Move the Go toolchain pins to 1.26, in CI and in every image
Two Dependabot PRs are stuck behind the same number. #35 raises the go directive to 1.26.0 in six modules, because golang.org/x/crypto v0.56.0 requires it -- x/crypto tracks the two most recent Go releases and 0.56 dropped 1.25. A module that says 1.26 cannot be built by the 1.25 this repository pins in two places, so that PR fails every Go job. #29 raises actions/setup-go to v7, which sets GOTOOLCHAIN=local. With that set, `go install golang.org/x/vuln/cmd/govulncheck@latest` cannot quietly fetch a newer toolchain, and stops with golang.org/x/[email protected] requires go >= 1.26.0 (running go 1.25.14) Under setup-go v5 the same install succeeded by downloading 1.26 behind our backs, which is its own reason to be on 1.26 deliberately instead. So: security-scan's go-version and all eight Dockerfiles move together, 1.25 -> 1.26. Nothing else needs to. A newer toolchain builds an older directive happily, so this stands on its own before #35 lands, and the go.mod files stay where they are here. Checked by building rather than by reading: the api and ingest images both build on golang:1.26-alpine, and api, ingest and enterprise still `go build ./...` clean against their existing 1.25 directives.
This commit is contained in:
@@ -58,17 +58,18 @@ jobs:
|
|||||||
- uses: actions/setup-go@v5
|
- uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
# Deliberately NOT go-version-file. Each go.mod pins an exact
|
# Deliberately NOT go-version-file. Each go.mod pins an exact
|
||||||
# patch (`go 1.25.0`), so go-version-file made CI scan against
|
# patch, so go-version-file made CI scan against the *unpatched*
|
||||||
# the *unpatched* 1.25.0 standard library and fail on 28
|
# standard library of that patch and fail on 28 stdlib CVEs --
|
||||||
# stdlib CVEs -- crypto/x509 quadratic name-constraint parsing
|
# crypto/x509 quadratic name-constraint parsing (GO-2025-4007)
|
||||||
# (GO-2025-4007) and friends, all fixed in 1.25.3. None of it
|
# and friends, all long since fixed. None of it was real: every
|
||||||
# was real: every Dockerfile builds `FROM golang:1.25-alpine`,
|
# Dockerfile builds `FROM golang:1.26-alpine`, a floating tag
|
||||||
# a floating tag that resolves to the newest 1.25.x, so the
|
# that resolves to the newest 1.26.x, so the shipped binaries
|
||||||
# shipped binaries already had the fixes. The go directive
|
# already had the fixes. The go directive states the minimum
|
||||||
# states the minimum language version, not the toolchain to
|
# language version, not the toolchain to audit with. Track the
|
||||||
# audit with. Track the floating 1.25 line so this scans what
|
# floating 1.26 line so this scans what production actually
|
||||||
# production actually builds.
|
# builds, and keep it in step with the Dockerfiles above all --
|
||||||
go-version: '1.25'
|
# a mismatch here fails every module at once.
|
||||||
|
go-version: '1.26'
