Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
ARG TOOLS_IMAGE=${OS_VARIANT}:${OS_VERSION}
ARG RUNNER_IMAGE=alpine:3.23.4 # TODO: change back to ${OS_VARIANT}:${OS_VERSION}

FROM node:24.11.1-alpine as node

Check warning on line 8 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test Build Docker image

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/

WORKDIR /app

Expand All @@ -27,12 +27,12 @@
COPY js/console/ ./console/
COPY js/design-system/ ./design-system/

ARG VITE_PROD_SECRET_KEY

Check warning on line 30 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test Build Docker image

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "VITE_PROD_SECRET_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
ARG VITE_SENTRY_DSN
ARG SENTRY_AUTH_TOKEN

Check warning on line 32 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test Build Docker image

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "SENTRY_AUTH_TOKEN") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
ARG GIT_COMMIT

ENV VITE_PROD_SECRET_KEY=${VITE_PROD_SECRET_KEY} \

Check warning on line 35 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test Build Docker image

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "SENTRY_AUTH_TOKEN") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 35 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test Build Docker image

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "VITE_PROD_SECRET_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
VITE_GIT_COMMIT=${GIT_COMMIT} \
VITE_SENTRY_DSN=${VITE_SENTRY_DSN} \
SENTRY_AUTH_TOKEN=${SENTRY_AUTH_TOKEN}
Expand Down Expand Up @@ -88,7 +88,7 @@

RUN mix do db.certs, agent.chart, sentry.package_source_code, release

FROM alpine:3.21.3 as tools

Check warning on line 91 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test Build Docker image

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/

ARG TARGETARCH=amd64
ENV CLI_VERSION=v0.12.66
Expand Down Expand Up @@ -152,4 +152,5 @@

EXPOSE 4000 6000 4369 50051

CMD mkdir -p /tmp/sqlite; /opt/app/bin/console start

Check warning on line 155 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test Build Docker image

JSON arguments recommended for ENTRYPOINT/CMD to prevent unintended behavior related to OS signals

JSONArgsRecommended: JSON arguments recommended for CMD to prevent unintended behavior related to OS signals More info: https://docs.docker.com/go/dockerfile/rule/json-args-recommended/
HEALTHCHECK --interval=30s --timeout=5s --start-period=30s --retries=3 CMD ["/bin/sh", "-c", "wget -q -O /dev/null http://127.0.0.1:4000/health || wget -q -O /dev/null http://127.0.0.1:4000/"]
7 changes: 3 additions & 4 deletions dockerfiles/Dockerfile.softserve
Original file line number Diff line number Diff line change
Expand Up @@ -12,10 +12,9 @@ EXPOSE 23233
EXPOSE 9418

# basics, in case need to access shell to debug/troubleshoot
RUN apk update --no-cache
# Upgrade OpenSSL packages to fix CVE-2025-1670 (NULL pointer dereference in CMS EnvelopedData processing)
# and QUIC PATH_CHALLENGE DoS vulnerability
RUN apk add --no-cache "libssl3>=3.5.7-r0" "libcrypto3>=3.5.7-r0"
RUN apk update --no-cache && apk add --no-cache "libssl3>=3.5.7-r0" "libcrypto3>=3.5.7-r0"
# Upgrade libexpat to fix authorization bypass vulnerability allowing arbitrary SQL execution
RUN apk upgrade --no-cache libexpat
# Upgrade zlib to fix buffer overflow vulnerability in untgz utility (CVE in zlib <= 1.3.1)
Expand Down Expand Up @@ -51,10 +50,9 @@ EXPOSE 23233
EXPOSE 9418

# needs git for repos to be accessible
RUN apk update --no-cache
# Upgrade OpenSSL packages to fix CVE-2025-1670 (NULL pointer dereference in CMS EnvelopedData processing)
# and QUIC PATH_CHALLENGE DoS vulnerability
RUN apk add --no-cache "libssl3>=3.5.7-r0" "libcrypto3>=3.5.7-r0"
RUN apk update --no-cache && apk add --no-cache "libssl3>=3.5.7-r0" "libcrypto3>=3.5.7-r0"
# Upgrade libexpat to fix authorization bypass vulnerability allowing arbitrary SQL execution
RUN apk upgrade --no-cache libexpat musl musl-utils zlib
RUN apk add --no-cache git
Expand All @@ -68,3 +66,4 @@ RUN chown -R softserve:softserve /data
USER softserve

ENTRYPOINT [ "soft", "serve" ]
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["soft", "--help"]
2 changes: 1 addition & 1 deletion dockerfiles/Dockerfile.test
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ RUN if [ "$OS_VARIANT" = "alpine" ]; then \
apk update && apk upgrade --no-cache && \
apk add --no-cache git build-base curl ca-certificates; \
else \
apt-get update && apt-get install -y git build-essential curl ca-certificates; \
apt-get update && apt-get install -y --no-install-recommends git build-essential curl ca-certificates; \
rm -rf "${RUSTUP_HOME}" "${CARGO_HOME}"; \
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --profile minimal --default-toolchain ${RUST_TOOLCHAIN}; \
fi && \
Expand Down
1 change: 1 addition & 0 deletions go/ai-proxy/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Build the binary
FROM golang:1.27.1 as builder

Check warning on line 2 in go/ai-proxy/Dockerfile

View workflow job for this annotation

GitHub Actions / Build ai-proxy image (linux/arm64, ubuntu-24.04-arm)

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/

Check warning on line 2 in go/ai-proxy/Dockerfile

View workflow job for this annotation

GitHub Actions / Build ai-proxy image (linux/amd64, ubuntu-24.04)

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/
ARG TARGETOS
ARG TARGETARCH
ARG VERSION
Expand Down Expand Up @@ -39,3 +39,4 @@
USER 65532:65532

ENTRYPOINT ["/ai-proxy"]
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/ai-proxy", "--help"]
10 changes: 7 additions & 3 deletions go/cloud-query/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ COPY internal/ internal/
# Build the cloud-query binary
RUN CGO_ENABLED=0 go build -o bin/cloud-query cmd/*.go

FROM cgr.dev/chainguard/wolfi-base AS final
FROM cgr.dev/chainguard/wolfi-base:latest AS final

ARG BUILD_TIME=1970-01-01T00:00:00Z
ARG GIT_COMMIT=unknown
Expand All @@ -40,6 +40,10 @@ LABEL org.opencontainers.image.created="${BUILD_TIME}" \
# Copy cloud-query and steampipe extensions
COPY --from=builder /workspace/bin/cloud-query /usr/local/bin/cloud-query

USER nonroot
USER root

CMD ["/usr/local/bin/cloud-query"]
EXPOSE 8080
RUN apk add --no-cache curl
USER nonroot
CMD ["/usr/local/bin/cloud-query"]
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 CMD ["curl", "--fail", "--silent", "--show-error", "http://127.0.0.1:8080/healthz"]
1 change: 1 addition & 0 deletions go/controller/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -58,3 +58,4 @@ COPY --from=builder /workspace/controller/manager .
USER 65532:65532

ENTRYPOINT ["/manager"]
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/manager", "--help"]
1 change: 1 addition & 0 deletions go/datastore/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -39,3 +39,4 @@ COPY --from=builder /workspace/controller/manager .
USER 65532:65532

ENTRYPOINT ["/manager"]
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/manager", "--help"]
2 changes: 1 addition & 1 deletion go/datastore/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -164,7 +164,7 @@ require (
gomodules.xyz/jsonpatch/v2 v2.5.0 // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20260803160001-6ac0973c030d // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d // indirect
google.golang.org/grpc v1.83.0 // indirect
google.golang.org/grpc v1.83.2 // indirect
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // indirect
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
gopkg.in/inf.v0 v0.9.1 // indirect
Expand Down
2 changes: 2 additions & 0 deletions go/datastore/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -481,6 +481,8 @@ google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d h1:
google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
google.golang.org/grpc v1.83.0 h1:JeNZEKJFbQxArAMl+hiytHauacDNqJUllNfmIMmpqnQ=
google.golang.org/grpc v1.83.0/go.mod h1:kDyl6SKsiHKt0uylY5gtn5cEjkrIOhQOGDgIc4JGwzQ=
google.golang.org/grpc v1.83.2 h1:EManeRomTObA0BU7I8vXgg/78uE5MJ9M8B39EX2WscU=
google.golang.org/grpc v1.83.2/go.mod h1:YPI1hK3kDked6iHvgX3tR0y+nX/qpMFKhPgFsokw1S8=
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af h1:+5/Sw3GsDNlEmu7TfklWKPdQ0Ykja5VEmq2i817+jbI=
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
Expand Down
7 changes: 5 additions & 2 deletions go/demo/flaky-service/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -17,13 +17,14 @@ COPY . .
RUN CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -o flaky-service .

