Skip to content

fix(security): remediate Console image dependencies - #809

Closed
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/console-image-remediation-20260925
Closed

plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/console-image-remediation-20260925

Conversation

@plural-copilot

Copy link
Copy Markdown
Contributor

Summary

  • CVE-2026-93990: pin the final runtime-stage Alpine package from libexpat 2.8.4-r0 to exactly 2.8.5-r0.
  • CVE-2026-81870: upgrade go.opentelemetry.io/otel/sdk v1.44.0 -> v1.45.0, with the required coherent family moves: otel, metric, sdk/metric, and trace v1.44.0 -> v1.45.0; otel/metric/x v0.66.0 -> v0.67.0; and SDK-required github.com/go-logr/logr v1.4.3 -> v1.4.4.
  • GO-2026-5932 is intentionally not addressed: golang.org/x/crypto remains v0.56.0 because no fixed version exists.

Verified build wiring and scope

The dependency source specified for this Console remediation is plural-cli. The governing image paths are:

  • Dockerfile: final runtime stage runs apk add --no-cache git build-base libexpat=2.8.5-r0. git pulls libexpat in that live runtime transaction, so the pin is not confined to an unused build stage.
  • .github/workflows/ci.yaml: build-image builds that Dockerfile from repository-root context; publish-image assembles/pushes the plural-cli image.

No GitOps, image tag, deployment-manifest, or promotion changes are included.

Validation

  • Passed: docker run --rm -v "$PWD":/workspace -w /workspace golang:1.26.6-alpine3.24 sh -ec 'go mod verify; go list -m all ...' — module integrity passed; resolved OTel is v1.45.0; golang.org/x/crypto remains v0.56.0.
  • Passed: docker run ... golang:1.26.6-alpine3.24 sh -ec 'go test ./pkg/console'.
  • Passed: docker run --rm alpine:3.24 sh -ec 'apk update; apk add --simulate git build-base' — the runtime transaction includes libexpat 2.8.5-r0.
  • Attempted: timeout 10m docker build --build-arg TARGETARCH=amd64 ... -t plural-cli-remediation:local . — dependency stage completed, but compilation of cmd/plural exceeded the local timeout (exit 124), so no local image was produced.

This source PR does not publish or promote an image. GitOps promotion requires a published rebuilt Console image.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create one remediation PR for fixable vulnerabilities in the live Console image ghcr.io/pluralsh/console:sha-debb0b5 (digest sha256:b8de0f568c0e49e7b505cb3716caf92746302afb5db386c42e0d2be190a26c28). Although this is a Console image, its Go dependencies are intentionally sourced from plural-cli....
🔗 Run history View run history

@greptile-apps

greptile-apps Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[High risk] Updates Go dependencies and container base image.

The PR appears safe to merge, though the exact Alpine package pin should be made resilient to future package revisions.

Findings

  1. P2 Exact pin risks future builds ▶

Summary

This PR pins the final image’s libexpat package and upgrades the OpenTelemetry dependency family and go-logr/logr.

  • The exact Alpine package revision creates a future image-build maintenance risk.
  • Greptile automatically discovered no related ticket that informed this review.

Reviews (1) · Last reviewed commit: "fix(security): remediate console image d..."

Comment thread Dockerfile
WORKDIR /

RUN apk update && apk add --no-cache git build-base
RUN apk update && apk add --no-cache git build-base libexpat=2.8.5-r0

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Exact pin risks future builds

If Alpine 3.24 replaces libexpat 2.8.5-r0 with a newer revision, this exact pin will make apk add fail instead of installing the updated package. That would interrupt the amd64 and arm64 image builds until the Dockerfile is changed. A minimum-version constraint would retain the security floor without tying builds to one revision.

@michaeljguarino
michaeljguarino deleted the agent/console-image-remediation-20260925 branch September 25, 2026 18:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant