From ae2f276d19f486f726264e393f94104119762d40 Mon Sep 17 00:00:00 2001 From: yuneng-jiang Date: Tue, 21 Jul 2026 12:56:56 -0700 Subject: [PATCH] ci(image-scan): match Python packages against CPE data (#34136) grype defaults match.python.using-cpes to false, so PyPI packages are matched only against the GitHub Advisory Database. When a CVE is published to NVD but its GHSA has not propagated to the global advisory database, the scan reports clean even though grype's own database already carries the NVD record with the correct version ranges. The pypdf CVEs (CVE-2026-59935 / 59936 / 59937 / 59938, analyzed in NVD since 2026-07-08) are the case that exposed this; their GHSA IDs are still repo-level and return 404 from the global advisory API, so the ecosystem matcher has nothing to match on. Enabling CPE matching for Python closes that gap. Measured against a v1.91.1 build the finding count goes from 28 to 38; the additions are mostly actionable, and the few cross-product CPE collisions cannot fail the build because --only-fixed drops the ones carrying no fix version and the remainder land below the --fail-on high threshold. --- .github/workflows/image-scan.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/image-scan.yml b/.github/workflows/image-scan.yml index 90ede5a653f..8d791ca5bc7 100644 --- a/.github/workflows/image-scan.yml +++ b/.github/workflows/image-scan.yml @@ -58,6 +58,8 @@ jobs: # free OSS, run as a pinned, checksum-verified binary; no GitHub Action # dependency and no vendor SaaS callout. - name: Scan image for fixable HIGH/CRITICAL CVEs + env: + GRYPE_MATCH_PYTHON_USING_CPES: "true" run: | "$RUNNER_TEMP/grype" litellm-image-scan:${{ github.sha }} \ --only-fixed \