security(self-managed): remediate Samba 1.0.5 catalog blockers
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 218
- Forks
- 72
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 427
Description
Problem
Batch 7 cannot publish samba:1.0.5 to the public NGC catalog because both required platform digests fail the blocking nSpect Container OSS Vuln Out of SLA criterion. Container OSS Scan Rating also fails but is non-blocking. Release contacts, digest registration, secret/configuration scans, OSRB approval, malware, and export compliance pass.
- Catalog MR: https://gitlab-master.nvidia.com/ngc/publishing/ngc-publishing-configs/-/merge_requests/8628
- AMD64 nSpect details: https://nspect.nvidia.com/reports/launch/container?nspectId=NSPECT-JNT9-FHIU&resourceId=156513&digest=sha256:bbd4cc64de70698e6b60c4ae2e8eb4aebf73facc6b1df2445258adde11cb343a&programVersionId=75275&policyName=public-catalog
- ARM64 nSpect details: https://nspect.nvidia.com/reports/launch/container?nspectId=NSPECT-JNT9-FHIU&resourceId=156513&digest=sha256:d69f45a9eee85e190db1a20f7c905846f92f2b9e52db8329ca27c32623b2e2e1&programVersionId=75275&policyName=public-catalog
Requirements
- Enumerate the launch-ready findings for both platform digests.
- Remediate affected packages or add evidence-backed VEX for findings that are not exploitable.
- Produce a replacement multi-architecture version if the existing tag cannot be remediated in place.
- Keep AMD64 and ARM64/v8 on one immutable OCI index.
Acceptance criteria
- Both required platform digests pass the public-catalog
Container OSS Vuln Out of SLAcriterion. - The replacement version, if needed, is reflected in the self-managed stack inventory.
- nvpublish completes AMD64 and ARM64 Pulse checks and creates a green catalog MR.
- Catalog MR !8628 is merged if 1.0.5 is remediated, or closed as superseded if a new version is required.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the AMD64 and ARM64 nSpect reports and catalog MR !8628, then enumerate the launch-ready findings for both digests. Remediate affected packages or document evidence-backed VEX, and verify the acceptance criteria through nvpublish, the self-managed stack inventory, and the catalog MR outcome.
Written by the indexing model from the issue text.
Assessment
- Domain
- devops, release, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100