Repository navigation
Conversation
Go 1.23 no longer gets security fixes. The image was built with Go 1.23.12, whose standard library has known vulnerabilities, among them CVE-2025-68121 (critical) in crypto/tls certificate verification, fixed in 1.24.13 and 1.25.7. The manager relies on crypto/tls for its Docker hosts in DOCKER_HOSTS_TLS. - Dockerfile and Dockerfile.dev build with golang:1.27.1-alpine3.24, pinned to the patch release and the Alpine version. The official golang images set GOTOOLCHAIN=local, so Dockerfile.dev has to follow go.mod. - go.mod: go 1.27.0, toolchain go1.27.1. - The contributing guide asks for Go 1.27+. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The versions in go.mod have known vulnerabilities: x/crypto v0.37.0 (11 high), x/net v0.34.0 (5 high) and x/text v0.24.0 (1 high), as reported by Trivy for the built image. - golang.org/x/crypto v0.37.0 => v0.57.0 - golang.org/x/net v0.34.0 => v0.59.0 - golang.org/x/text v0.24.0 => v0.42.0 - golang.org/x/sync v0.13.0 => v0.23.0 and golang.org/x/sys v0.32.0 => v0.48.0, which the new versions require. These versions need Go 1.26 or later; go.mod already asks for 1.27. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@fklnc94 is attempting to deploy a commit to the HHF Technologies' projects Team on Vercel. A member of the Team first needs to authorize it. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The image is built with Go 1.23.12, which no longer gets security fixes, and with old
golang.org/xmodules. Trivy finds 1 critical and 38 high vulnerabilities in the manager binary:crypto/tls(fixed in Go 1.24.13 and 1.25.7). The Docker client usescrypto/tlswhenDOCKER_HOSTpoints to a TLS endpoint (DOCKER_TLS_VERIFY,DOCKER_CERT_PATH).golang.org/x/cryptov0.37.0 (11),x/netv0.34.0 (5) andx/textv0.24.0 (1).Changes
DockerfileandDockerfile.devbuild withgolang:1.27.1-alpine3.24, pinned to the patch release and the Alpine version. Go 1.27 and 1.26 are the supported releases today.go.mod:go 1.27.0,toolchain go1.27.1. The official golang images setGOTOOLCHAIN=local, soDockerfile.devhas to followgo.mod.golang.org/x/cryptov0.37.0 → v0.57.0,x/netv0.34.0 → v0.59.0,x/textv0.24.0 → v0.42.0.x/syncandx/sysmove up as these require. They need Go 1.26 or later.Trivy
aquasec/trivy:0.74.0 image --scanners vuln --severity HIGH,CRITICALon the built image:dev(6c8f777)The Alpine 3.24 packages have no findings either way. At lower severities two findings remain:
github.com/docker/docker. It is a daemon bug indocker plugin install; the manager only uses the client packages.x/crypto/openpgpis unmaintained. The package is not compiled into the manager.Testing
go build ./...,go vet ./...andgo test -race ./...pass with Go 1.27.1./healthreturns 200 and both SQLite databases are created.Note
Dockerfile.devdid not build before this change either.go install github.com/cosmtrek/air@latestnow resolves to air v1.67.4, which needs Go 1.26 or later and declares its module path asgithub.com/air-verse/air. This PR only updates its base image; switching the install togithub.com/air-verse/aircan be a follow-up.🤖 Generated with Claude Code