|
||||||
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
|
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
|
||||||
- name: Check for known vulnerabilities
|
- name: Check for known vulnerabilities
|
||||||
working-directory: ${{ matrix.module_dir }}
|
working-directory: ${{ matrix.module_dir }}
|
||||||
|
|||||||
+1
-1
@@ -2,7 +2,7 @@
|
|||||||
# so unlike api/ingest/search this build context is just alerting/ itself,
|
# so unlike api/ingest/search this build context is just alerting/ itself,
|
||||||
# same shape as cli/Dockerfile:
|
# same shape as cli/Dockerfile:
|
||||||
# docker build -f alerting/Dockerfile -t cairnobs-alerting alerting/
|
# docker build -f alerting/Dockerfile -t cairnobs-alerting alerting/
|
||||||
FROM golang:1.25-alpine AS builder
|
FROM golang:1.26-alpine AS builder
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/alerting ./cmd/alerting
|
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/alerting ./cmd/alerting
|
||||||
|
|||||||
+1
-1
@@ -3,7 +3,7 @@
|
|||||||
# Go bindings via the `replace` directive in api/go.mod):
|
# Go bindings via the `replace` directive in api/go.mod):
|
||||||
# docker build -f api/Dockerfile -t cairnobs-api .
|
# docker build -f api/Dockerfile -t cairnobs-api .
|
||||||
|
|
||||||
FROM golang:1.25-alpine AS builder
|
FROM golang:1.26-alpine AS builder
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY proto ./proto
|
COPY proto ./proto
|
||||||
COPY api ./api
|
COPY api ./api
|
||||||
|
|||||||
+1
-1
@@ -1,5 +1,5 @@
|
|||||||
# docker build -f cli/Dockerfile -t cairnobsctl cli/
|
# docker build -f cli/Dockerfile -t cairnobsctl cli/
|
||||||
FROM golang:1.25-alpine AS builder
|
FROM golang:1.26-alpine AS builder
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/cairnobsctl ./cmd/cairnobsctl
|
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/cairnobsctl ./cmd/cairnobsctl
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
# (alerting/Dockerfile, enterprise/Dockerfile) -- context is
|
# (alerting/Dockerfile, enterprise/Dockerfile) -- context is
|
||||||
# deploy/operator/ itself, no /proto dependency.
|
# deploy/operator/ itself, no /proto dependency.
|
||||||
# docker build -f deploy/operator/Dockerfile -t cairnobs-tenant-operator deploy/operator/
|
# docker build -f deploy/operator/Dockerfile -t cairnobs-tenant-operator deploy/operator/
|
||||||
FROM golang:1.25-alpine AS builder
|
FROM golang:1.26-alpine AS builder
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/tenant-operator ./cmd/tenant-operator
|
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/tenant-operator ./cmd/tenant-operator
|
||||||
|
|||||||
@@ -14,7 +14,7 @@
|
|||||||
# enterprise-api's and enterprise-ingest's Dockerfiles already use for
|
# enterprise-api's and enterprise-ingest's Dockerfiles already use for
|
||||||
# the identical reason.
|
# the identical reason.
|
||||||
# docker build -f enterprise/Dockerfile -t cairnobs-enterprise-auth .
|
# docker build -f enterprise/Dockerfile -t cairnobs-enterprise-auth .
|
||||||
FROM golang:1.25-alpine AS builder
|
FROM golang:1.26-alpine AS builder
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY . .
|
COPY . .
|
||||||
WORKDIR /src/enterprise
|
WORKDIR /src/enterprise
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
# context must be the repo root (needs both enterprise/ and proto/, like
|
# context must be the repo root (needs both enterprise/ and proto/, like
|
||||||
# api/Dockerfile does for api/ + proto/), not enterprise/ alone.
|
# api/Dockerfile does for api/ + proto/), not enterprise/ alone.
|
||||||
# docker build -f enterprise/cmd/enterprise-api/Dockerfile -t cairnobs-enterprise-api .
|
# docker build -f enterprise/cmd/enterprise-api/Dockerfile -t cairnobs-enterprise-api .
|
||||||
FROM golang:1.25-alpine AS builder
|
FROM golang:1.26-alpine AS builder
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY . .
|
COPY . .
|
||||||
WORKDIR /src/enterprise
|
WORKDIR /src/enterprise
|
||||||
|
|||||||
@@ -3,7 +3,7 @@
|
|||||||
# like enterprise-api/Dockerfile does for api/ + proto/ + enterprise/),
|
# like enterprise-api/Dockerfile does for api/ + proto/ + enterprise/),
|
||||||
# not enterprise/ alone.
|
# not enterprise/ alone.
|
||||||
# docker build -f enterprise/cmd/enterprise-ingest/Dockerfile -t cairnobs-enterprise-ingest .
|
# docker build -f enterprise/cmd/enterprise-ingest/Dockerfile -t cairnobs-enterprise-ingest .
|
||||||
FROM golang:1.25-alpine AS builder
|
FROM golang:1.26-alpine AS builder
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY . .
|
COPY . .
|
||||||
WORKDIR /src/enterprise
|
WORKDIR /src/enterprise
|
||||||
|
|||||||
+1
-1
@@ -2,7 +2,7 @@
|
|||||||
# needs both ingest/ and proto/:
|
# needs both ingest/ and proto/:
|
||||||
# docker build -f ingest/Dockerfile -t cairnobs-ingest .
|
# docker build -f ingest/Dockerfile -t cairnobs-ingest .
|
||||||
|
|
||||||
FROM golang:1.25-alpine AS builder
|
FROM golang:1.26-alpine AS builder
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY proto ./proto
|
COPY proto ./proto
|
||||||
COPY ingest ./ingest
|
COPY ingest ./ingest
|
||||||
|
|||||||
Reference in New Issue
Block a user