Repository navigation
fix(deps): bump Go modules with critical and high CVEs - #15
Conversation
Trivy on v1.3.0-gn-v10 reported 39 findings (3 CRITICAL, 36 HIGH) in Go modules that are linked into usr/bin/kratos. A local Trivy scan of the image from this commit reports 0. Version changes: - go directive: 1.22 -> 1.26.0 (the new module versions need it; the builder image and ci.yaml already use Go 1.26) - github.com/jackc/pgx/v5: v5.6.0 -> v5.10.0 - google.golang.org/grpc: v1.65.0 -> v1.84.0 - golang.org/x/crypto: v0.25.0 -> v0.57.0 - golang.org/x/net: v0.27.0 -> v0.59.0 - golang.org/x/oauth2: v0.21.0 -> v0.37.0 - golang.org/x/text: v0.16.0 -> v0.42.0 - golang.org/x/mod: v0.19.0 -> v0.41.0 - github.com/go-jose/go-jose/v3: v3.0.3 -> v3.0.5 - github.com/go-jose/go-jose/v4: v4.0.2 -> v4.1.5 - github.com/golang-jwt/jwt/v4: v4.5.0 -> v4.5.2 - github.com/golang-jwt/jwt/v5: v5.2.1 -> v5.3.1 - go.opentelemetry.io/otel/sdk: v1.28.0 -> v1.46.0 - github.com/ory/dockertest/v3: v3.11.0 -> v3.12.0 pgx stays at v5.10.0 and not at v5.11.0. v5.11.0 replaces the connection URI parser: it ends the user part at the first "@" and keeps "+" in a query value as a literal character, so a DSN that works today can fail to connect. v5.10.0 has the CVE fixes (Trivy needs 5.9.0). RunTestSMTP and CleanUpTestSMTP move from package x to internal/testhelpers. Package x is part of the server, so the helper linked dockertest, docker/cli and runc into the release binary. The bump of dockertest does not reach the fixed versions of docker/cli (29.2.0) and runc (1.2.8), and the server does not use these modules. Effects of the go directive, and their fixes: - Go 1.26 vet rejects a non-constant format string, and go test runs that check. Eight calls change to a constant format or to the non-format function, as upstream Ory did. - golang.org/x/net v0.59.0 marks its context.Context alias for inlining, and govet reports each use, so the password settings strategy imports the standard context package. - go-swagger v0.31.0 panics on a type alias, and Go 1.23 and later materialize aliases by default. The sdk make target sets GODEBUG=gotypesalias=0 for the spec generation step. With it, the generated spec is identical to the committed spec/swagger.json. Go 1.27 removes this setting, so go-swagger must change before that toolchain move. Newer go-swagger releases and the upstream fork change the generated spec, so they are not used here. - licenses.yml and format.yml: Go 1.22 -> 1.26. With Go 1.22 the toolchain switch made go-licenses reject each standard library package. Scan workflow (cve-scan.yaml) gate changes: - It now also runs on a push to goodnotes and on a pull request into goodnotes. Before, a fork pull request got no scan until the tag. - The three Anchore steps are removed. The Anchore step failed on every run before it scanned: scan-action v3 pins grype v0.74.4, and grype refuses a vulnerability database that is more than 5 days old. Its SARIF upload used the deprecated CodeQL v2 action. - .grype.yaml is deleted, because the Anchore step was its only reader. - The Trivy step stays as the vulnerability gate (CRITICAL and HIGH, exit code 42). Claude-Session: https://claude.ai/code/session_01A5FnxmDnKJUUrV6ZBFMCHU
77d78c5 to
ffc99c0
Compare
|
Check before the rollout of the next tag: database pool size. The Kratos sizes two things from
Example: a pod with CPU limit 1 on a 16-core node, and a DSN with no There is no effect if the pod has no CPU limit, or if the DSN sets If the limit is set and the DSN does not size the pool, set Source: review round |
|
Ship summary: https://claude.ai/artifact/MBuH8YKC2du3PVCNCy7ZLx |
Bumps 14 Go modules to versions with the CVE fixes (
pgxv5.10.0,grpcv1.84.0,golang.org/x/*,go-jose,jwt,otel/sdk), raises thegodirective to 1.26.0, movesRunTestSMTPtointernal/testhelpersso thatdockertest,docker/cli, andruncleave the release binary, and makescve-scan.yamlrun ongoodnoteswithout the broken Anchore steps.Trivy on
v1.3.0-gn-v10found 3 CRITICAL and 36 HIGH findings inusr/bin/kratos, and each fork image from v8 has them;pgxstays at v5.10.0 because v5.11.0 reads a DSN differently, andmake sdksetsGODEBUG=gotypesalias=0becausego-swaggerv0.31.0 panics on type aliases (this holds until Go 1.27).Tested: Trivy on the
make dockerimage reports 0 findings, locally and in thescannerscheck; 464 migrations,serve, identity create, and password login pass against CockroachDB v22.2.6;golangci-lintreports 0 issues; the generated spec is identical to the committedspec/swagger.json; the short suite gives 5,179 pass, 191 fail, 55 skip on this branch and on the base commit, with identical failed tests.Not fixed here: the
CItest and end-to-end jobs were red ongoodnotesbefore this PR, and Trivy cannot seeCVE-2026-33503(Kratos itself, HIGH) in the image, because the image build gives the binary no module version.Do not merge before a human review, and merge with a merge commit.
https://claude.ai/code/session_01A5FnxmDnKJUUrV6ZBFMCHU