Merge pull request #41 from Coffey-Labs/go-1.26-pins

Move the Go toolchain pins to 1.26, in CI and in every image
This commit is contained in:
jcoffey
2026-09-10 09:58:08 -07:00
committed by GitHub
9 changed files with 20 additions and 19 deletions
+12 -11
View File
@@ -58,17 +58,18 @@ jobs:
- uses: actions/setup-go@v5
with:
# Deliberately NOT go-version-file. Each go.mod pins an exact
# patch (`go 1.25.0`), so go-version-file made CI scan against
# the *unpatched* 1.25.0 standard library and fail on 28
# stdlib CVEs -- crypto/x509 quadratic name-constraint parsing
# (GO-2025-4007) and friends, all fixed in 1.25.3. None of it
# was real: every Dockerfile builds `FROM golang:1.25-alpine`,
# a floating tag that resolves to the newest 1.25.x, so the
# shipped binaries already had the fixes. The go directive
# states the minimum language version, not the toolchain to
# audit with. Track the floating 1.25 line so this scans what
# production actually builds.
go-version: '1.25'
# patch, so go-version-file made CI scan against the *unpatched*
# standard library of that patch and fail on 28 stdlib CVEs --
# crypto/x509 quadratic name-constraint parsing (GO-2025-4007)
# and friends, all long since fixed. None of it was real: every
# Dockerfile builds `FROM golang:1.26-alpine`, a floating tag
# that resolves to the newest 1.26.x, so the shipped binaries
# already had the fixes. The go directive states the minimum
# language version, not the toolchain to audit with. Track the
# floating 1.26 line so this scans what production actually
# builds, and keep it in step with the Dockerfiles above all --
# a mismatch here fails every module at once.
go-version: '1.26'
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
- name: Check for known vulnerabilities
working-directory: ${{ matrix.module_dir }}
+1 -1
View File
@@ -2,7 +2,7 @@
# so unlike api/ingest/search this build context is just alerting/ itself,
# same shape as cli/Dockerfile:
# docker build -f alerting/Dockerfile -t cairnobs-alerting alerting/
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder
WORKDIR /src
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/alerting ./cmd/alerting
+1 -1
View File
@@ -3,7 +3,7 @@
# Go bindings via the `replace` directive in api/go.mod):
# docker build -f api/Dockerfile -t cairnobs-api .
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder
WORKDIR /src
COPY proto ./proto
COPY api ./api
+1 -1
View File
@@ -1,5 +1,5 @@
# docker build -f cli/Dockerfile -t cairnobsctl cli/
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder
WORKDIR /src
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/cairnobsctl ./cmd/cairnobsctl
+1 -1
View File
@@ -2,7 +2,7 @@
# (alerting/Dockerfile, enterprise/Dockerfile) -- context is
# deploy/operator/ itself, no /proto dependency.
# docker build -f deploy/operator/Dockerfile -t cairnobs-tenant-operator deploy/operator/
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder
WORKDIR /src
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/tenant-operator ./cmd/tenant-operator
+1 -1
View File
@@ -14,7 +14,7 @@
# enterprise-api's and enterprise-ingest's Dockerfiles already use for
# the identical reason.
# docker build -f enterprise/Dockerfile -t cairnobs-enterprise-auth .
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder
WORKDIR /src
COPY . .
WORKDIR /src/enterprise
+1 -1
View File
@@ -2,7 +2,7 @@
# context must be the repo root (needs both enterprise/ and proto/, like
# api/Dockerfile does for api/ + proto/), not enterprise/ alone.
# docker build -f enterprise/cmd/enterprise-api/Dockerfile -t cairnobs-enterprise-api .
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder
WORKDIR /src
COPY . .
WORKDIR /src/enterprise
+1 -1
View File
@@ -3,7 +3,7 @@
# like enterprise-api/Dockerfile does for api/ + proto/ + enterprise/),
# not enterprise/ alone.
# docker build -f enterprise/cmd/enterprise-ingest/Dockerfile -t cairnobs-enterprise-ingest .
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder
WORKDIR /src
COPY . .
WORKDIR /src/enterprise
+1 -1
View File
@@ -2,7 +2,7 @@
# needs both ingest/ and proto/:
# docker build -f ingest/Dockerfile -t cairnobs-ingest .
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder
WORKDIR /src
COPY proto ./proto
COPY ingest ./ingest