diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index e18fb8b..6b13b52 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -58,17 +58,18 @@ jobs: - uses: actions/setup-go@v5 with: # Deliberately NOT go-version-file. Each go.mod pins an exact - # patch (`go 1.25.0`), so go-version-file made CI scan against - # the *unpatched* 1.25.0 standard library and fail on 28 - # stdlib CVEs -- crypto/x509 quadratic name-constraint parsing - # (GO-2025-4007) and friends, all fixed in 1.25.3. None of it - # was real: every Dockerfile builds `FROM golang:1.25-alpine`, - # a floating tag that resolves to the newest 1.25.x, so the - # shipped binaries already had the fixes. The go directive - # states the minimum language version, not the toolchain to - # audit with. Track the floating 1.25 line so this scans what - # production actually builds. - go-version: '1.25' + # patch, so go-version-file made CI scan against the *unpatched* + # standard library of that patch and fail on 28 stdlib CVEs -- + # crypto/x509 quadratic name-constraint parsing (GO-2025-4007) + # and friends, all long since fixed. None of it was real: every + # Dockerfile builds `FROM golang:1.26-alpine`, a floating tag + # that resolves to the newest 1.26.x, so the shipped binaries + # already had the fixes. The go directive states the minimum + # language version, not the toolchain to audit with. Track the + # floating 1.26 line so this scans what production actually + # builds, and keep it in step with the Dockerfiles above all -- + # a mismatch here fails every module at once. + go-version: '1.26' - run: go install golang.org/x/vuln/cmd/govulncheck@latest - name: Check for known vulnerabilities working-directory: ${{ matrix.module_dir }} diff --git a/alerting/Dockerfile b/alerting/Dockerfile index 8e24c50..9ffbfdc 100644 --- a/alerting/Dockerfile +++ b/alerting/Dockerfile @@ -2,7 +2,7 @@ # so unlike api/ingest/search this build context is just alerting/ itself, # same shape as cli/Dockerfile: # docker build -f alerting/Dockerfile -t cairnobs-alerting alerting/ -FROM golang:1.25-alpine AS builder +FROM golang:1.26-alpine AS builder WORKDIR /src COPY . . RUN CGO_ENABLED=0 GOOS=linux go build -o /out/alerting ./cmd/alerting diff --git a/api/Dockerfile b/api/Dockerfile index 47f12de..0b1ac88 100644 --- a/api/Dockerfile +++ b/api/Dockerfile @@ -3,7 +3,7 @@ # Go bindings via the `replace` directive in api/go.mod): # docker build -f api/Dockerfile -t cairnobs-api . -FROM golang:1.25-alpine AS builder +FROM golang:1.26-alpine AS builder WORKDIR /src COPY proto ./proto COPY api ./api diff --git a/cli/Dockerfile b/cli/Dockerfile index ea3c749..bcbd8bb 100644 --- a/cli/Dockerfile +++ b/cli/Dockerfile @@ -1,5 +1,5 @@ # docker build -f cli/Dockerfile -t cairnobsctl cli/ -FROM golang:1.25-alpine AS builder +FROM golang:1.26-alpine AS builder WORKDIR /src COPY . . RUN CGO_ENABLED=0 GOOS=linux go build -o /out/cairnobsctl ./cmd/cairnobsctl diff --git a/deploy/operator/Dockerfile b/deploy/operator/Dockerfile index 8332499..96c4345 100644 --- a/deploy/operator/Dockerfile +++ b/deploy/operator/Dockerfile @@ -2,7 +2,7 @@ # (alerting/Dockerfile, enterprise/Dockerfile) -- context is # deploy/operator/ itself, no /proto dependency. # docker build -f deploy/operator/Dockerfile -t cairnobs-tenant-operator deploy/operator/ -FROM golang:1.25-alpine AS builder +FROM golang:1.26-alpine AS builder WORKDIR /src COPY . . RUN CGO_ENABLED=0 GOOS=linux go build -o /out/tenant-operator ./cmd/tenant-operator diff --git a/enterprise/Dockerfile b/enterprise/Dockerfile index fbe6f8f..e5dd329 100644 --- a/enterprise/Dockerfile +++ b/enterprise/Dockerfile @@ -14,7 +14,7 @@ # enterprise-api's and enterprise-ingest's Dockerfiles already use for # the identical reason. # docker build -f enterprise/Dockerfile -t cairnobs-enterprise-auth . -FROM golang:1.25-alpine AS builder +FROM golang:1.26-alpine AS builder WORKDIR /src COPY . . WORKDIR /src/enterprise diff --git a/enterprise/cmd/enterprise-api/Dockerfile b/enterprise/cmd/enterprise-api/Dockerfile index de3ae0a..8825ba5 100644 --- a/enterprise/cmd/enterprise-api/Dockerfile +++ b/enterprise/cmd/enterprise-api/Dockerfile @@ -2,7 +2,7 @@ # context must be the repo root (needs both enterprise/ and proto/, like # api/Dockerfile does for api/ + proto/), not enterprise/ alone. # docker build -f enterprise/cmd/enterprise-api/Dockerfile -t cairnobs-enterprise-api . -FROM golang:1.25-alpine AS builder +FROM golang:1.26-alpine AS builder WORKDIR /src COPY . . WORKDIR /src/enterprise diff --git a/enterprise/cmd/enterprise-ingest/Dockerfile b/enterprise/cmd/enterprise-ingest/Dockerfile index 423d21b..9263315 100644 --- a/enterprise/cmd/enterprise-ingest/Dockerfile +++ b/enterprise/cmd/enterprise-ingest/Dockerfile @@ -3,7 +3,7 @@ # like enterprise-api/Dockerfile does for api/ + proto/ + enterprise/), # not enterprise/ alone. # docker build -f enterprise/cmd/enterprise-ingest/Dockerfile -t cairnobs-enterprise-ingest . -FROM golang:1.25-alpine AS builder +FROM golang:1.26-alpine AS builder WORKDIR /src COPY . . WORKDIR /src/enterprise diff --git a/ingest/Dockerfile b/ingest/Dockerfile index 55132d1..439e587 100644 --- a/ingest/Dockerfile +++ b/ingest/Dockerfile @@ -2,7 +2,7 @@ # needs both ingest/ and proto/: # docker build -f ingest/Dockerfile -t cairnobs-ingest . -FROM golang:1.25-alpine AS builder +FROM golang:1.26-alpine AS builder WORKDIR /src COPY proto ./proto COPY ingest ./ingest