# Step 2: Create a smaller image to run the application
FROM alpine:latest
FROM alpine:3.22

# Install necessary dependencies to run Go binaries
RUN apk --no-cache add ca-certificates

# Set the Current Working Directory inside the container
WORKDIR /root/
WORKDIR /app
RUN adduser -D -u 65532 flaky && chown flaky:flaky /app

# Copy the Go binary from the build stage
COPY --from=build /app/flaky-service .
Expand All @@ -34,3 +35,5 @@ EXPOSE 8081

# Command to run the application
CMD ["./flaky-service", "--response-behavior-modifier=timestamp", "--behavior-modifier-timestamp-modulus=3"]
USER flaky
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 CMD ["/bin/sh", "-c", "wget -q -O /dev/null http://127.0.0.1:8081/metrics"]
2 changes: 2 additions & 0 deletions go/demo/flaky-service/Dockerfile.sidecar
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,5 @@ RUN chmod +x ./api_caller.sh
# Set the default command to run the shell script with the provided arguments
CMD ["./api_caller.sh", "-e", "localhost:8080/api", "-m", "localhost:8081/metrics", "-t", "1.34"]

RUN adduser -D -u 65532 sidecar && chown sidecar:sidecar /api_caller.sh
USER sidecar
1 change: 1 addition & 0 deletions go/deployment-operator/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -56,3 +56,4 @@ USER 65532:65532
ENV GOMONTY_FFI_CACHE_DIR=/tmp/gomonty

ENTRYPOINT ["/workspace/deployment-agent"]
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/workspace/deployment-agent", "--help"]
Original file line number Diff line number Diff line change
Expand Up @@ -42,3 +42,5 @@ RUN claude-agent-acp --version

# The entrypoint remains the agent-harness binary
# The agent-harness launches claude-agent-acp, which uses the pinned Claude CLI.

HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["claude-agent-acp", "--version"]
Original file line number Diff line number Diff line change
Expand Up @@ -41,3 +41,5 @@ USER 65532:65532

# The entrypoint remains the agent-harness binary
# The agent-harness launches codex-acp directly.

HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["codex-acp", "--version"]
Original file line number Diff line number Diff line change
Expand Up @@ -36,3 +36,5 @@ USER 65532:65532

# The entrypoint remains the agent-harness binary
# The agent-harness will call the opencode CLI as needed

HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["opencode", "--version"]
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,8 @@ FROM alpine:3.22.1

RUN apk --no-cache add ca-certificates

WORKDIR /root/
WORKDIR /app
RUN adduser -D -u 65532 mcp && chown mcp:mcp /app

# Copy the binary from the builder stage
COPY --from=builder /workspace/deployment-operator/terraform-mcpserver .
Expand All @@ -35,3 +36,5 @@ COPY --from=builder /workspace/deployment-operator/terraform-mcpserver .

