-
Notifications
You must be signed in to change notification settings - Fork 690
fix: update golang container to remove CVE #3088
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Signed-off-by: Harrison King Saturley-Hall <[email protected]>
WalkthroughUpdated the Docker base image version in deploy/cloud/operator/Earthfile from distroless/go:v3.1.10 to distroless/go:v3.1.12; no other steps or logic changed. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related PRs
Poem
Pre-merge checks❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
Tip 👮 Agentic pre-merge checks are now available in preview!Pro plan users can now enable pre-merge checks in their settings to enforce checklists before merging PRs.
Please see the documentation for more information. Example: reviews:
pre_merge_checks:
custom_checks:
- name: "Undocumented Breaking Changes"
mode: "warning"
instructions: |
Pass/fail criteria: All breaking changes to public APIs, CLI flags, environment variables, configuration keys, database schemas, or HTTP/GraphQL endpoints must be documented in the "Breaking Change" section of the PR description and in CHANGELOG.md. Exclude purely internal or private changes (e.g., code not exported from package entry points or explicitly marked as internal).Please share your feedback with us on this Discord post. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 0
🧹 Nitpick comments (1)
deploy/cloud/operator/Earthfile (1)
39-49: Harden supply chain: pin by digest and ensure non-root ownership of the binary.
- Tags can drift; pin to an image digest for reproducible, tamper‑resistant builds.
- Set ownership at copy time; avoids root-owned artifacts when running as UID 65532.
Apply:
docker: ARG DOCKER_SERVER=my-registry ARG IMAGE_TAG=latest ARG IMAGE_SUFFIX=dynamo-operator - FROM nvcr.io/nvidia/distroless/go:v3.1.12 + # Pin to immutable digest to prevent tag drift + ARG GO_IMAGE="nvcr.io/nvidia/distroless/go@sha256:<REPLACE_WITH_DIGEST>" + FROM $GO_IMAGE WORKDIR / - COPY +build/manager . + COPY --chown=65532:65532 +build/manager /manager USER 65532:65532 - CMD ["./manager"] + CMD ["/manager"] SAVE IMAGE --push $DOCKER_SERVER/$IMAGE_SUFFIX:$IMAGE_TAGIf you prefer to keep the tag in VCS, at least add a comment with the resolved digest and pin in CI/CD.
📜 Review details
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (1)
deploy/cloud/operator/Earthfile(1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
- GitHub Check: Build and Test - sglang
- GitHub Check: Build and Test - dynamo
🔇 Additional comments (1)
deploy/cloud/operator/Earthfile (1)
43-43: Approve — bump nvcr.io/nvidia/distroless/go to v3.1.12rg output shows no remaining v3.1.10/11 references and the only occurrence is deploy/cloud/operator/Earthfile:43.
Signed-off-by: Harrison King Saturley-Hall <[email protected]>
Signed-off-by: Harrison King Saturley-Hall <[email protected]>
Signed-off-by: Harrison King Saturley-Hall <[email protected]> Signed-off-by: Kristen Kelleher <[email protected]>
Overview:
Security scan of operator container resulted in detection of CVE-2025-4802. By bumping the base container to
nvcr.io/nvidia/distroless/go:v3.1.12the vulnerability is no longer detected by NSpectRelates to OPS-1169
Summary by CodeRabbit