Skip to content

Conversation

@kvinwang
Copy link
Collaborator

Summary

Fix dcap-qvl security vulnerability by switching to a fork with the fix applied.

Security Advisory

Changes

  • Switch from upstream MoeMahhouk/gramine-sealing-key-provider to kvinwang/gramine-sealing-key-provider fork
  • The fork upgrades dcap-qvl from 0.2.0 to 0.3.10
  • Remove the local Cargo.lock since the fork has the correct dependencies

Related

Test plan

  • Verify key-provider-build Docker image builds successfully

Switch to kvinwang fork with dcap-qvl upgraded from 0.2.0 to 0.3.10.
This fixes "Missing Verification for QE Identity" vulnerability.

- Update Cargo.lock with dcap-qvl 0.3.10
- Verified release build succeeds

Security advisory: GHSA-796p-j2gh-9m2q
Upstream PR: MoeMahhouk/gramine-sealing-key-provider#13
@kvinwang kvinwang force-pushed the fix/dcap-qvl-security-v2 branch from 4a6c3cd to 173a374 Compare January 27, 2026 00:55
@kvinwang kvinwang changed the title Fix dcap-qvl security vulnerability in key-provider-build Fix dcap-qvl security vulnerability in key-provider Jan 27, 2026
@kvinwang kvinwang merged commit ef01991 into master Jan 27, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants