Pin hosted Go builders to refreshed 1.26.8 image

Advance the provider control-plane source builder and integration mock builder
on Pulse PR #2275's reviewed 1.26.8 Alpine digest. Keep their exact compiler
image locked by an installability proof and record what this does not qualify.
The published prebuilt runtime path is unchanged.

Change-source: pulse-maintainer
This commit is contained in:
pulse-triage[bot] 2026-09-29 22:36:11 +01:00
parent 75d72f5868
commit 91d8822d76
4 changed files with 31 additions and 2 deletions

View file

@ -12,7 +12,7 @@ COPY SECURITY.md TERMS.md /app/
RUN --mount=type=cache,id=pulse-control-plane-npm-cache,target=/root/.npm \
npm run build
FROM --platform=$BUILDPLATFORM golang:1.26.8-alpine@sha256:51a7c389a5ddaf82f527191a1e9bff9928655130a44e4975dd1d7e0acf59f1ae AS builder
FROM --platform=$BUILDPLATFORM golang:1.26.8-alpine@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c AS builder
ARG VERSION=dev
ARG BUILD_TIME=unknown
ARG GIT_COMMIT=unknown

View file

@ -3724,6 +3724,13 @@ vulnerabilities in the current patch level, the canonical fix is to advance the
governed release toolchain and immutable Go builder digest together, not to
suppress the scanner or produce release artifacts with an older patched-over
runtime.
The hosted control-plane source builder and integration mock builder are both
on the reviewed `golang:1.26.8-alpine` digest
`sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c`.
`TestProviderMSPGoBuilderMatchesIntegrationMock` pins their exact agreement;
it does not pull the image, prove its registry contents, or qualify a deployed
control plane. The release publisher's prebuilt control-plane target is a
separate path and does not rebuild its binary from this stage.
As of 2026-08-27, the governed release floor is Go `1.26.7`. It supersedes
`1.26.5`, whose standard library is reachable through seven vulnerable Pulse
call paths reported by `govulncheck`, including HTTP/TLS, URL parsing, SAML XML

View file

@ -4,12 +4,34 @@ import (
"os"
"os/exec"
"path/filepath"
"regexp"
"strings"
"testing"
"gopkg.in/yaml.v3"
)
func TestProviderMSPGoBuilderMatchesIntegrationMock(t *testing.T) {
// These builders use the same Go patch level and immutable image. The
// mock's build must not exercise a different compiler from the hosted
// control plane merely because Dependabot advanced one Dockerfile.
const expected = "golang:1.26.8-alpine@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c"
pattern := regexp.MustCompile(`(?m)^FROM (?:--platform=\$BUILDPLATFORM )?(golang:[^[:space:]]+) AS builder$`)
for _, path := range [][]string{
{"deploy", "provider-msp", "Dockerfile.control-plane"},
{"tests", "integration", "mock-github-server", "Dockerfile"},
} {
content, err := os.ReadFile(repoFile(path...))
if err != nil {
t.Fatalf("read %s: %v", filepath.Join(path...), err)
}
match := pattern.FindStringSubmatch(string(content))
if len(match) != 2 || match[1] != expected {
t.Errorf("%s Go builder = %q, want %q", filepath.Join(path...), match, expected)
}
}
}
func TestProviderMSPControlPlaneImageConsumesExactCandidate(t *testing.T) {
dockerfileBytes, err := os.ReadFile(repoFile("deploy", "provider-msp", "Dockerfile.control-plane"))
if err != nil {

View file

@ -1,4 +1,4 @@
FROM golang:1.26.8-alpine@sha256:51a7c389a5ddaf82f527191a1e9bff9928655130a44e4975dd1d7e0acf59f1ae AS builder
FROM golang:1.26.8-alpine@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c AS builder
WORKDIR /build
COPY go.mod ./