Repository navigation
fix: clear remaining scanner findings (stacked on #535) - #536
Closed
coder[bot] wants to merge 8 commits into
Closed
coder[bot] wants to merge 8 commits into
coder[bot] wants to merge 8 commits into
Conversation
added 8 commits
October 11, 2026 00:50
…/moby/api Drops github.com/docker/docker and the github.com/moby/moby monolith from the module graph. The monolith was only selected because docker/cli (+incompatible, no go.mod) imports moby/moby/api/types/network; requiring the split moby/moby/api module resolves that import instead.
runc is only reached through a coder/coder test dependency (ory/dockertest), but its checksum is recorded in go.sum, which module scanners report.
trivy is only reached through coder/coder test packages (coderdtest via coder/preview), but its checksum is recorded in go.sum, which module scanners report. v0.72.0 is the lowest release that fixes the reported advisories; MVS also raises aws-sdk-go-v2/service/ecr, go-redis, zap and gopsutil in the binary.
containerd v1 is only reached through kaniko's pkg/executor tests, but its checksum is recorded in go.sum. v1.7.36 clears the advisories that have a v1.7 fix; the remaining CRI advisories affect every v1 release.
Re-pins the kaniko fork to coder/kaniko@76b64cc0, which imports platforms from github.com/containerd/platforms instead of containerd v1. containerd v1 is no longer in the module graph, so the v1.7.36 requirement is dropped. The fork now declares go 1.26.9, which raises the go directive here and makes the separate toolchain line redundant.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #535 (
stirby/kaniko-moby). Goal: get every package/container scanner to report zero findings by upgrading or removing flagged dependencies instead of leaving them as "not affected".Depends on coder/kaniko#40 (
stirby/kaniko-containerd-platforms,76b64cc0), which is stacked on coder/kaniko#38. The kanikoreplacepoints at that unmerged commit. Re-pin it once the kaniko change lands.Summary
This drops the scanner findings from 116 to 5.
grypeon the image now reports 0. Every remaining finding is the same advisory, GO-2026-5932 (golang.org/x/crypto/openpgp). It lists every x/crypto version as affected and has no fixed version. envbuilder doesn't import openpgp. See Unresolved.Before / after
Tools: trivy 0.75.0, grype 0.120.1, govulncheck v1.8.0 (vuln.go.dev DB 2026-10-08). The image is built with
scripts/build.sh --arch=amd64. It isFROM scratchwith no OS packages, so the only scanned target is the Go binary.govulncheck -show verbose ./...govulncheck -mode=binarytrivy fs --scanners vuln .grype dir:.trivy imagegrypeimageBaseline findings by advisory
Changes
fix: build with Go 1.26.9: the stdlib fixes. The last commit turns this intogo 1.26.9, because the kaniko fork now declares it.fix: bump golang.org/x/net to v0.60.0 and google.golang.org/grpc to v1.83.2:golang.org/x/cryptoalso moves to v0.58.0, and the other x/ modules move with them.fix: bump tailscale transitive deps:insomniacslk/dhcpandcilium/ebpf. Both come in through coder/tailscale, which coder/coder pulls in.test(integration): migrate Docker client to moby/moby/client and moby/moby/api: this removesdocker/dockerand themoby/mobymonolith from go.mod and go.sum. The monolith was only being selected because docker/cli (+incompatible, no go.mod) importsmoby/moby/api/types/network. Requiring the splitmoby/moby/apimodule resolves that import instead.fix: require opencontainers/runc v1.3.6,aquasecurity/trivy v0.72.0: neither module ends up in the binary. They're only reached through coder/coder test packages (dbtestutil/dockertest,coderdtest/preview). Butgo mod tidyrecords their checksums in go.sum, andgrype dir:.reports them from there.fix: require containerd/containerd v1.7.36was an intermediate step.fix: pin kaniko without containerd v1 and drop containerd/containerdreplaces it: it re-pins kaniko tocoder/kaniko@76b64cc0, which importsgithub.com/containerd/platformsinstead. containerd v1 is no longer in the module graph.Behavior changes
aws-sdk-go-v2/service/ecr(v1.27.4 to v1.57.2, used by the ECR credential helper),go-redis/v9(v9.7.3 to v9.20.0),zap(v1.27.1 to v1.28.0) andgopsutil/v4(v4.26.2 to v4.26.3).61a5b7da: ACR token handling updates, Go 1.26.9, and test/CI fixes.go.modnow declaresgo 1.26.9(previouslygo 1.26.5+toolchain go1.26.9).Validation
make lint,make fmt,make gen(includingscripts/docsgen): clean, no diff.make test(unit and integration, local registry viamake test-registry): 348 passed, 3 skipped, 0 failed in two consecutive full runs at the final commit.t.Skips):gitTestShallowCloneRepo/OK,TestCloneRepo/invalid_auth/AlreadyCloned,TestCloneRepo/auth_but_no_creds/AlreadyCloned.TestCloneFailsFallback/BadRepo, whereOpenFile(/.envbuilder/Dockerfile)returned ENOENT. It hasn't reproduced since, in 3 isolated and 4 full runs, and it passes on the fix: drop docker/docker and bump buildkit to v0.31.2 via the kaniko fork #535 base..devcontainer/Dockerfileanddevcontainer.json. It built the image, ranpostCreateCommand, and reached the init script (SMOKE_INIT_OK).Decision log
agentsdkandagent/protodRPC). Replacing it would mean a protocol reimplementation, which is out of scope.github.com/coder/trivy, which is what coder/coder does. That fork is based on v0.69.3 and doesn't include the fixes, so it would only hide the findings by changing the module path. I required upstream v0.72.0 (the lowest fixed version) instead. v0.75.0 needs Go 1.27 and pulls in buildkit and go-containerregistry upgrades.platforms, which already lives in thegithub.com/containerd/platformsmodule.Unresolved
golang.org/x/crypto/openpgp). envbuilder never imports openpgp; govulncheck reports it at module level only. Upstream x/crypto split openpgp out and deleted it on master (commits2f1f834..99e4382, 2026-10-09). Once x/crypto v0.59.0 is tagged and vuln.go.dev marks it fixed, bumping x/crypto will clear this from every scanner.replaceoncestirby/kaniko-containerd-platformslands.