Skip to content

chore: apply security audit improvements (CR-100, CR-111, CR-101)#938

Open
Dev10-sys wants to merge 2 commits into
repository-service-tuf:mainfrom
Dev10-sys:fix/security-audit-852-clean
Open

chore: apply security audit improvements (CR-100, CR-111, CR-101)#938
Dev10-sys wants to merge 2 commits into
repository-service-tuf:mainfrom
Dev10-sys:fix/security-audit-852-clean

Conversation

@Dev10-sys

Copy link
Copy Markdown

Description

This PR applies a set of improvements based on the RSTUF security audit findings.

Changes included:

  • Pin jinja2 to version >= 3.1.6 to avoid outdated dependency usage
  • Run the API container as a non-root user (rstuf)
  • Update the base image to Python 3.14

These updates improve dependency safety and container security without affecting existing functionality.

Reference

Security Audit Parent Issue:
repository-service-tuf/repository-service-tuf#852

…-tuf#852)

Signed-off-by: Dev10-sys <kalpanagola9897@gmail.com>
@Dev10-sys Dev10-sys force-pushed the fix/security-audit-852-clean branch from 9a423db to e0554e0 Compare April 18, 2026 17:44
Signed-off-by: Dev10-sys <kalpanagola9897@gmail.com>
@Dev10-sys Dev10-sys force-pushed the fix/security-audit-852-clean branch from 5b0f1bd to 308a8fd Compare April 19, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant