Repository navigation
Conversation
Pins coder/kaniko to 8e293b69, which removes github.com/docker/docker, bumps buildkit to v0.31.2 and go-archive to v0.3.3, and vendors a fixed ACR credential helper. Fixes GO-2026-4858, GO-2026-4859, GO-2026-6255, GO-2026-6253, GO-2026-6225, and removes docker/docker (GO-2026-4883, GO-2026-4887) from the envbuilder binary. Parse Dockerfiles with an initialized linter: buildkit v0.31 applies "# check=" comments to the linter and panicked with a nil one.
…v0.21.7 go-containerregistry v0.21 holds a pull limiter slot per open remote blob reader. The previous kaniko pin deadlocked extracting base images with more than four layers, and v0.21.6 tarball.Write hangs the same way. Also close the devcontainer feature layer reader.
Lisa-Fiander
reviewed
Oct 9, 2026
| // There are a few options we need added to Kaniko! | ||
| // See: https://github.com/GoogleContainerTools/kaniko/compare/main...coder:kaniko:main | ||
| replace github.com/GoogleContainerTools/kaniko => github.com/coder/kaniko v0.0.0-20251107135632-b20ff58093d8 | ||
| replace github.com/GoogleContainerTools/kaniko => github.com/coder/kaniko v0.0.0-20261008191411-61a5b7da7ea3 |
There was a problem hiding this comment.
The pin points at an unmerged commit(v0.0.0-20261008191411-61a5b7da7ea3) - needs re-pined after merged and make sure coder/kaniko#38 is merged first
Lisa-Fiander
reviewed
Oct 9, 2026
| @@ -6,7 +6,7 @@ toolchain go1.26.6 | |||
|
|
|||
| // There are a few options we need added to Kaniko! | |||
There was a problem hiding this comment.
Not caused by this PR, but advisories published yesterday now flag toolchain go1.26.6 (12 reachable stdlib advisories, fixed in 1.26.9) and golang.org/x/net v0.58.0 (fixed in v0.60.0). Worth bumping both here or in a quick follow-up.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pins the kaniko fork to coder/kaniko#38, which drops
github.com/docker/dockerand the chrismellard ACR helper and bumps buildkit to v0.31.2. This fixes the remaining reachable advisories in envbuilder.Depends on coder/kaniko#38. The
replacepoints at61a5b7daon that PR. Later commits there only change CI and integration fixtures, not Go code. Re-pin to the merge commit once #38 lands.Test template on dogfood, which builds envbuilder from this branch: https://dogfood.cdr.dev/templates/coder/kirby-envbuilder-rollup
Advisories
govulncheck ./...(reachable):main(a5b7329)moby/buildkit)docker/docker)moby/go-archive)chrismellard/docker-credential-acr-env)govulncheck -mode=binaryoncmd/envbuilderreports only GO-2026-6443 (grpc). grpc is intentionally left alone in this PR.docker/docker, themoby/mobymonolith andchrismellard.docker/dockerandmoby/mobystay ingo.modas the Docker client for./integrationtests only. Also x/crypto openpgp and dhcp findings, which are unreachable.Changes
devcontainer.UserFromDockerfile: passes a buildkit linter toParseInstructionWithLinter. Without one, buildkit v0.31 panics on Dockerfiles with# check=directives. Test:TestUserFromDockerfile_BuildArgs/LintCheckComment.features.Extract: now closes the feature layer reader. go-containerregistry v0.21 holds a pull slot until the reader is closed.Behavior changes
COPY/ADD --exclude,COPY --parents,ADD --unpack,RUN --security=insecureandRUN --devicewith "not supported by kaniko". 1.3.0 also failed on these, as unknown flags.*.localregistries: go-containerregistry v0.21 no longer falls back to plain HTTP for them. Onlylocalhost,*.localhostand loopback IPs fall back. Plain-HTTP in-cluster registries (for exampleregistry.ns.svc.cluster.local:5000) needENVBUILDER_INSECURE=true.Validation
make testpasses (all 36 integration tests, 0 skipped), as domake lint,make fmtandmake gen(no diff).maindevcontainer (64-layer base image) builds to INIT. An earlier pin of this branch deadlocked at layer 5 (go-containerregistry pull limiter, fixed in kaniko#38).FROM <stage>andCOPY --from=golang:1.25-bookwormbuilds. The earlier pin deadlocked in "Storing source image".# check=Dockerfile builds.COPY --excludefails with the new error, and a plain Dockerfile builds.envbuilder-rollup-mainon the test template builds coder/codermain. The agent is ready,/.envbuilder/builtexists, and code-server returns healthy. The binary reportsvcs.revision=9e64f32,coder/kaniko 61a5b7daand go-containerregistry v0.21.7.replacedirectives) and its acceptance tests pass.Decision log
github.com/moby/moby/v2betas, so kaniko ports the few helpers it used instead of upgrading.tarball.Writeleaks pull slots and hangs multi-stage builds. A subagent review of the v0.19 → v0.21 diff found it, and it was reproduced locally..localHTTP fallback documented, not shimmed: it is an upstream security hardening.ENVBUILDER_INSECUREcovers kaniko pulls, pushes and the cache repo. It does not cover envbuilder's own devcontainer image config and feature fetches, which never honored it../integrationoffdocker/docker.