# Run the MCP server
CMD ["./terraform-mcpserver"]
USER mcp
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/app/terraform-mcpserver", "--help"]
10 changes: 5 additions & 5 deletions go/deployment-operator/terratest/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@ require (
github.com/evanphx/json-patch/v5 v5.9.11 // indirect
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
github.com/go-errors/errors v1.5.1 // indirect
github.com/go-logr/logr v1.4.3 // indirect
github.com/go-logr/logr v1.4.4 // indirect
github.com/go-ole/go-ole v1.3.0 // indirect
github.com/go-openapi/jsonpointer v0.22.5 // indirect
github.com/go-openapi/jsonreference v0.21.5 // indirect
Expand Down Expand Up @@ -163,10 +163,10 @@ require (
go.opentelemetry.io/collector/featuregate v1.51.1-0.20260205185216-81bc641f26c0 // indirect
go.opentelemetry.io/collector/pdata v1.51.1-0.20260205185216-81bc641f26c0 // indirect
go.opentelemetry.io/collector/pdata/pprofile v0.145.1-0.20260205185216-81bc641f26c0 // indirect
go.opentelemetry.io/otel v1.44.0 // indirect
go.opentelemetry.io/otel/metric v1.44.0 // indirect
go.opentelemetry.io/otel/sdk v1.44.0 // indirect
go.opentelemetry.io/otel/trace v1.44.0 // indirect
go.opentelemetry.io/otel v1.45.0 // indirect
go.opentelemetry.io/otel/metric v1.45.0 // indirect
go.opentelemetry.io/otel/sdk v1.45.0 // indirect
go.opentelemetry.io/otel/trace v1.45.0 // indirect
go.opentelemetry.io/proto/otlp v1.10.0 // indirect
go.uber.org/atomic v1.11.0 // indirect
go.uber.org/multierr v1.11.0 // indirect
Expand Down
11 changes: 11 additions & 0 deletions go/deployment-operator/terratest/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -169,6 +169,8 @@ github.com/go-errors/errors v1.5.1 h1:ZwEMSLRCapFLflTpT7NKaAc7ukJ8ZPEjzlxt8rPN8b
github.com/go-errors/errors v1.5.1/go.mod h1:sIVyrIiJhuEF+Pj9Ebtd6P/rEYROXFi3BopGUQ5a5Og=
github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI=
github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
github.com/go-logr/logr v1.4.4 h1:tG4xh9yMsRCAiodLVTxyrkzSZ9+o0L1Kg/+cPVcbP/8=
github.com/go-logr/logr v1.4.4/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag=
github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE=
github.com/go-logr/zapr v1.3.0 h1:XGdV8XW8zdwFiwOA2Dryh1gj2KRQyOOoNmBy4EplIcQ=
Expand Down Expand Up @@ -422,14 +424,23 @@ go.opentelemetry.io/collector/processor/xprocessor v0.145.0 h1:DaIE7MxRlg0OL1o2P
go.opentelemetry.io/collector/processor/xprocessor v0.145.0/go.mod h1:kUwRyKBU/kjCmXodd+0z7CpvcP0A9G9/QL+MaJt4U2o=
go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU=
go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc=
go.opentelemetry.io/otel v1.45.0 h1:pdrWmLHofpubmArBv1LgFSv1Z0Ie/ppdZzu+kUN5EeU=
go.opentelemetry.io/otel v1.45.0/go.mod h1:XZxIqPapzEYnhNSScF5DIqXhm/rYi0FzCe2XddAwZfQ=
go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc=
go.opentelemetry.io/otel/metric v1.44.0/go.mod h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo=
go.opentelemetry.io/otel/metric v1.45.0 h1:7Eg1uH7CJ5cXv9is6tnBe1FI6rj1nwUdbFypRm3br/M=
go.opentelemetry.io/otel/metric v1.45.0/go.mod h1:HAPbm1nd3p1PmFH7v2dR+6BjXxw+Lq4a2+pndMAm08s=
go.opentelemetry.io/otel/sdk v1.44.0 h1:nHYwb9lK+fJPU/dnT6s7W7Z8itMWyqrnVfbheVYrZ58=
go.opentelemetry.io/otel/sdk v1.44.0/go.mod h1:Osuydd3Se74nqjAKxid74N5eC+jfEqfTegHRnq58oK0=
go.opentelemetry.io/otel/sdk v1.45.0 h1:4VVSMgQ83dUgW2aoX5f6JgLvHwIvzcuLnF9lUdCSpCw=
go.opentelemetry.io/otel/sdk v1.45.0/go.mod h1:Sr40LgXV7DsKMMJMKOhUWOgMWTfAaqvm2kF0g7ilwuA=
go.opentelemetry.io/otel/sdk/metric v1.44.0 h1:3LlKgI+VjbVsjNRFZJZAJ30WjXC5VkNRks6si09iEfI=
go.opentelemetry.io/otel/sdk/metric v1.44.0/go.mod h1:5B5pMARnXxKhltooO4xUuCBorl65a4EpnTalObqOigA=
go.opentelemetry.io/otel/sdk/metric v1.45.0 h1:oVFszMfyj1Am6s24Vtc7wBb8BKLcwepJjNEYILuiE3o=
go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk=
go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE=
go.opentelemetry.io/otel/trace v1.45.0 h1:l/mP6Uv7oNO7/TblbhpbgMidxhq1uO/rPsikOyVhxag=
go.opentelemetry.io/otel/trace v1.45.0/go.mod h1:qoJJA2xNMnxRrdISU/kLtfUH2wNeQbiv+jhs/CxI8bc=
