Bug 2530055 (CVE-2026-87058)

Summary: CVE-2026-87058 olm-operator-konflux-sample: olm-operator-konflux-sample: Hermetic build disabled by default; bundle build performs live network fetches
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: gbenhaim, niyer, twaugh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in olm-operator-konflux-sample. The hermetic build mode is disabled by default, allowing bundle builds to perform live network fetches. This means that external, unverified resources can be pulled during the build process, potentially compromising the integrity and trustworthiness of the resulting software artifacts. This introduces a supply chain risk where the final product might contain unintended or malicious code.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-08 19:06:06 UTC
## Hermetic build disabled by default; bundle build performs live network fetches

**Component:** olm-operator-konflux-sample

Hermetic build mode is disabled by default in the shared pipelines, and the bundle build performs live network fetches (including in-build `skopeo inspect` calls for architecture detection) rather than relying on prefetched, verified inputs.

### Remediation
Set `hermetic` default to `"true"` in both shared pipelines, supply `prefetch-input` for the gatekeeper/gatekeeper-operator Go builds, and replace the in-build `skopeo inspect` arch detection with statically-declared arch labels (the supported arch set is already known from `build-platforms`).

---
*Source: Ex-Wing/Glasswing Konflux CI security assessment (Mythos), finding FIND-002*