Skip to content

fix: clear remaining scanner findings (stacked on #535) - #536

Closed
coder[bot] wants to merge 8 commits into
stirby/kaniko-mobyfrom
stirby/envbuilder-zero-vulns
Closed

coder[bot] wants to merge 8 commits into
stirby/kaniko-mobyfrom
stirby/envbuilder-zero-vulns

Conversation

@coder

@coder coder Bot commented Oct 11, 2026

Copy link
Copy Markdown

Stacked on #535 (stirby/kaniko-moby). Goal: get every package/container scanner to report zero findings by upgrading or removing flagged dependencies instead of leaving them as "not affected".

Generated by Coder Agents on behalf of @stirby.

Depends on coder/kaniko#40 (stirby/kaniko-containerd-platforms, 76b64cc0), which is stacked on coder/kaniko#38. The kaniko replace points at that unmerged commit. Re-pin it once the kaniko change lands.

Summary

This drops the scanner findings from 116 to 5. grype on the image now reports 0. Every remaining finding is the same advisory, GO-2026-5932 (golang.org/x/crypto/openpgp). It lists every x/crypto version as affected and has no fixed version. envbuilder doesn't import openpgp. See Unresolved.

Before / after

Tools: trivy 0.75.0, grype 0.120.1, govulncheck v1.8.0 (vuln.go.dev DB 2026-10-08). The image is built with scripts/build.sh --arch=amd64. It is FROM scratch with no OS packages, so the only scanned target is the Go binary.

Scanner Before After Remaining
govulncheck -show verbose ./... 16 (12 symbol, 2 package, 2 module) 1 (module only, not called) GO-2026-5932
govulncheck -mode=binary 15 1 (module only, not called) GO-2026-5932
trivy fs --scanners vuln . 17 1 GO-2026-5932
grype dir:. 31 1 GO-2026-5932
trivy image 20 1 GO-2026-5932
grype image 17 0
Baseline findings by advisory
ID(s) Module Installed Fixed Scanners Resolution
GO-2026-6599/6600/6603/6604/6605/6607/6608/6609/6610/6611/6612/6613/6617 (+CVE aliases) stdlib go1.26.6 1.26.9 all except trivy fs Go 1.26.9
GO-2026-6603/6610/6611/6612/6617 (CVE-2026-78659/78660/78663/78669/97032) golang.org/x/net v0.58.0 v0.60.0 all bumped
GO-2026-6443 / GHSA-2v4p-qf9q-27wj / CVE-2026-84445 google.golang.org/grpc v1.83.1 v1.83.2 all bumped
GO-2026-6237 github.com/insomniacslk/dhcp 2023-12-06 pseudo 2026-07-19 pseudo govulncheck, grype dir bumped to 2026-09-01 pseudo
GHSA-xhgw-qwwf-pg32 / CVE-2026-10722 github.com/cilium/ebpf v0.16.0 v0.22.0 trivy fs, grype dir bumped
CVE-2026-33997/41567/41568/42306, GO-2026-4887, GHSA-pxq6/rg2x/vp62/x86f github.com/docker/docker v28.5.2+incompatible none / 29.3.1 trivy fs, grype dir removed from module graph
CVE-2026-34040/33997/41567/41568/42306, GHSA-x744/pxq6/rg2x/vp62/x86f github.com/moby/moby v28.3.0+incompatible none / 29.3.1 trivy fs, grype dir removed from module graph
GHSA-q3fv-x8vg-qqm4, GHSA-mcj4-mphf-j9ff, GHSA-8rc5-4fr6-64pw github.com/aquasecurity/trivy v0.61.1 pseudo 0.72.0 grype dir required v0.72.0
GHSA-xjvp-4fhw-gc47 github.com/opencontainers/runc v1.2.8 1.3.6 grype dir required v1.3.6
GO-2026-5064/5338/5622, GHSA-fqw6/jpcc/xhf5/7jxh/pg57 github.com/containerd/containerd v1.7.29 none for v1 (GO), 1.7.32 to 1.7.36 (GHSA) grype dir removed from module graph (kaniko change)
GO-2026-5932 golang.org/x/crypto v0.56.0 none all except grype image bumped to v0.58.0; unresolved

Changes

  • fix: build with Go 1.26.9: the stdlib fixes. The last commit turns this into go 1.26.9, because the kaniko fork now declares it.
  • fix: bump golang.org/x/net to v0.60.0 and google.golang.org/grpc to v1.83.2: golang.org/x/crypto also moves to v0.58.0, and the other x/ modules move with them.
  • fix: bump tailscale transitive deps: insomniacslk/dhcp and cilium/ebpf. Both come in through coder/tailscale, which coder/coder pulls in.
  • test(integration): migrate Docker client to moby/moby/client and moby/moby/api: this removes docker/docker and the moby/moby monolith from go.mod and go.sum. The monolith was only being selected because docker/cli (+incompatible, no go.mod) imports moby/moby/api/types/network. Requiring the split moby/moby/api module resolves that import instead.
  • fix: require opencontainers/runc v1.3.6, aquasecurity/trivy v0.72.0: neither module ends up in the binary. They're only reached through coder/coder test packages (dbtestutil/dockertest, coderdtest/preview). But go mod tidy records their checksums in go.sum, and grype dir:. reports them from there.
  • fix: require containerd/containerd v1.7.36 was an intermediate step. fix: pin kaniko without containerd v1 and drop containerd/containerd replaces it: it re-pins kaniko to coder/kaniko@76b64cc0, which imports github.com/containerd/platforms instead. containerd v1 is no longer in the module graph.

