Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,10 @@ RUN npm run build
# Runtime stage - multi-arch base image
# ==============================================
# Image pinned to a SHA256 digest for reproducible builds.
FROM alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
# To refresh: `docker buildx imagetools inspect alpine:3.24.1` and update the
# digest below. This is the multi-arch index digest, not a per-platform one, so
# it stays correct for every TARGETARCH this image is built for.
FROM alpine:3.24.1@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b

# Re-declare args for use in this stage
ARG TARGETARCH
Expand Down
8 changes: 5 additions & 3 deletions scripts/scan-shipped-image.sh
Original file line number Diff line number Diff line change
Expand Up @@ -39,9 +39,11 @@
# WHAT IT DOES NOT COVER. OS package CVEs in the base image (musl, openssl,
# zlib, curl). govulncheck only knows about Go modules and the Go standard
# library. A Trivy scan-type: image step would cover those; it is not added
# here because the pinned alpine:3.21.3 runtime base already carries fixable
# CRITICAL/HIGH openssl, musl and zlib advisories, so such a gate would land
# red. Tracked separately.
# here, and is tracked separately. The reason it was originally deferred is
# gone: the runtime base was alpine:3.21.3, which carried fixable CRITICAL/HIGH
# openssl, musl and zlib advisories that would have landed such a gate red on
# day one. The base is now alpine:3.24.1, measured clean of fixable
# CRITICAL/HIGH OS advisories, so adding that gate is unblocked.
#
# Exit 0 = every Go binary found, and no advisory with a published fix.
# Exit 1 = at least one fixable advisory, or the enumeration came back empty.
Expand Down
Loading