mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-10-02 20:29:43 +00:00
Pin hosted Go builders to refreshed 1.26.8 image
Advance the provider control-plane source builder and integration mock builder on Pulse PR #2275's reviewed 1.26.8 Alpine digest. Keep their exact compiler image locked by an installability proof and record what this does not qualify. The published prebuilt runtime path is unchanged. Change-source: pulse-maintainer
This commit is contained in:
parent
75d72f5868
commit
91d8822d76
4 changed files with 31 additions and 2 deletions
|
|
@ -12,7 +12,7 @@ COPY SECURITY.md TERMS.md /app/
|
|||
RUN --mount=type=cache,id=pulse-control-plane-npm-cache,target=/root/.npm \
|
||||
npm run build
|
||||
|
||||
FROM --platform=$BUILDPLATFORM golang:1.26.8-alpine@sha256:51a7c389a5ddaf82f527191a1e9bff9928655130a44e4975dd1d7e0acf59f1ae AS builder
|
||||
FROM --platform=$BUILDPLATFORM golang:1.26.8-alpine@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c AS builder
|
||||
ARG VERSION=dev
|
||||
ARG BUILD_TIME=unknown
|
||||
ARG GIT_COMMIT=unknown
|
||||
|
|
|
|||
|
|
@ -3724,6 +3724,13 @@ vulnerabilities in the current patch level, the canonical fix is to advance the
|
|||
governed release toolchain and immutable Go builder digest together, not to
|
||||
suppress the scanner or produce release artifacts with an older patched-over
|
||||
runtime.
|
||||
The hosted control-plane source builder and integration mock builder are both
|
||||
on the reviewed `golang:1.26.8-alpine` digest
|
||||
`sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c`.
|
||||
`TestProviderMSPGoBuilderMatchesIntegrationMock` pins their exact agreement;
|
||||
it does not pull the image, prove its registry contents, or qualify a deployed
|
||||
control plane. The release publisher's prebuilt control-plane target is a
|
||||
separate path and does not rebuild its binary from this stage.
|
||||
As of 2026-08-27, the governed release floor is Go `1.26.7`. It supersedes
|
||||
`1.26.5`, whose standard library is reachable through seven vulnerable Pulse
|
||||
call paths reported by `govulncheck`, including HTTP/TLS, URL parsing, SAML XML
|
||||
|
|
|
|||
|
|
@ -4,12 +4,34 @@ import (
|
|||
"os"
|
||||
"os/exec"
|
||||
"path/filepath"
|
||||
"regexp"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"gopkg.in/yaml.v3"
|
||||
)
|
||||
|
||||
func TestProviderMSPGoBuilderMatchesIntegrationMock(t *testing.T) {
|
||||
// These builders use the same Go patch level and immutable image. The
|
||||
// mock's build must not exercise a different compiler from the hosted
|
||||
// control plane merely because Dependabot advanced one Dockerfile.
|
||||
const expected = "golang:1.26.8-alpine@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c"
|
||||
pattern := regexp.MustCompile(`(?m)^FROM (?:--platform=\$BUILDPLATFORM )?(golang:[^[:space:]]+) AS builder$`)
|
||||
for _, path := range [][]string{
|
||||
{"deploy", "provider-msp", "Dockerfile.control-plane"},
|
||||
{"tests", "integration", "mock-github-server", "Dockerfile"},
|
||||
} {
|
||||
content, err := os.ReadFile(repoFile(path...))
|
||||
if err != nil {
|
||||
t.Fatalf("read %s: %v", filepath.Join(path...), err)
|
||||
}
|
||||
match := pattern.FindStringSubmatch(string(content))
|
||||
if len(match) != 2 || match[1] != expected {
|
||||
t.Errorf("%s Go builder = %q, want %q", filepath.Join(path...), match, expected)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestProviderMSPControlPlaneImageConsumesExactCandidate(t *testing.T) {
|
||||
dockerfileBytes, err := os.ReadFile(repoFile("deploy", "provider-msp", "Dockerfile.control-plane"))
|
||||
if err != nil {
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
FROM golang:1.26.8-alpine@sha256:51a7c389a5ddaf82f527191a1e9bff9928655130a44e4975dd1d7e0acf59f1ae AS builder
|
||||
FROM golang:1.26.8-alpine@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c AS builder
|
||||
|
||||
WORKDIR /build
|
||||
COPY go.mod ./
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue