image build (e.g. the `dnf upgrade` step in
# Dockerfile.lambda). Never invoked by the Lambda handler while processing a
# request.
#
# - curl-minimal / libcurl-minimal 8.21.0-5.amzn2023.0.1 (fix: .0.2): `rpm -q
# --whatrequires curl-minimal libcurl-minimal` returns no results. The app's
# outbound HTTP calls go through `httpx`, which does not link against libcurl.
#
# - pcre2 / pcre2-syntax 10.40-1.amzn2023.0.3 (fix: .0.4): the only dependent is
# `libselinux`, unrelated to request handling.

# libxml2 2.10.4-1.amzn2023.0.20 → 0.21 required (unreachable, see above)
CVE-2026-74860 # libxml2 — heap buffer overflow, CWE-763 — unreachable, lxml bundles its own libxml2
CVE-2026-86140 # libxml2 — buffer overflow, CWE-121/120 — unreachable, lxml bundles its own libxml2
CVE-2026-86138 # libxml2 — integer overflow, CWE-190 — unreachable, lxml bundles its own libxml2
CVE-2026-86144 # libxml2 — unsafe reflection-equivalent issue, CWE-669 — unreachable, lxml bundles its own libxml2
CVE-2026-86142 # libxml2 — heap buffer overflow, CWE-122/805 — unreachable, lxml bundles its own libxml2
CVE-2026-86143 # libxml2 — integer overflow, CWE-192 — unreachable, lxml bundles its own libxml2
CVE-2026-86137 # libxml2 — out-of-bounds read, CWE-125 (medium) — unreachable, lxml bundles its own libxml2

# rpm / rpm-libs 4.16.1.3-29.amzn2023.0.7 → 0.8 required (unreachable, see above)
CVE-2026-78367 # rpm — command injection, CWE-94 — build-time tool only, not invoked by handler
CVE-2026-84233 # rpm — OS command injection, CWE-78 — build-time tool only, not invoked by handler

# pcre2 / pcre2-syntax 10.40-1.amzn2023.0.3 → 0.4 required (unreachable, see above)
CVE-2026-89161 # pcre2 — ReDoS / improper handling, CWE-590/1341 — only pulled in by libselinux

# curl-minimal / libcurl-minimal 8.21.0-5.amzn2023.0.1 → 0.2 required (unreachable, see above)
CVE-2026-80230 # curl — improper certificate/authentication handling, CWE-295/303 — app uses httpx, not libcurl
2 changes: 1 addition & 1 deletion .pre-commit-config.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
repos:
- repo: https://github.com/astral-sh/ruff-pre-commit
rev: v0.14.14 # Utilisez la dernière version
rev: v0.16.10 # Utilisez la dernière version
hooks:
- id: ruff
args: ["--fix"]
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM ghcr.io/astral-sh/uv:0.12.3-python3.14-alpine AS base
FROM ghcr.io/astral-sh/uv:0.12.23-python3.14-alpine AS base

WORKDIR /app
ENV PYTHONPATH=/app
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile.lambda
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# from https://docs.astral.sh/uv/guides/integration/aws-lambda/#deploying-a-docker-image

FROM ghcr.io/astral-sh/uv:0.12.3 AS uv
FROM ghcr.io/astral-sh/uv:0.12.23 AS uv

# First, bundle the dependencies into the task root.
FROM public.ecr.aws/lambda/python:3.14 AS builder
Expand Down
6 changes: 3 additions & 3 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,14 +7,14 @@ readme = "README.md"
requires-python = ">=3.14"
keywords = ["drillapi"]
dependencies = [
"fastapi>=0.141.1",
"fastapi>=0.142.2",
"httpx>=0.28.1",
"jinja2>=3.1.6",
"mangum>=0.22.0",
"owslib>=0.36.0",
"pydantic-settings>=2.15.0",
"slowapi>=0.1.10",
"uvicorn>=0.52.4",
"uvicorn>=0.54.0",
]

[project.optional-dependencies]
Expand All @@ -25,7 +25,7 @@ dev = [
"requests",
"respx",
"pytest-asyncio",
"ruff>=0.16.4",
"ruff>=0.16.10",
]

[tool.coverage.run]
Expand Down
Loading
Loading