Behavior changes

  • Runtime code is unchanged. The binary's module set changes only through version bumps: the x/ modules, grpc, and dhcp. Requiring trivy v0.72.0 also makes MVS raise aws-sdk-go-v2/service/ecr (v1.27.4 to v1.57.2, used by the ECR credential helper), go-redis/v9 (v9.7.3 to v9.20.0), zap (v1.27.1 to v1.28.0) and gopsutil/v4 (v4.26.2 to v4.26.3).
  • The kaniko re-pin also brings in the fix: drop docker/docker and the chrismellard ACR helper, bump buildkit to v0.31.2 kaniko#38 commits that landed after 61a5b7da: ACR token handling updates, Go 1.26.9, and test/CI fixes.
  • go.mod now declares go 1.26.9 (previously go 1.26.5 + toolchain go1.26.9).
  • Integration tests use the moby client v0.6 API (options and result structs). Test coverage is unchanged.

Validation

  • make lint, make fmt, make gen (including scripts/docsgen): clean, no diff.
  • make test (unit and integration, local registry via make test-registry): 348 passed, 3 skipped, 0 failed in two consecutive full runs at the final commit.
    • Skipped tests (existing t.Skips): git TestShallowCloneRepo/OK, TestCloneRepo/invalid_auth/AlreadyCloned, TestCloneRepo/auth_but_no_creds/AlreadyCloned.
    • An earlier run on this branch had one flake: TestCloneFailsFallback/BadRepo, where OpenFile(/.envbuilder/Dockerfile) returned ENOENT. It hasn't reproduced since, in 3 isolated and 4 full runs, and it passes on the fix: drop docker/docker and bump buildkit to v0.31.2 via the kaniko fork #535 base.
  • Rebuilt the image and reran all six scans (table above).
  • Smoke test: ran the built image against a workspace with .devcontainer/Dockerfile and devcontainer.json. It built the image, ran postCreateCommand, and reached the init script (SMOKE_INIT_OK).

Decision log

  • Bump in envbuilder, don't drop coder/coder. coder/coder brings in tailscale, trivy, dockertest and runc only for log streaming (agentsdk and agent/proto dRPC). Replacing it would mean a protocol reimplementation, which is out of scope.
  • Did not replace trivy with github.com/coder/trivy, which is what coder/coder does. That fork is based on v0.69.3 and doesn't include the fixes, so it would only hide the findings by changing the module path. I required upstream v0.72.0 (the lowest fixed version) instead. v0.75.0 needs Go 1.27 and pulls in buildkit and go-containerregistry upgrades.
  • Fixed containerd in kaniko, not here. Every v1 release is affected by the CRI advisories. kaniko only used v1 for platforms, which already lives in the github.com/containerd/platforms module.
  • Did not pin x/crypto to an untagged master pseudo-version. The vuln DB still lists all versions as affected, so scanners would keep flagging it. It would also put unreleased x/crypto into a release.
  • Kept Go on 1.26.x (1.26.9) instead of moving to 1.27.2: it's the smallest change that fixes the stdlib findings.

Unresolved

  • GO-2026-5932 (golang.org/x/crypto/openpgp). envbuilder never imports openpgp; govulncheck reports it at module level only. Upstream x/crypto split openpgp out and deleted it on master (commits 2f1f834..99e4382, 2026-10-09). Once x/crypto v0.59.0 is tagged and vuln.go.dev marks it fixed, bumping x/crypto will clear this from every scanner.
  • Before merge: re-pin the kaniko replace once stirby/kaniko-containerd-platforms lands.

default added 8 commits October 11, 2026 00:50
…/moby/api

Drops github.com/docker/docker and the github.com/moby/moby monolith from
the module graph. The monolith was only selected because docker/cli
(+incompatible, no go.mod) imports moby/moby/api/types/network; requiring
the split moby/moby/api module resolves that import instead.
runc is only reached through a coder/coder test dependency (ory/dockertest),
but its checksum is recorded in go.sum, which module scanners report.
trivy is only reached through coder/coder test packages (coderdtest via
coder/preview), but its checksum is recorded in go.sum, which module
scanners report. v0.72.0 is the lowest release that fixes the reported
advisories; MVS also raises aws-sdk-go-v2/service/ecr, go-redis, zap and
gopsutil in the binary.
containerd v1 is only reached through kaniko's pkg/executor tests, but its
checksum is recorded in go.sum. v1.7.36 clears the advisories that have a
v1.7 fix; the remaining CRI advisories affect every v1 release.
Re-pins the kaniko fork to coder/kaniko@76b64cc0, which imports platforms
from github.com/containerd/platforms instead of containerd v1. containerd
v1 is no longer in the module graph, so the v1.7.36 requirement is
dropped. The fork now declares go 1.26.9, which raises the go directive
here and makes the separate toolchain line redundant.
@coder coder Bot assigned stirby Oct 11, 2026
@coder
coder Bot requested a review from johnstcn October 11, 2026 01:12
@stirby stirby closed this Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant