diff --git a/.github/workflows/security-release-gate.yml b/.github/workflows/security-release-gate.yml index f1b7e23..4948b90 100644 --- a/.github/workflows/security-release-gate.yml +++ b/.github/workflows/security-release-gate.yml @@ -24,7 +24,7 @@ jobs: env: DAPPER_IMAGE: pasturestack-kubectl-service-dapper:security-gate DAPPER_TRIVY_CACHE: /tmp/pasturestack-trivy-cache - VERSION_OVERRIDE: v0.9.16 + VERSION_OVERRIDE: v0.9.17 steps: - name: Check out the complete source history uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -119,28 +119,50 @@ jobs: --format json \ --output /evidence/dapper.raw.json \ "$DAPPER_IMAGE" - run_image_scan image \ - --cache-dir /tmp/trivy-cache \ - --skip-db-update \ - --offline-scan \ - --scanners vuln,secret \ - --severity CRITICAL,HIGH \ - --vex /workspace/security/openvex.json \ - --format json \ - --output /evidence/dapper.applicable.json \ - --exit-code 1 \ - "$DAPPER_IMAGE" + test -s dist/dapper.raw.json + jq -e '.SchemaVersion >= 2 and (.Results | type == "array")' dist/dapper.raw.json >/dev/null + jq -e '[.Results[]? | (.Secrets // [])[]] | length == 0' dist/dapper.raw.json >/dev/null + jq -e ' + [.Results[]? as $result | ($result.Vulnerabilities // [])[] | + select( + $result.Target != "pasturestack-kubectl-service-dapper:security-gate (ubuntu 26.04)" or + .PkgName != "linux-libc-dev" or + .InstalledVersion != "7.0.0-31.31" or + (.FixedVersion // "") != "" or + .Status != "affected" or + (.Severity != "CRITICAL" and .Severity != "HIGH") + ) + ] | length == 0 + ' dist/dapper.raw.json >/dev/null || { + echo 'Dapper contains a finding outside the explicitly bounded build-only Linux header package' >&2 + jq -r '.Results[]? as $result | (($result.Vulnerabilities // []) + ($result.Secrets // []))[] | [$result.Target, (.VulnerabilityID // .RuleID // "unknown"), (.PkgName // "-"), (.InstalledVersion // "-"), (.FixedVersion // "-"), (.Status // "-")] | @tsv' dist/dapper.raw.json >&2 + exit 1 + } + jq '{ + schema: "pasturestack.accepted-build-header-findings/v1", + boundary: { + package: "linux-libc-dev", + version: "7.0.0-31.31", + scope: "ephemeral Dapper build environment only", + runtimeImagesMustContainPackage: false, + rationale: "The package supplies Linux userspace API headers; affected kernel implementation code is not present, and no fixed Ubuntu package is published at this snapshot." + }, + findings: [.Results[]? as $result | ($result.Vulnerabilities // [])[] | { + target: $result.Target, + vulnerabilityId: .VulnerabilityID, + severity: .Severity, + package: .PkgName, + installedVersion: .InstalledVersion, + fixedVersion: (.FixedVersion // ""), + status: .Status + }] + }' dist/dapper.raw.json > dist/dapper.accepted-build-header-findings.json docker run --rm \ --entrypoint /usr/bin/cat \ "$DAPPER_IMAGE" \ /licenses/DAPPER-UBUNTU-APT-PACKAGES.tsv \ > dist/dapper-ubuntu-apt-packages.tsv - docker run --rm \ - --entrypoint /usr/bin/cat \ - "$DAPPER_IMAGE" \ - /licenses/TRIVY-BUILDER-UBUNTU-APT-PACKAGES.tsv \ - > dist/trivy-builder-ubuntu-apt-packages.tsv cp package/ubuntu-apt.lock dist/ubuntu-apt.lock printf '%s\n' "$GITHUB_SHA" > dist/source-revision.txt sha256sum dist/*.json dist/*.tsv dist/*.lock | LC_ALL=C sort -k2 > dist/SHA256SUMS @@ -150,7 +172,8 @@ jobs: printf '%s%s%s\n' '- Source revision: `' "$GITHUB_SHA" '`' echo '- Ubuntu APT snapshot: `20260909T000000Z`' echo '- Product Critical/High/secret findings: 0' - echo '- Dapper applicable Critical/High/secret findings after OpenVEX: 0' + echo '- Dapper tool binaries Critical/High findings: 0' + echo '- Dapper accepted findings: build-only linux-libc-dev headers with no Ubuntu fixed package; absent from every product image' echo echo '### Evidence SHA-256' echo '```text' @@ -159,6 +182,7 @@ jobs: } >> "$GITHUB_STEP_SUMMARY" - name: Upload short-lived SBOM and scan evidence + if: ${{ always() && hashFiles('dist/*.json') != '' }} uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: kubectl-service-security-evidence-${{ github.run_id }} diff --git a/Dockerfile.dapper b/Dockerfile.dapper index 471c68c..85b1c19 100644 --- a/Dockerfile.dapper +++ b/Dockerfile.dapper @@ -1,19 +1,38 @@ FROM docker:29.7.2-cli@sha256:000bb62ff495f986c9f5578eb67cc2cb98b91138eda81d7762d5371eb8a497fe AS docker-cli -FROM docker/buildx-bin:0.36.1@sha256:1f2f6b2be4a2511ada67336e76892f1a588c89746009dd4b21069e4d867465be AS buildx - -FROM aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969 AS trivy - FROM ubuntu:26.04@sha256:2260313b31c8c011cd2eebe728008efac1b3982be73eb71348ea2648d2c0e09b COPY --from=docker-cli /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt COPY package/ubuntu-apt.lock /licenses/ubuntu-apt.lock +COPY toolchain/buildx-security.patch /usr/share/pasturestack/patches/buildx-security.patch ARG DAPPER_HOST_ARCH=amd64 +ARG DOCKER_VERSION=29.7.2 +ARG DOCKER_GIT_COMMIT=a7dcaa6fdb6ed04aacbfdc76357fdae01605609e +ARG DOCKER_SOURCE_DATE_EPOCH=1785922455 +ARG DOCKER_SOURCE_SHA256=6e5c91d3a5a79db78cf989d07727d00e757aa0da4d135a3ce4b86061b83fb511 +ARG DOCKER_UPSTREAM_X_TEXT_VERSION=v0.40.0 +ARG DOCKER_X_TEXT_VERSION=v0.41.0 +ARG DOCKER_UPSTREAM_GRPC_VERSION=v1.82.1 +ARG DOCKER_GRPC_VERSION=v1.83.2 ARG BUILDX_VERSION=0.36.1 ARG BUILDX_GIT_COMMIT=1d8dde89b8aba914e05e45366770736fea1fd690 +ARG BUILDX_SOURCE_DATE_EPOCH=1785856317 +ARG BUILDX_SOURCE_SHA256=fb28b5c2a198d05482f0656dfb7ee161240a904e36697bf7108e5d517f23854b +ARG BUILDX_SECURITY_PATCH_SHA256=9d424e752f24ea0e34ccd80340428f067ae8109204c401c93786a2b0be6ea993 +ARG BUILDX_GO_ARCHIVE_VERSION=v0.3.0 +ARG BUILDX_X_MOD_VERSION=v0.40.0 +ARG BUILDX_UPSTREAM_GRPC_VERSION=v1.82.1 +ARG BUILDX_GRPC_VERSION=v1.83.2 ARG TRIVY_VERSION=0.74.0 -ARG TRIVY_IMAGE_DIGEST=sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969 +ARG TRIVY_GIT_COMMIT=e1fd17a0ea4a8cf24bc4b4dd7e2cfbf4bb31b994 +ARG TRIVY_SOURCE_DATE_EPOCH=1786703098 +ARG TRIVY_SOURCE_SHA256=285594b257470eb444fd2836be95a835565ee600382320c977b3993d8efbb767 +ARG TRIVY_UPSTREAM_GRPC_VERSION=v1.82.1 +ARG TRIVY_GRPC_VERSION=v1.83.2 +ARG TRIVY_GO_VERSION=1.26.8 +ARG TRIVY_GO_SHA256_amd64=d0f743b33e8d8945e6b1f432edd15785c70507121d6e2a723b21285eddf8b57b +ARG TRIVY_GO_SHA256_arm64=211ffced9dcb9633a55eac6364816ec0ddd951389a740e88fa8b3337971bdda0 ARG GO_VERSION=1.27.0 ARG GO_SHA256_amd64=675c26c449cbb18fc24b74650de1eabbae6e16f64326fd85a283fb3b58280685 ARG GO_SHA256_arm64=51798d2c42d0e1c6ed7fd9f48728b4193abac9e8aad6dbac2fe96a81f5909bda @@ -29,9 +48,6 @@ ENV HOST_ARCH=${DAPPER_HOST_ARCH} \ PATH=/go/bin:/usr/local/go/bin:${PATH} \ SHELL=/bin/bash -COPY --from=docker-cli /usr/local/bin/docker /usr/bin/docker -COPY --from=buildx /buildx /usr/libexec/docker/cli-plugins/docker-buildx -COPY --from=trivy /usr/local/bin/trivy /usr/local/bin/trivy COPY build-tools/TRIVY-LICENSE /licenses/TRIVY-LICENSE RUN set -eux; \ @@ -49,6 +65,7 @@ RUN set -eux; \ gcc="${UBUNTU_APT_GCC_VERSION}" \ git="${UBUNTU_APT_GIT_VERSION}" \ libc6-dev="${UBUNTU_APT_LIBC6_DEV_VERSION}" \ + linux-libc-dev="${UBUNTU_APT_LINUX_LIBC_DEV_VERSION}" \ make="${UBUNTU_APT_MAKE_VERSION}" \ tar="${UBUNTU_APT_TAR_VERSION}" \ xz-utils="${UBUNTU_APT_XZ_UTILS_VERSION}"; \ @@ -72,7 +89,6 @@ RUN set -eux; \ echo "${go_sha} /tmp/go.tgz" | sha256sum -c -; \ tar -C /usr/local -xzf /tmp/go.tgz; \ rm -f /tmp/go.tgz; \ - chmod +x /usr/bin/docker; \ mkdir -p \ /go/bin \ /go/src/github.com/PastureStack/kubectl-service \ @@ -86,23 +102,128 @@ RUN set -eux; \ /tmp/go-config \ /tmp/pasturestack-dapper-home; \ git config --system --add safe.directory '*'; \ - go version; \ - docker --version; \ + go version + +RUN set -eux; \ + docker_source_uri="https://codeload.github.com/docker/cli/tar.gz/${DOCKER_GIT_COMMIT}"; \ + curl -fsSL --retry 5 --retry-all-errors --retry-delay 2 --connect-timeout 10 --max-time 300 \ + -o /tmp/docker-cli.tar.gz "${docker_source_uri}"; \ + echo "${DOCKER_SOURCE_SHA256} /tmp/docker-cli.tar.gz" | sha256sum -c -; \ + mkdir -p /tmp/docker-cli-src; \ + tar -xzf /tmp/docker-cli.tar.gz -C /tmp/docker-cli-src --strip-components=1; \ + cd /tmp/docker-cli-src; \ + grep -F "golang.org/x/text ${DOCKER_UPSTREAM_X_TEXT_VERSION}" vendor.mod; \ + grep -F "google.golang.org/grpc ${DOCKER_UPSTREAM_GRPC_VERSION}" vendor.mod; \ + cp vendor.mod go.mod; \ + cp vendor.sum go.sum; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=https://proxy.golang.org GOSUMDB=sum.golang.org GOMODCACHE=/tmp/docker-go-mod \ + go get "golang.org/x/text@${DOCKER_X_TEXT_VERSION}" "google.golang.org/grpc@${DOCKER_GRPC_VERSION}"; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=https://proxy.golang.org GOSUMDB=sum.golang.org GOMODCACHE=/tmp/docker-go-mod go mod download; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/docker-go-mod go mod verify; \ + docker_build_time="$(date -u --date="@${DOCKER_SOURCE_DATE_EPOCH}" +'%Y-%m-%dT%H:%M:%SZ')"; \ + SOURCE_DATE_EPOCH="${DOCKER_SOURCE_DATE_EPOCH}" CGO_ENABLED=0 GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/docker-go-mod GOOS=linux GOARCH="${DAPPER_HOST_ARCH}" \ + go build -trimpath -buildvcs=false -tags 'grpcnotrace osusergo netgo' \ + -ldflags "-s -w -buildid= -X github.com/docker/cli/cli/version.Version=${DOCKER_VERSION} -X github.com/docker/cli/cli/version.GitCommit=${DOCKER_GIT_COMMIT} -X github.com/docker/cli/cli/version.BuildTime=${docker_build_time}" \ + -o /usr/bin/docker ./cmd/docker; \ + chmod +x /usr/bin/docker; \ + docker --version | grep -F "Docker version ${DOCKER_VERSION},"; \ + go version -m /usr/bin/docker > /licenses/DOCKER-CLI-GO-VERSION.txt; \ + test "$(awk 'NR == 1 { print $NF }' /licenses/DOCKER-CLI-GO-VERSION.txt)" = "go${GO_VERSION}"; \ + grep -F $'dep\tgolang.org/x/text\t'"${DOCKER_X_TEXT_VERSION}"$'\t' /licenses/DOCKER-CLI-GO-VERSION.txt; \ + grep -F $'dep\tgoogle.golang.org/grpc\t'"${DOCKER_GRPC_VERSION}"$'\t' /licenses/DOCKER-CLI-GO-VERSION.txt; \ + cd /; \ + rm -rf /tmp/docker-cli-src /tmp/docker-cli.tar.gz /tmp/docker-go-mod /tmp/go-build-cache + +RUN set -eux; \ + buildx_source_uri="https://codeload.github.com/docker/buildx/tar.gz/${BUILDX_GIT_COMMIT}"; \ + curl -fsSL --retry 5 --retry-all-errors --retry-delay 2 --connect-timeout 10 --max-time 300 \ + -o /tmp/buildx.tar.gz "${buildx_source_uri}"; \ + echo "${BUILDX_SOURCE_SHA256} /tmp/buildx.tar.gz" | sha256sum -c -; \ + echo "${BUILDX_SECURITY_PATCH_SHA256} /usr/share/pasturestack/patches/buildx-security.patch" | sha256sum -c -; \ + mkdir -p /tmp/buildx-src /usr/libexec/docker/cli-plugins; \ + tar -xzf /tmp/buildx.tar.gz -C /tmp/buildx-src --strip-components=1; \ + cd /tmp/buildx-src; \ + git apply --check /usr/share/pasturestack/patches/buildx-security.patch; \ + git apply /usr/share/pasturestack/patches/buildx-security.patch; \ + grep -F "google.golang.org/grpc ${BUILDX_UPSTREAM_GRPC_VERSION}" go.mod; \ + go mod edit -droprequire=github.com/docker/docker; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=https://proxy.golang.org GOSUMDB=sum.golang.org GOMODCACHE=/tmp/buildx-go-mod \ + go get "github.com/moby/go-archive@${BUILDX_GO_ARCHIVE_VERSION}" "golang.org/x/mod@${BUILDX_X_MOD_VERSION}" "google.golang.org/grpc@${BUILDX_GRPC_VERSION}"; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=https://proxy.golang.org GOSUMDB=sum.golang.org GOMODCACHE=/tmp/buildx-go-mod go mod download; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/buildx-go-mod go mod verify; \ + test "$(GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/buildx-go-mod go list -m -f '{{.Version}}' github.com/moby/go-archive)" = "${BUILDX_GO_ARCHIVE_VERSION}"; \ + test "$(GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/buildx-go-mod go list -m -f '{{.Version}}' golang.org/x/mod)" = "${BUILDX_X_MOD_VERSION}"; \ + test "$(GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/buildx-go-mod go list -m -f '{{.Version}}' google.golang.org/grpc)" = "${BUILDX_GRPC_VERSION}"; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/buildx-go-mod go list -deps ./cmd/buildx > /tmp/buildx-deps.txt; \ + ! grep '^github.com/docker/docker/' /tmp/buildx-deps.txt; \ + SOURCE_DATE_EPOCH="${BUILDX_SOURCE_DATE_EPOCH}" CGO_ENABLED=0 GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/buildx-go-mod GOOS=linux GOARCH="${DAPPER_HOST_ARCH}" \ + go build -trimpath -buildvcs=false \ + -ldflags "-s -w -buildid= -X github.com/docker/buildx/version.Version=v${BUILDX_VERSION} -X github.com/docker/buildx/version.Revision=${BUILDX_GIT_COMMIT} -X github.com/docker/buildx/version.Package=github.com/docker/buildx" \ + -o /usr/libexec/docker/cli-plugins/docker-buildx ./cmd/buildx; \ + chmod +x /usr/libexec/docker/cli-plugins/docker-buildx; \ docker buildx version | grep -F "github.com/docker/buildx v${BUILDX_VERSION} ${BUILDX_GIT_COMMIT}"; \ + go version -m /usr/libexec/docker/cli-plugins/docker-buildx > /licenses/BUILDX-GO-VERSION.txt; \ + test "$(awk 'NR == 1 { print $NF }' /licenses/BUILDX-GO-VERSION.txt)" = "go${GO_VERSION}"; \ + ! grep -F $'dep\tgithub.com/docker/docker\t' /licenses/BUILDX-GO-VERSION.txt; \ + grep -F $'dep\tgithub.com/moby/go-archive\t'"${BUILDX_GO_ARCHIVE_VERSION}"$'\t' /licenses/BUILDX-GO-VERSION.txt; \ + grep -F $'dep\tgolang.org/x/mod\t'"${BUILDX_X_MOD_VERSION}"$'\t' /licenses/BUILDX-GO-VERSION.txt; \ + grep -F $'dep\tgoogle.golang.org/grpc\t'"${BUILDX_GRPC_VERSION}"$'\t' /licenses/BUILDX-GO-VERSION.txt; \ + cd /; \ + rm -rf /tmp/buildx-src /tmp/buildx.tar.gz /tmp/buildx-deps.txt /tmp/buildx-go-mod /tmp/go-build-cache + +RUN set -eux; \ + case "${DAPPER_HOST_ARCH}" in \ + amd64) trivy_go_arch=amd64; trivy_go_sha="${TRIVY_GO_SHA256_amd64}" ;; \ + arm64) trivy_go_arch=arm64; trivy_go_sha="${TRIVY_GO_SHA256_arm64}" ;; \ + *) echo "unsupported DAPPER_HOST_ARCH=${DAPPER_HOST_ARCH}" >&2; exit 1 ;; \ + esac; \ + curl -fsSL --retry 5 --retry-all-errors --retry-delay 2 --connect-timeout 10 --max-time 300 \ + -o /tmp/trivy-go.tgz "https://go.dev/dl/go${TRIVY_GO_VERSION}.linux-${trivy_go_arch}.tar.gz"; \ + echo "${trivy_go_sha} /tmp/trivy-go.tgz" | sha256sum -c -; \ + mkdir -p /opt/trivy-go; \ + tar -C /opt/trivy-go --strip-components=1 -xzf /tmp/trivy-go.tgz; \ + rm -f /tmp/trivy-go.tgz; \ + export PATH="/opt/trivy-go/bin:${PATH}"; \ + export GOTOOLCHAIN=local; \ + test "$(go version | awk '{print $3}')" = "go${TRIVY_GO_VERSION}"; \ + trivy_source_uri="https://codeload.github.com/aquasecurity/trivy/tar.gz/${TRIVY_GIT_COMMIT}"; \ + curl -fsSL --retry 5 --retry-all-errors --retry-delay 2 --connect-timeout 10 --max-time 300 \ + -o /tmp/trivy.tar.gz "${trivy_source_uri}"; \ + echo "${TRIVY_SOURCE_SHA256} /tmp/trivy.tar.gz" | sha256sum -c -; \ + mkdir -p /tmp/trivy-src; \ + tar -xzf /tmp/trivy.tar.gz -C /tmp/trivy-src --strip-components=1; \ + cd /tmp/trivy-src; \ + grep -F "google.golang.org/grpc ${TRIVY_UPSTREAM_GRPC_VERSION}" go.mod; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=https://proxy.golang.org GOSUMDB=sum.golang.org GOMODCACHE=/tmp/trivy-go-mod \ + go get "google.golang.org/grpc@${TRIVY_GRPC_VERSION}"; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=https://proxy.golang.org GOSUMDB=sum.golang.org GOMODCACHE=/tmp/trivy-go-mod go mod download; \ + GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/trivy-go-mod go mod verify; \ + SOURCE_DATE_EPOCH="${TRIVY_SOURCE_DATE_EPOCH}" CGO_ENABLED=0 GOEXPERIMENT=jsonv2 GOFLAGS=-mod=mod GOWORK=off GOPROXY=off GOSUMDB=sum.golang.org GOMODCACHE=/tmp/trivy-go-mod GOOS=linux GOARCH="${DAPPER_HOST_ARCH}" \ + go build -trimpath -buildvcs=false \ + -ldflags "-s -w -buildid= -X=github.com/aquasecurity/trivy/pkg/version/app.ver=${TRIVY_VERSION}" \ + -o /usr/local/bin/trivy ./cmd/trivy; \ + chmod +x /usr/local/bin/trivy; \ trivy --version | tee /licenses/TRIVY-BUILDINFO.txt; \ - test "$(cat /licenses/TRIVY-BUILDINFO.txt)" = "Version: ${TRIVY_VERSION}" + test "$(cat /licenses/TRIVY-BUILDINFO.txt)" = "Version: ${TRIVY_VERSION}"; \ + go version -m /usr/local/bin/trivy > /licenses/TRIVY-GO-VERSION.txt; \ + test "$(awk 'NR == 1 { print $NF }' /licenses/TRIVY-GO-VERSION.txt)" = "go${TRIVY_GO_VERSION}-X:jsonv2"; \ + grep -F $'dep\tgoogle.golang.org/grpc\t'"${TRIVY_GRPC_VERSION}"$'\t' /licenses/TRIVY-GO-VERSION.txt; \ + cd /; \ + rm -rf /opt/trivy-go /tmp/trivy-src /tmp/trivy.tar.gz /tmp/trivy-go-mod /tmp/go-build-cache ENV DAPPER_SOURCE=/go/src/github.com/PastureStack/kubectl-service \ DAPPER_OUTPUT="bin dist" \ DAPPER_DOCKER_SOCKET=true \ - DAPPER_ENV="TAG REPO IMAGE_NAME VERSION_OVERRIDE SOURCE_REVISION KUBERNETES_VERSION KUBERNETES_GIT_COMMIT KUBERNETES_SOURCE_SHA256 KUBERNETES_LICENSE_SHA256 HELM_VERSION HELM_GIT_COMMIT HELM_SOURCE_SHA256 HELM_LICENSE_SHA256 HELM_ORAS_GO_VERSION HELM_PATCHED_GO_MOD_SHA256 HELM_PATCHED_GO_SUM_SHA256 DOCKER_BUILDKIT DOCKER_BUILD_NETWORK" \ + DAPPER_ENV="TAG REPO IMAGE_NAME VERSION_OVERRIDE SOURCE_REVISION KUBERNETES_VERSION KUBERNETES_GIT_COMMIT KUBERNETES_SOURCE_SHA256 KUBERNETES_LICENSE_SHA256 HELM_VERSION HELM_GIT_COMMIT HELM_SOURCE_SHA256 HELM_LICENSE_SHA256 HELM_ORAS_GO_VERSION HELM_X_CRYPTO_VERSION HELM_PATCHED_GO_MOD_SHA256 HELM_PATCHED_GO_SUM_SHA256 DOCKER_BUILDKIT DOCKER_BUILD_NETWORK" \ HOME=/tmp/pasturestack-dapper-home WORKDIR ${DAPPER_SOURCE} LABEL io.pasturestack.build.buildx.version="${BUILDX_VERSION}" \ io.pasturestack.build.buildx.revision="${BUILDX_GIT_COMMIT}" \ io.pasturestack.build.trivy.version="${TRIVY_VERSION}" \ - io.pasturestack.build.trivy.image-digest="${TRIVY_IMAGE_DIGEST}" \ + io.pasturestack.build.trivy.revision="${TRIVY_GIT_COMMIT}" \ + io.pasturestack.build.trivy.source-sha256="${TRIVY_SOURCE_SHA256}" \ + io.pasturestack.build.trivy.go-version="${TRIVY_GO_VERSION}" \ io.pasturestack.build.ubuntu.snapshot="20260909T000000Z" \ io.pasturestack.build.gcc.version="4:15.2.0-5ubuntu1" USER 65534:65534 diff --git a/Makefile b/Makefile index 51c7dfd..bfa0b94 100644 --- a/Makefile +++ b/Makefile @@ -55,6 +55,7 @@ $(TARGETS): dapper-image -e HELM_SOURCE_SHA256 \ -e HELM_LICENSE_SHA256 \ -e HELM_ORAS_GO_VERSION \ + -e HELM_X_CRYPTO_VERSION \ -e HELM_PATCHED_GO_MOD_SHA256 \ -e HELM_PATCHED_GO_SUM_SHA256 \ $(DAPPER_IMAGE) $@ diff --git a/README.md b/README.md index af48960..80af2a1 100644 --- a/README.md +++ b/README.md @@ -9,7 +9,7 @@ Rancher Labs or SUSE. The repository preserves the history and Apache-2.0 license of the upstream `rancher/kubectld` project. Earlier non-numeric releases remain immutable historical evidence. The -maintained release coordinate is the pure numeric successor `v0.9.16`; product +maintained release coordinate is the pure numeric successor `v0.9.17`; product identity and provenance are carried by the package name, labels, SBOM, and attestations rather than a text qualifier in the tag. @@ -38,7 +38,7 @@ WebSocket, and `x/sys` are pinned by `go.mod` and `go.sum`. ```sh make test make validate -make package IMAGE_NAME=local/pasturestack/kubectl-service TAG=v0.9.16 +make package IMAGE_NAME=local/pasturestack/kubectl-service TAG=v0.9.17 ``` Packaging verifies both source archives and licenses, the upstream Git commits, diff --git a/package/Dockerfile b/package/Dockerfile index efed9ad..cea9427 100644 --- a/package/Dockerfile +++ b/package/Dockerfile @@ -7,8 +7,9 @@ ARG HELM_GIT_COMMIT=3900f434fd3ef2b84065dc04508df48f288dba00 ARG HELM_SOURCE_SHA256=f1a1aa56fff071cfa1eecc18c6a7212b2e5c7a0a123fd8e4dcae620bd51b4286 ARG HELM_LICENSE_SHA256=881467e52efeb1807406134b0ec04b1c6f52dc9dc49382713ef9ac4e0cae42f8 ARG HELM_ORAS_GO_VERSION=2.6.2 -ARG HELM_PATCHED_GO_MOD_SHA256=3c0166a13121fea5425d0e6ed0f11ad74cc14ed184cf3dfd96724b8113bbbadf -ARG HELM_PATCHED_GO_SUM_SHA256=249a8957dab7b66ea7d71bf9b1e1c8df3cb046a4bff801bdbc2cec210e3f9e21 +ARG HELM_X_CRYPTO_VERSION=0.56.0 +ARG HELM_PATCHED_GO_MOD_SHA256=76accd79d2f7cec3edaf79d444438d0f5bdc0b1f1fd57485a299ba5491fcb319 +ARG HELM_PATCHED_GO_SUM_SHA256=2913265cc341d02288ad38054b13d8c6a11b185513b7169293706d0878c4f59a ENV GOMAXPROCS=2 GOTELEMETRY=off GOTOOLCHAIN=local RUN set -eux; \ @@ -23,12 +24,15 @@ RUN set -eux; \ echo "${HELM_LICENSE_SHA256} LICENSE" | sha256sum -c -; \ grep -Fxq 'go 1.26.0' go.mod; \ grep -Fq 'oras.land/oras-go/v2 v2.6.1' go.mod; \ - go mod edit -go=1.27.0 -require="oras.land/oras-go/v2@v${HELM_ORAS_GO_VERSION}"; \ + go mod edit -go=1.27.0 \ + -require="oras.land/oras-go/v2@v${HELM_ORAS_GO_VERSION}" \ + -require="golang.org/x/crypto@v${HELM_X_CRYPTO_VERSION}"; \ go mod tidy; \ echo "${HELM_PATCHED_GO_MOD_SHA256} go.mod" | sha256sum -c -; \ echo "${HELM_PATCHED_GO_SUM_SHA256} go.sum" | sha256sum -c -; \ go mod verify; \ test "$(go list -m -f '{{.Version}}' oras.land/oras-go/v2)" = "v${HELM_ORAS_GO_VERSION}"; \ + test "$(go list -m -f '{{.Version}}' golang.org/x/crypto)" = "v${HELM_X_CRYPTO_VERSION}"; \ CGO_ENABLED=0 go build -p=2 -mod=readonly -trimpath -buildvcs=false \ -ldflags "-w -s -X helm.sh/helm/v4/internal/version.version=${HELM_VERSION} -X helm.sh/helm/v4/internal/version.metadata= -X helm.sh/helm/v4/internal/version.gitCommit=${HELM_GIT_COMMIT} -X helm.sh/helm/v4/internal/version.gitTreeState=clean" \ -o /out/helm ./cmd/helm; \ @@ -38,6 +42,9 @@ RUN set -eux; \ awk -v expected="v${HELM_ORAS_GO_VERSION}" \ '$1 == "dep" && $2 == "oras.land/oras-go/v2" && $3 == expected { found=1 } END { exit found ? 0 : 1 }' \ /out/HELM-BUILDINFO.txt; \ + awk -v expected="v${HELM_X_CRYPTO_VERSION}" \ + '$1 == "dep" && $2 == "golang.org/x/crypto" && $3 == expected { found=1 } END { exit found ? 0 : 1 }' \ + /out/HELM-BUILDINFO.txt; \ cp LICENSE /out/HELM-LICENSE; \ chmod 0555 /out/helm; \ chmod 0444 /out/HELM-BUILDINFO.txt /out/HELM-LICENSE @@ -86,6 +93,7 @@ ARG KUBERNETES_VERSION=v1.36.4 ARG HELM_VERSION=v4.2.4 ARG HELM_GIT_COMMIT=3900f434fd3ef2b84065dc04508df48f288dba00 ARG HELM_ORAS_GO_VERSION=2.6.2 +ARG HELM_X_CRYPTO_VERSION=0.56.0 ENV DEBIAN_FRONTEND=noninteractive \ HOME=/home/pasturestack \ @@ -152,6 +160,7 @@ LABEL org.opencontainers.image.title="pasturestack-kubectl-service" \ io.pasturestack.helm.version="${HELM_VERSION}" \ io.pasturestack.tools.compiler="go1.27.0" \ io.pasturestack.helm.oras-go.version="${HELM_ORAS_GO_VERSION}" \ + io.pasturestack.helm.x-crypto.version="${HELM_X_CRYPTO_VERSION}" \ io.pasturestack.ubuntu.snapshot="20260909T000000Z" \ io.pasturestack.runtime.user="65534:65534" \ io.pasturestack.shell.requires-privileged="false" diff --git a/package/ubuntu-apt.lock b/package/ubuntu-apt.lock index 311babf..5333094 100644 --- a/package/ubuntu-apt.lock +++ b/package/ubuntu-apt.lock @@ -14,6 +14,7 @@ UBUNTU_APT_GIT_VERSION='1:2.53.0-1ubuntu1' UBUNTU_APT_LIBC6_DEV_VERSION='2.43-2ubuntu2.4' UBUNTU_APT_LIBC6_VERSION='2.43-2ubuntu2.4' UBUNTU_APT_LIBCURL4_VERSION='8.18.0-1ubuntu2.5' +UBUNTU_APT_LINUX_LIBC_DEV_VERSION='7.0.0-31.31' UBUNTU_APT_LIBSSH2_VERSION='1.11.1-1ubuntu0.26.04.4' UBUNTU_APT_MAKE_VERSION='4.4.1-3' UBUNTU_APT_NETCAT_OPENBSD_VERSION='1.234-1' diff --git a/scripts/package b/scripts/package index 8a9db63..451f516 100755 --- a/scripts/package +++ b/scripts/package @@ -15,8 +15,9 @@ HELM_GIT_COMMIT=${HELM_GIT_COMMIT:-3900f434fd3ef2b84065dc04508df48f288dba00} HELM_SOURCE_SHA256=${HELM_SOURCE_SHA256:-f1a1aa56fff071cfa1eecc18c6a7212b2e5c7a0a123fd8e4dcae620bd51b4286} HELM_LICENSE_SHA256=${HELM_LICENSE_SHA256:-881467e52efeb1807406134b0ec04b1c6f52dc9dc49382713ef9ac4e0cae42f8} HELM_ORAS_GO_VERSION=${HELM_ORAS_GO_VERSION:-2.6.2} -HELM_PATCHED_GO_MOD_SHA256=${HELM_PATCHED_GO_MOD_SHA256:-3c0166a13121fea5425d0e6ed0f11ad74cc14ed184cf3dfd96724b8113bbbadf} -HELM_PATCHED_GO_SUM_SHA256=${HELM_PATCHED_GO_SUM_SHA256:-249a8957dab7b66ea7d71bf9b1e1c8df3cb046a4bff801bdbc2cec210e3f9e21} +HELM_X_CRYPTO_VERSION=${HELM_X_CRYPTO_VERSION:-0.56.0} +HELM_PATCHED_GO_MOD_SHA256=${HELM_PATCHED_GO_MOD_SHA256:-76accd79d2f7cec3edaf79d444438d0f5bdc0b1f1fd57485a299ba5491fcb319} +HELM_PATCHED_GO_SUM_SHA256=${HELM_PATCHED_GO_SUM_SHA256:-2913265cc341d02288ad38054b13d8c6a11b185513b7169293706d0878c4f59a} if [ -z "${SOURCE_REVISION:-}" ]; then SOURCE_REVISION=$(git -C "$repo_root" rev-parse HEAD) @@ -58,6 +59,7 @@ build_args=( --build-arg "HELM_SOURCE_SHA256=${HELM_SOURCE_SHA256}" --build-arg "HELM_LICENSE_SHA256=${HELM_LICENSE_SHA256}" --build-arg "HELM_ORAS_GO_VERSION=${HELM_ORAS_GO_VERSION}" + --build-arg "HELM_X_CRYPTO_VERSION=${HELM_X_CRYPTO_VERSION}" --build-arg "HELM_PATCHED_GO_MOD_SHA256=${HELM_PATCHED_GO_MOD_SHA256}" --build-arg "HELM_PATCHED_GO_SUM_SHA256=${HELM_PATCHED_GO_SUM_SHA256}" ) @@ -76,6 +78,7 @@ test "$(docker image inspect "$IMAGE" --format '{{index .Config.Labels "io.pastu test "$(docker image inspect "$IMAGE" --format '{{index .Config.Labels "io.pasturestack.helm.version"}}')" = "$HELM_VERSION" test "$(docker image inspect "$IMAGE" --format '{{index .Config.Labels "io.pasturestack.tools.compiler"}}')" = "go1.27.0" test "$(docker image inspect "$IMAGE" --format '{{index .Config.Labels "io.pasturestack.helm.oras-go.version"}}')" = "$HELM_ORAS_GO_VERSION" +test "$(docker image inspect "$IMAGE" --format '{{index .Config.Labels "io.pasturestack.helm.x-crypto.version"}}')" = "$HELM_X_CRYPTO_VERSION" test "$(docker run --rm --entrypoint /usr/bin/dpkg-query "$IMAGE" -W -f='${Version}' libc6)" = "$UBUNTU_APT_LIBC6_VERSION" test "$(docker run --rm --entrypoint /usr/bin/dpkg-query "$IMAGE" -W -f='${Version}' libcurl4t64)" = "$UBUNTU_APT_LIBCURL4_VERSION" test "$(docker run --rm --entrypoint /usr/bin/dpkg-query "$IMAGE" -W -f='${Version}' libssh2-1t64)" = "$UBUNTU_APT_LIBSSH2_VERSION" @@ -112,4 +115,8 @@ trivy image --skip-db-update --offline-scan --format cyclonedx \ --output ../dist/kubectl-service.cdx.json "$IMAGE" docker run --rm --entrypoint /usr/bin/cat "$IMAGE" /licenses/KUBECTL-SERVICE-UBUNTU-APT-PACKAGES.tsv \ > ../dist/kubectl-service-ubuntu-apt-packages.tsv +if grep -q '^linux-libc-dev[[:space:]]' ../dist/kubectl-service-ubuntu-apt-packages.tsv; then + echo 'linux-libc-dev build headers must not be present in the runtime image' >&2 + exit 1 +fi printf '%s\n' "$IMAGE" > ../dist/images diff --git a/scripts/validate b/scripts/validate index b28d308..88af9f2 100755 --- a/scripts/validate +++ b/scripts/validate @@ -30,7 +30,25 @@ grep -Fq 'perl-base="${UBUNTU_APT_PERL_BASE_VERSION}"' package/Dockerfile grep -Fq -- '--cap-drop ALL' scripts/package grep -Fq -- '--security-opt no-new-privileges:true' scripts/package grep -Fq 'ARG TRIVY_VERSION=0.74.0' Dockerfile.dapper -grep -Fq 'aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969' Dockerfile.dapper +grep -Fq 'ARG TRIVY_GIT_COMMIT=e1fd17a0ea4a8cf24bc4b4dd7e2cfbf4bb31b994' Dockerfile.dapper +grep -Fq 'ARG TRIVY_SOURCE_SHA256=285594b257470eb444fd2836be95a835565ee600382320c977b3993d8efbb767' Dockerfile.dapper +grep -Fq 'ARG TRIVY_UPSTREAM_GRPC_VERSION=v1.82.1' Dockerfile.dapper +grep -Fq 'ARG TRIVY_GRPC_VERSION=v1.83.2' Dockerfile.dapper +grep -Fq 'ARG TRIVY_GO_VERSION=1.26.8' Dockerfile.dapper +grep -Fq 'ARG TRIVY_GO_SHA256_amd64=d0f743b33e8d8945e6b1f432edd15785c70507121d6e2a723b21285eddf8b57b' Dockerfile.dapper +grep -Fq 'ARG TRIVY_GO_SHA256_arm64=211ffced9dcb9633a55eac6364816ec0ddd951389a740e88fa8b3337971bdda0' Dockerfile.dapper +grep -Fq 'https://go.dev/dl/go${TRIVY_GO_VERSION}.linux-${trivy_go_arch}.tar.gz' Dockerfile.dapper +grep -Fq 'export GOTOOLCHAIN=local' Dockerfile.dapper +grep -Fq 'test "$(go version | awk '\''{print $3}'\'')" = "go${TRIVY_GO_VERSION}"' Dockerfile.dapper +grep -Fq 'test "$(awk '\''NR == 1 { print $NF }'\'' /licenses/TRIVY-GO-VERSION.txt)" = "go${TRIVY_GO_VERSION}-X:jsonv2"' Dockerfile.dapper +grep -Fq 'CGO_ENABLED=0 GOEXPERIMENT=jsonv2 GOFLAGS=-mod=mod' Dockerfile.dapper +grep -Fq 'go get "google.golang.org/grpc@${TRIVY_GRPC_VERSION}"' Dockerfile.dapper +grep -Fq 'ARG DOCKER_GRPC_VERSION=v1.83.2' Dockerfile.dapper +grep -Fq 'ARG BUILDX_GO_ARCHIVE_VERSION=v0.3.0' Dockerfile.dapper +grep -Fq 'ARG BUILDX_X_MOD_VERSION=v0.40.0' Dockerfile.dapper +grep -Fq 'ARG BUILDX_UPSTREAM_GRPC_VERSION=v1.82.1' Dockerfile.dapper +grep -Fq 'ARG BUILDX_GRPC_VERSION=v1.83.2' Dockerfile.dapper +grep -Fq 'go get "github.com/moby/go-archive@${BUILDX_GO_ARCHIVE_VERSION}" "golang.org/x/mod@${BUILDX_X_MOD_VERSION}" "google.golang.org/grpc@${BUILDX_GRPC_VERSION}"' Dockerfile.dapper expected_trivy_license_sha256='c71d239df91726fc519c6eb72d318ec65820627232b2f796219e87dcf35d0ab4' actual_trivy_license_sha256=$(sha256sum build-tools/TRIVY-LICENSE | awk '{print $1}') if [ "$actual_trivy_license_sha256" != "$expected_trivy_license_sha256" ]; then @@ -39,10 +57,7 @@ if [ "$actual_trivy_license_sha256" != "$expected_trivy_license_sha256" ]; then exit 1 fi test ! -e build-tools/trivy-v0.73.0-oras-go-v2.6.2-go-git-v5.19.2.patch -if grep -E 'TRIVY_UPSTREAM_VERSION|trivy-security\.patch|GOEXPERIMENT=jsonv2' Dockerfile.dapper; then - echo 'Retired custom Trivy rebuild path remains active' >&2 - exit 1 -fi +test ! -e security/openvex.json active_paths=(main.go helm package scripts/package Makefile) if grep -R -i -E 'helm[ -]?2|tiller|legacy-helm|v1\.12\.' "${active_paths[@]}"; then @@ -70,4 +85,4 @@ if grep -R -n -E 'GO111MODULE=off|GO15VENDOREXPERIMENT|github.com/codegangsta/cl exit 1 fi -echo 'KUBECTL_SERVICE_VALIDATE_OK kubernetes=v1.36.4 helm=v4.2.4 compiler=go1.27.0 oras-go=v2.6.2' +echo 'KUBECTL_SERVICE_VALIDATE_OK kubernetes=v1.36.4 helm=v4.2.4 compiler=go1.27.0 oras-go=v2.6.2 x-crypto=v0.56.0' diff --git a/security/openvex.json b/security/openvex.json deleted file mode 100644 index ab41744..0000000 --- a/security/openvex.json +++ /dev/null @@ -1,94 +0,0 @@ -{ - "@context": "https://openvex.dev/ns/v0.2.0", - "@id": "https://github.com/PastureStack/kubectl-service/security/openvex/dapper-toolchain-v0.36.1-ubuntu26.04", - "author": "PastureStack Security", - "timestamp": "2026-08-08T11:00:00Z", - "version": 2, - "statements": [ - { - "vulnerability": { - "name": "CVE-2026-34040" - }, - "products": [ - { - "@id": "pkg:golang/github.com/docker/docker@v28.5.2%2Bincompatible" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_in_execute_path", - "impact_statement": "The advisory affects Docker daemon authorization-plugin request handling. The immutable Buildx v0.36.1 source dependency graph compiles only github.com/docker/docker/pkg/namesgenerator from this legacy module into the Buildx CLI; no daemon, authorization, API-server, or request-body code from the affected path is present." - }, - { - "vulnerability": { - "name": "CVE-2026-41567" - }, - "products": [ - { - "@id": "pkg:golang/github.com/docker/docker@v28.5.2%2Bincompatible" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_in_execute_path", - "impact_statement": "The advisory affects Docker daemon archive extraction for docker cp and PUT /containers/{id}/archive. The immutable Buildx v0.36.1 source dependency graph compiles only github.com/docker/docker/pkg/namesgenerator from this legacy module into the Buildx CLI; the daemon archive upload, decompressor resolution, and container-copy paths are absent." - }, - { - "vulnerability": { - "name": "CVE-2026-42306" - }, - "products": [ - { - "@id": "pkg:golang/github.com/docker/docker@v28.5.2%2Bincompatible" - } - ], - "status": "not_affected", - "justification": "vulnerable_code_not_in_execute_path", - "impact_statement": "The advisory affects Docker daemon docker cp bind-mount setup. The immutable Buildx v0.36.1 source dependency graph compiles only github.com/docker/docker/pkg/namesgenerator from this legacy module into the Buildx CLI; no daemon mount, archive, or container-copy implementation from the affected path is present." - }, - {"vulnerability":{"name":"CVE-2025-40190"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-46331"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-52908"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-52909"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-52910"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-52924"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53145"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53148"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53151"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53153"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53159"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53170"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53171"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53172"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53173"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53175"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53176"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53178"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53182"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53183"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53185"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53186"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53192"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53193"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53196"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53198"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53212"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53215"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53224"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53235"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53239"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53240"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53250"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53254"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53256"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53259"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53260"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53262"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53264"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53266"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53269"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53270"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53275"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53276"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-53359"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."}, - {"vulnerability":{"name":"CVE-2026-64531"},"products":[{"@id":"pkg:deb/ubuntu/linux-libc-dev@7.0.0-29.29?arch=amd64&distro=ubuntu-26.04"}],"status":"not_affected","justification":"vulnerable_code_not_present","impact_statement":"This build-only package contains Linux userspace API headers, not the vulnerable kernel implementation. It is used only to compile go test -race and is not copied into any product image."} - ] -} diff --git a/toolchain/buildx-security.patch b/toolchain/buildx-security.patch new file mode 100644 index 0000000..97b1aba --- /dev/null +++ b/toolchain/buildx-security.patch @@ -0,0 +1,51 @@ +--- a/store/util.go ++++ b/store/util.go +@@ -3,8 +3,9 @@ + import ( +- "os" +- "regexp" +- "strings" +- +- "github.com/docker/docker/pkg/namesgenerator" +- "github.com/pkg/errors" ++ "crypto/rand" ++ "encoding/hex" ++ "os" ++ "regexp" ++ "strings" ++ ++ "github.com/pkg/errors" + ) +@@ -40,15 +40,19 @@ + func GenerateName(txn *Txn) (string, error) { +- var name string +- for i := range 6 { +- name = namesgenerator.GetRandomName(i) +- if _, err := txn.NodeGroupByName(name); err != nil { +- if !os.IsNotExist(errors.Cause(err)) { +- return "", err +- } +- } else { +- continue +- } +- return name, nil +- } +- return "", errors.Errorf("failed to generate random name") ++ var name string ++ for range 6 { ++ random := make([]byte, 8) ++ if _, err := rand.Read(random); err != nil { ++ return "", errors.Wrap(err, "failed to generate random builder name") ++ } ++ name = "builder-" + hex.EncodeToString(random) ++ if _, err := txn.NodeGroupByName(name); err != nil { ++ if !os.IsNotExist(errors.Cause(err)) { ++ return "", err ++ } ++ } else { ++ continue ++ } ++ return name, nil ++ } ++ return "", errors.Errorf("failed to generate random name") + }