Skip to content

Bump pinned traefik version in traefik feature (v3.3 -> v3.7) - #4

Merged
z4nr34l merged 1 commit into
mainfrom
claude/cool-meitner-97frf6
Jul 20, 2026
Merged

z4nr34l merged 1 commit into
mainfrom
claude/cool-meitner-97frf6

Conversation

@z4nr34l

@z4nr34l z4nr34l commented Jul 20, 2026

Copy link
Copy Markdown
Member

Summary

Automated dependency/version audit of the pinned CLI/tool versions across src/*/devcontainer-feature.json and install.sh, plus the top-level Dockerfile.

Most features (bun, claude-code, gemini-cli, openai-codex, opencode, stripe-cli, supabase-cli, tinybird-cli) install from a "latest" channel (curl installer, npm install -g without a version pin, apt-get install, or a GitHub releases/latest URL) and are not actually pinned to a stale version — nothing to bump there. The Dockerfile base image (mcr.microsoft.com/devcontainers/base:bookworm) is a floating codename tag, also not pinned to a specific stale version.

The one feature with a genuinely pinned, stale version is traefik:

Tool Old New Security-relevant
traefik (Docker image in src/traefik/install.sh) v3.3 (Dec 2024, unmaintained branch) v3.7 Yes

Why this one is flagged as security-relevant

v3.3 is several minor versions behind the currently maintained branches (v2.11.x, v3.6.x, v3.7.x as of July 2026). Traefik has shipped multiple CVEs against v3.x since v3.3 was pinned, including:

  • CVE-2026-33186 — gRPC-Go HTTP/2 :path pseudo-header authorization bypass (CVSS 7.8, High). Fixed in v3.6.12 / v3.7.0-ea.3. The v3.3 branch does not receive this fix.
  • An earlier path-traversal issue via PathPrefix/Path/PathRegex matchers (fixed in v3.3.6), plus additional 2025/2026 advisories against the 3.x line.

Bumped to the v3.7 floating tag (matching the existing style of pinning to a major.minor tag) to land on a currently supported, patched branch.

Also bumped the traefik feature's own devcontainer-feature.json version (1.3.1 → 1.3.2), per this repo's semver convention (CONTRIBUTING.md: "Patch — tool version bumps, bug fixes").

Not auto-fixed (found but out of scope for a safe bump)

  • tinybird-cli's install.sh pins --python 3.13 for the uv tool install. Not stale/vulnerable, just a stable interpreter pin — left as-is.
  • All "latest"-tracking features (bun, claude-code, gemini-cli, openai-codex, opencode, stripe-cli, supabase-cli) will pick up current versions on next container build automatically; no action needed.

Test plan

  • devcontainer features test -f traefik . (per CONTRIBUTING.md)
  • Manually verify traefik-start still brings up the reverse proxy and routes correctly with the new image tag

🤖 Generated with Claude Code

https://claude.ai/code/session_01P5JaRVYhL51RgereorbFzR


Generated by Claude Code

The pinned traefik image (v3.3, released Dec 2024) is on an
unmaintained minor branch. Current upstream security fixes only land
on v3.7.x/v3.6.x/v2.11.x. Notably CVE-2026-33186 (gRPC-Go HTTP/2
:path pseudo-header authorization bypass, CVSS 7.8) was fixed in
v3.6.12/v3.7.0-ea.3 and is not backported to v3.3. Bumping to the
v3.7 floating tag keeps the container on a supported, patched branch.

Also bumps the traefik feature's own devcontainer-feature.json
version (1.3.1 -> 1.3.2) per this repo's semver convention for tool
version bumps.
@z4nr34l z4nr34l self-assigned this Jul 20, 2026
@z4nr34l
z4nr34l marked this pull request as ready for review July 20, 2026 11:56
@z4nr34l
z4nr34l merged commit 8171985 into main Jul 20, 2026
0 of 2 checks passed
@z4nr34l
z4nr34l deleted the claude/cool-meitner-97frf6 branch July 20, 2026 11:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants