Skip to content

Build with Go 1.27.1 and update golang.org/x/crypto, x/net and x/text - #138

Open
fklnc94 wants to merge 2 commits into
hhftechnology:devfrom
fklnc94:build/go-1.27-security
Open

fklnc94 wants to merge 2 commits into
hhftechnology:devfrom
fklnc94:build/go-1.27-security

Conversation

@fklnc94

@fklnc94 fklnc94 commented Sep 29, 2026

Copy link
Copy Markdown

The image is built with Go 1.23.12, which no longer gets security fixes, and with old golang.org/x modules. Trivy finds 1 critical and 38 high vulnerabilities in the manager binary:

  • 22 in the Go 1.23.12 standard library, including the critical one: CVE-2025-68121, incorrect certificate validation in crypto/tls (fixed in Go 1.24.13 and 1.25.7). The Docker client uses crypto/tls when DOCKER_HOST points to a TLS endpoint (DOCKER_TLS_VERIFY, DOCKER_CERT_PATH).
  • 17 in golang.org/x/crypto v0.37.0 (11), x/net v0.34.0 (5) and x/text v0.24.0 (1).

Changes

  • Dockerfile and Dockerfile.dev build with golang:1.27.1-alpine3.24, pinned to the patch release and the Alpine version. Go 1.27 and 1.26 are the supported releases today.
  • go.mod: go 1.27.0, toolchain go1.27.1. The official golang images set GOTOOLCHAIN=local, so Dockerfile.dev has to follow go.mod.
  • golang.org/x/crypto v0.37.0 → v0.57.0, x/net v0.34.0 → v0.59.0, x/text v0.24.0 → v0.42.0. x/sync and x/sys move up as these require. They need Go 1.26 or later.
  • The contributing guide asks for Go 1.27+.

Trivy

aquasec/trivy:0.74.0 image --scanners vuln --severity HIGH,CRITICAL on the built image:

Critical High
dev (6c8f777) 1 38
this PR 0 0

The Alpine 3.24 packages have no findings either way. At lower severities two findings remain:

  • MEDIUM CVE-2026-33997 in github.com/docker/docker. It is a daemon bug in docker plugin install; the manager only uses the client packages.
  • GO-2026-5932: x/crypto/openpgp is unmaintained. The package is not compiled into the manager.

Testing

  • go build ./..., go vet ./... and go test -race ./... pass with Go 1.27.1.
  • The image builds with CGO and go-sqlite3. The container starts, /health returns 200 and both SQLite databases are created.

Note

Dockerfile.dev did not build before this change either. go install github.com/cosmtrek/air@latest now resolves to air v1.67.4, which needs Go 1.26 or later and declares its module path as github.com/air-verse/air. This PR only updates its base image; switching the install to github.com/air-verse/air can be a follow-up.

🤖 Generated with Claude Code

fklnc94 and others added 2 commits September 29, 2026 23:09
Go 1.23 no longer gets security fixes. The image was built with Go
1.23.12, whose standard library has known vulnerabilities, among them
CVE-2025-68121 (critical) in crypto/tls certificate verification, fixed
in 1.24.13 and 1.25.7. The manager relies on crypto/tls for its Docker
hosts in DOCKER_HOSTS_TLS.

- Dockerfile and Dockerfile.dev build with golang:1.27.1-alpine3.24,
  pinned to the patch release and the Alpine version. The official
  golang images set GOTOOLCHAIN=local, so Dockerfile.dev has to follow
  go.mod.
- go.mod: go 1.27.0, toolchain go1.27.1.
- The contributing guide asks for Go 1.27+.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The versions in go.mod have known vulnerabilities: x/crypto v0.37.0
(11 high), x/net v0.34.0 (5 high) and x/text v0.24.0 (1 high), as
reported by Trivy for the built image.

- golang.org/x/crypto v0.37.0 => v0.57.0
- golang.org/x/net v0.34.0 => v0.59.0
- golang.org/x/text v0.24.0 => v0.42.0
- golang.org/x/sync v0.13.0 => v0.23.0 and golang.org/x/sys v0.32.0 =>
  v0.48.0, which the new versions require.

These versions need Go 1.26 or later; go.mod already asks for 1.27.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 29, 2026

Copy link
Copy Markdown

@fklnc94 is attempting to deploy a commit to the HHF Technologies' projects Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: df40496c-f135-4784-8b7c-1c93f2afb509

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant