From 91d8822d76c5a7214995c0e370be637b6e6336e3 Mon Sep 17 00:00:00 2001 From: "pulse-triage[bot]" <249995291+pulse-triage[bot]@users.noreply.github.com> Date: Tue, 29 Sep 2026 22:36:11 +0100 Subject: [PATCH] Pin hosted Go builders to refreshed 1.26.8 image Advance the provider control-plane source builder and integration mock builder on Pulse PR #2275's reviewed 1.26.8 Alpine digest. Keep their exact compiler image locked by an installability proof and record what this does not qualify. The published prebuilt runtime path is unchanged. Change-source: pulse-maintainer --- deploy/provider-msp/Dockerfile.control-plane | 2 +- .../subsystems/deployment-installability.md | 7 ++++++ .../installtests/provider_msp_deploy_test.go | 22 +++++++++++++++++++ .../integration/mock-github-server/Dockerfile | 2 +- 4 files changed, 31 insertions(+), 2 deletions(-) diff --git a/deploy/provider-msp/Dockerfile.control-plane b/deploy/provider-msp/Dockerfile.control-plane index cde348f41..3049e143e 100644 --- a/deploy/provider-msp/Dockerfile.control-plane +++ b/deploy/provider-msp/Dockerfile.control-plane @@ -12,7 +12,7 @@ COPY SECURITY.md TERMS.md /app/ RUN --mount=type=cache,id=pulse-control-plane-npm-cache,target=/root/.npm \ npm run build -FROM --platform=$BUILDPLATFORM golang:1.26.8-alpine@sha256:51a7c389a5ddaf82f527191a1e9bff9928655130a44e4975dd1d7e0acf59f1ae AS builder +FROM --platform=$BUILDPLATFORM golang:1.26.8-alpine@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c AS builder ARG VERSION=dev ARG BUILD_TIME=unknown ARG GIT_COMMIT=unknown diff --git a/docs/release-control/v6/internal/subsystems/deployment-installability.md b/docs/release-control/v6/internal/subsystems/deployment-installability.md index 96cff70a0..25b94cd23 100644 --- a/docs/release-control/v6/internal/subsystems/deployment-installability.md +++ b/docs/release-control/v6/internal/subsystems/deployment-installability.md @@ -3724,6 +3724,13 @@ vulnerabilities in the current patch level, the canonical fix is to advance the governed release toolchain and immutable Go builder digest together, not to suppress the scanner or produce release artifacts with an older patched-over runtime. +The hosted control-plane source builder and integration mock builder are both +on the reviewed `golang:1.26.8-alpine` digest +`sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c`. +`TestProviderMSPGoBuilderMatchesIntegrationMock` pins their exact agreement; +it does not pull the image, prove its registry contents, or qualify a deployed +control plane. The release publisher's prebuilt control-plane target is a +separate path and does not rebuild its binary from this stage. As of 2026-08-27, the governed release floor is Go `1.26.7`. It supersedes `1.26.5`, whose standard library is reachable through seven vulnerable Pulse call paths reported by `govulncheck`, including HTTP/TLS, URL parsing, SAML XML diff --git a/scripts/installtests/provider_msp_deploy_test.go b/scripts/installtests/provider_msp_deploy_test.go index 039e17b48..54f0659c9 100644 --- a/scripts/installtests/provider_msp_deploy_test.go +++ b/scripts/installtests/provider_msp_deploy_test.go @@ -4,12 +4,34 @@ import ( "os" "os/exec" "path/filepath" + "regexp" "strings" "testing" "gopkg.in/yaml.v3" ) +func TestProviderMSPGoBuilderMatchesIntegrationMock(t *testing.T) { + // These builders use the same Go patch level and immutable image. The + // mock's build must not exercise a different compiler from the hosted + // control plane merely because Dependabot advanced one Dockerfile. + const expected = "golang:1.26.8-alpine@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c" + pattern := regexp.MustCompile(`(?m)^FROM (?:--platform=\$BUILDPLATFORM )?(golang:[^[:space:]]+) AS builder$`) + for _, path := range [][]string{ + {"deploy", "provider-msp", "Dockerfile.control-plane"}, + {"tests", "integration", "mock-github-server", "Dockerfile"}, + } { + content, err := os.ReadFile(repoFile(path...)) + if err != nil { + t.Fatalf("read %s: %v", filepath.Join(path...), err) + } + match := pattern.FindStringSubmatch(string(content)) + if len(match) != 2 || match[1] != expected { + t.Errorf("%s Go builder = %q, want %q", filepath.Join(path...), match, expected) + } + } +} + func TestProviderMSPControlPlaneImageConsumesExactCandidate(t *testing.T) { dockerfileBytes, err := os.ReadFile(repoFile("deploy", "provider-msp", "Dockerfile.control-plane")) if err != nil { diff --git a/tests/integration/mock-github-server/Dockerfile b/tests/integration/mock-github-server/Dockerfile index 93a38d356..af4acf087 100644 --- a/tests/integration/mock-github-server/Dockerfile +++ b/tests/integration/mock-github-server/Dockerfile @@ -1,4 +1,4 @@ -FROM golang:1.26.8-alpine@sha256:51a7c389a5ddaf82f527191a1e9bff9928655130a44e4975dd1d7e0acf59f1ae AS builder +FROM golang:1.26.8-alpine@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c AS builder WORKDIR /build COPY go.mod ./