go.opentelemetry.io/proto/otlp v1.10.0 h1:IQRWgT5srOCYfiWnpqUYz9CVmbO8bFmKcwYxpuCSL2g=
go.opentelemetry.io/proto/otlp v1.10.0/go.mod h1:/CV4QoCR/S9yaPj8utp3lvQPoqMtxXdzn7ozvvozVqk=
go.opentelemetry.io/proto/slim/otlp v1.9.0 h1:fPVMv8tP3TrsqlkH1HWYUpbCY9cAIemx184VGkS6vlE=
Expand Down
2 changes: 1 addition & 1 deletion go/helm-test/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ require (
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
github.com/blang/semver/v4 v4.0.0 // indirect
github.com/chai2010/gettext-go v1.0.3 // indirect
github.com/containerd/containerd v1.7.35 // indirect
github.com/containerd/containerd v1.7.36 // indirect
github.com/containerd/errdefs v1.0.0 // indirect
github.com/containerd/log v0.1.0 // indirect
github.com/containerd/platforms v1.0.0-rc.4 // indirect
Expand Down
10 changes: 6 additions & 4 deletions go/helm-test/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,8 @@ github.com/chai2010/gettext-go v1.0.3 h1:9liNh8t+u26xl5ddmWLmsOsdNLwkdRTg5AG+JnT
github.com/chai2010/gettext-go v1.0.3/go.mod h1:y+wnP2cHYaVj19NZhYKAwEMH2CI1gNHeQQ+5AjwawxA=
github.com/containerd/containerd v1.7.35 h1:7AU2T1qI2OdNBmKkreWZ7kASHUNFItN5Hgejd9sY938=
github.com/containerd/containerd v1.7.35/go.mod h1:ozI//0TomTCLPhQREnx0IXDIQMg+Fk7yTtg9fNvU8EQ=
github.com/containerd/containerd v1.7.36 h1:HyMsOG5kmp1LQsGzqwI6Ts06T4VpYZbszfDZYB0bW5w=
github.com/containerd/containerd v1.7.36/go.mod h1:ozI//0TomTCLPhQREnx0IXDIQMg+Fk7yTtg9fNvU8EQ=
github.com/containerd/errdefs v1.0.0 h1:tg5yIfIlQIrxYtu9ajqY42W3lpS19XqdxRQeEwYG8PI=
github.com/containerd/errdefs v1.0.0/go.mod h1:+YBYIdtsnF4Iw6nWZhJcqGSg/dwvV7tyJ/kCkyJ2k+M=
github.com/containerd/log v0.1.0 h1:TCJt7ioM2cr/tfR8GPbGf9/VRAX8D2B4PjzCpfX540I=
Expand Down Expand Up @@ -285,18 +287,18 @@ github.com/spf13/cast v1.10.0 h1:h2x0u2shc1QuLHfxi+cTJvs30+ZAHOGRic8uyGTDWxY=
github.com/spf13/cast v1.10.0/go.mod h1:jNfB8QC9IA6ZuY2ZjDp0KtFO2LZZlg4S/7bzP6qqeHo=
github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU=
github.com/spf13/cobra v1.10.2/go.mod h1:7C1pvHqHw5A4vrJfjNwvOdzYu0Gml16OCs2GRiTUUS4=
github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk=
github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4=
github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0=
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
github.com/tidwall/gjson v1.18.0 h1:FIDeeyB800efLX89e5a8Y0BNH+LOngJyGrIWxG2FKQY=
github.com/tidwall/gjson v1.18.0/go.mod h1:/wbyibRr2FHMks5tjHJ5F8dMZh3AcwJEMf5vlfC0lxk=
github.com/tidwall/match v1.1.1 h1:+Ho715JplO36QYgwN9PGYNhgZvoUSc9X2c80KVTi+GA=
Expand Down Expand Up @@ -374,9 +376,9 @@ golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7
golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.0.0-20210616094352-59db8d763f22/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
Expand Down
1 change: 1 addition & 0 deletions go/kubernetes-agent/api/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -70,3 +70,4 @@ USER nonroot:nonroot
# The port that the application listens on.
EXPOSE 8000 8001
ENTRYPOINT ["/dashboard-api", "--insecure-bind-address=0.0.0.0", "--bind-address=0.0.0.0"]
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/dashboard-api", "--help"]
2 changes: 2 additions & 0 deletions go/kubernetes-agent/hack/docker/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -117,3 +117,5 @@ ENTRYPOINT ["/kas"]
# 8154 - Kubernetes API
# 8155 - Internal API
EXPOSE 8000 8001 8150 8151 8153 8154 8155
USER nonroot:nonroot
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/kas", "--help"]
2 changes: 2 additions & 0 deletions go/kubernetes-agent/hack/docker/Dockerfile.agentk
Original file line number Diff line number Diff line change
Expand Up @@ -93,3 +93,5 @@ ENTRYPOINT ["/agentk"]
# 8154 - Kubernetes API
# 8155 - Internal API
# EXPOSE 8000 8001 8150 8151 8153 8154 8155
USER nonroot:nonroot
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/agentk", "--help"]
1 change: 1 addition & 0 deletions go/nexus/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -65,3 +65,4 @@ USER nonroot:nonroot
ENTRYPOINT ["/app/nexus"]
CMD ["--config", "/app/config/config.yaml"]

HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/app/nexus", "--help"]
1 change: 1 addition & 0 deletions go/observability-proxy/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,4 @@ EXPOSE 8080
USER nonroot:nonroot

ENTRYPOINT ["/app/observability-proxy"]
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/app/observability-proxy", "--help"]
1 change: 1 addition & 0 deletions go/oci-auth/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM golang:1.27.1 as builder

Check warning on line 1 in go/oci-auth/Dockerfile

View workflow job for this annotation

GitHub Actions / Build oci-auth image (linux/arm64, ubuntu-24.04-arm)

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/

Check warning on line 1 in go/oci-auth/Dockerfile

View workflow job for this annotation

GitHub Actions / Build oci-auth image (linux/amd64, ubuntu-24.04)

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/
ARG TARGETOS
ARG TARGETARCH

Expand Down Expand Up @@ -28,3 +28,4 @@
USER 65532:65532

ENTRYPOINT ["/oci-auth"]
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/oci-auth", "--help"]
2 changes: 1 addition & 1 deletion go/tools/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@ require (
github.com/ckaznocha/intrange v0.3.1 // indirect
github.com/clipperhouse/displaywidth v0.11.0 // indirect
github.com/clipperhouse/uax29/v2 v2.7.0 // indirect
github.com/containerd/containerd v1.7.35 // indirect
github.com/containerd/containerd v1.7.36 // indirect

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Containerd checksums are missing. This module selects containerd v1.7.36, but its go.sum still records only v1.7.35; the same mismatch exists in go/helm-test. Keeping the sums out of sync makes a clean or read-only dependency build that needs containerd depend on regenerating them.

github.com/containerd/errdefs v1.0.0 // indirect
github.com/containerd/platforms v1.0.0-rc.4 // indirect
github.com/curioswitch/go-reassign v0.3.0 // indirect
Expand Down
Loading
Loading