fix(security): remediate Console image dependencies - #809
plural-copilot[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:
| Name | Details |
|---|---|
| 💬 Prompt | Create one remediation PR for fixable vulnerabilities in the live Console image ghcr.io/pluralsh/console:sha-debb0b5 (digest sha256:b8de0f568c0e49e7b505cb3716caf92746302afb5db386c42e0d2be190a26c28). Although this is a Console image, its Go dependencies are intentionally sourced from plural-cli.... |
| 🔗 Run history | View run history |
|
| WORKDIR / | ||
|
|
||
| RUN apk update && apk add --no-cache git build-base | ||
| RUN apk update && apk add --no-cache git build-base libexpat=2.8.5-r0 |
There was a problem hiding this comment.
If Alpine 3.24 replaces libexpat 2.8.5-r0 with a newer revision, this exact pin will make apk add fail instead of installing the updated package. That would interrupt the amd64 and arm64 image builds until the Dockerfile is changed. A minimum-version constraint would retain the security floor without tying builds to one revision.
Summary
libexpat 2.8.4-r0to exactly2.8.5-r0.go.opentelemetry.io/otel/sdk v1.44.0 -> v1.45.0, with the required coherent family moves:otel,metric,sdk/metric, andtracev1.44.0 -> v1.45.0;otel/metric/x v0.66.0 -> v0.67.0; and SDK-requiredgithub.com/go-logr/logr v1.4.3 -> v1.4.4.GO-2026-5932is intentionally not addressed:golang.org/x/cryptoremainsv0.56.0because no fixed version exists.Verified build wiring and scope
The dependency source specified for this Console remediation is plural-cli. The governing image paths are:
Dockerfile: final runtime stage runsapk add --no-cache git build-base libexpat=2.8.5-r0.gitpullslibexpatin that live runtime transaction, so the pin is not confined to an unused build stage..github/workflows/ci.yaml:build-imagebuilds that Dockerfile from repository-root context;publish-imageassembles/pushes the plural-cli image.No GitOps, image tag, deployment-manifest, or promotion changes are included.
Validation
docker run --rm -v "$PWD":/workspace -w /workspace golang:1.26.6-alpine3.24 sh -ec 'go mod verify; go list -m all ...'— module integrity passed; resolved OTel isv1.45.0;golang.org/x/cryptoremainsv0.56.0.docker run ... golang:1.26.6-alpine3.24 sh -ec 'go test ./pkg/console'.docker run --rm alpine:3.24 sh -ec 'apk update; apk add --simulate git build-base'— the runtime transaction includeslibexpat 2.8.5-r0.timeout 10m docker build --build-arg TARGETARCH=amd64 ... -t plural-cli-remediation:local .— dependency stage completed, but compilation ofcmd/pluralexceeded the local timeout (exit 124), so no local image was produced.This source PR does not publish or promote an image. GitOps promotion requires a published rebuilt Console image.