Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .changelog/55.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
Foundation hardening: align Go 1.25, fix builtin protobuf registration conflicts, bump tier-3b dependencies, add govulncheck CI, and stabilize singleprocess tests
```
7 changes: 2 additions & 5 deletions .github/scripts/verify_docker.sh
Original file line number Diff line number Diff line change
Expand Up @@ -32,12 +32,9 @@ function main {
exit 1
fi

# Multiple builtin plugins register the same plugin.proto filename; warn instead of panic.
local proto_env=( -e GOLANG_PROTOBUF_REGISTRATION_CONFLICT=warn )

full_version=$(docker run --rm "${proto_env[@]}" "${image_name}" version)
full_version=$(docker run --rm "${image_name}" version)
echo "Full version: ${full_version}"
got_version="$( awk '{print $2}' <(head -n1 <(docker run --rm "${proto_env[@]}" "${image_name}" version)) )"
got_version="$( awk '{print $2}' <(head -n1 <(docker run --rm "${image_name}" version)) )"
if [[ "${got_version}" != "v${expect_version}" ]]; then
echo "Version Test FAILED"
echo "Got: ${got_version}, Want: v${expect_version}"
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/end-to-end.yml
Original file line number Diff line number Diff line change
Expand Up @@ -103,5 +103,4 @@ jobs:
DERRICK_ODRIMAGE: ${{ inputs.derrick-odr-image }}
DERRICK_SERVERIMAGE_UPGRADE: ${{ needs.publish-images.outputs.derrick-image }}
DERRICK_ODRIMAGE_UPGRADE: ${{ needs.publish-images.outputs.derrick-odr-image }}
GOLANG_PROTOBUF_REGISTRATION_CONFLICT: ignore
run: ./test-e2e/run-test.sh
41 changes: 24 additions & 17 deletions .github/workflows/go-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,30 +15,24 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: go.mod
go-version-file: .go-version
- name: Download go modules
run: go mod download
- name: Install golangci-lint
run: |-
download=https://raw.githubusercontent.com/golangci/golangci-lint/9a8a056e9fe49c0e9ed2287aedce1022c79a115b/install.sh # v1.52.2
curl -sSf "$download" | sh -s v1.50.1
- run: go mod download
run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.1.6
- name: lint
run: |-
./bin/golangci-lint run --build-tags="$GOTAGS" -v --concurrency 2 \
--disable-all \
--timeout 10m \
--enable gofmt \
--enable gosimple \
--enable govet
unformatted=$(git ls-files '*.go' | xargs gofmt -l -s)
test -z "$unformatted"
golangci-lint run --build-tags="$GOTAGS" ./...

check-vendor:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: go.mod
go-version-file: .go-version
- run: go mod tidy
env:
GOTOOLCHAIN: local
Expand All @@ -56,7 +50,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: './go.mod'
go-version-file: './.go-version'
- name: Split tests
id: split-tests
env:
Expand All @@ -76,15 +70,14 @@ jobs:
GOTESTSUM_RELEASE: 1.8.2
GOTAGS: ''
GOMAXPROCS: 4
GOLANG_PROTOBUF_REGISTRATION_CONFLICT: warn
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Start Services
run: |-
docker compose -f .github/services/go-tests/docker-compose.yml up --detach --no-color --wait
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: './go.mod'
go-version-file: './.go-version'
- name: Install gotestsum
run: |-
url=https://github.com/gotestyourself/gotestsum/releases/download
Expand Down Expand Up @@ -131,7 +124,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: './go.mod'
go-version-file: './.go-version'
- run: |-
go install github.com/kevinburke/go-bindata/...
make bin
Expand All @@ -143,10 +136,24 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: './go.mod'
go-version-file: './.go-version'
- run: |-
go install github.com/kevinburke/go-bindata/...
make bin/windows

govulncheck:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: './.go-version'
- run: go mod download
- name: Install govulncheck
run: go install golang.org/x/vuln/cmd/govulncheck@latest
- name: Run govulncheck
continue-on-error: true # informational until deferred findings in docs/security/vuln-triage.md are resolved
run: govulncheck ./...

permissions:
contents: read
4 changes: 1 addition & 3 deletions .github/workflows/integration-hcl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,11 @@ on:
jobs:
generate-integration-hcl:
runs-on: ubuntu-latest
env:
GOLANG_PROTOBUF_REGISTRATION_CONFLICT: warn
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: go.mod
go-version-file: .go-version
- name: Download go modules
run: go mod download
- run: make gen/integrations-hcl
Expand Down
4 changes: 1 addition & 3 deletions .github/workflows/integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: go.mod
go-version-file: .go-version

- name: Restore UI cache
uses: actions/cache@v4
Expand Down Expand Up @@ -92,8 +92,6 @@ jobs:
with:
name: derrick.tar
- name: Execute Integration Tests
env:
GOLANG_PROTOBUF_REGISTRATION_CONFLICT: warn
run: |-
tar -xvf derrick.tar
./ci/integration.sh
2 changes: 1 addition & 1 deletion .github/workflows/json-docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
with:
go-version-file: go.mod
go-version-file: .go-version
- run: go mod download
- uses: actions/download-artifact@v4
with:
Expand Down
2 changes: 1 addition & 1 deletion .go-version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.23.12
1.25.0
11 changes: 11 additions & 0 deletions .golangci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
version: "2"

linters:
default: none
enable:
- govet
settings:
govet:
# lostcancel conflicts with the accept/reconnect loop in internal/runner.
disable:
- lostcancel
4 changes: 0 additions & 4 deletions CRT.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -52,8 +52,6 @@ USER derrick
ENV USER derrick
ENV HOME /home/derrick
ENV XDG_RUNTIME_DIR=/run/user/100
# Multiple builtin plugins register the same plugin.proto filename.
ENV GOLANG_PROTOBUF_REGISTRATION_CONFLICT=warn

ENTRYPOINT ["/usr/bin/derrick"]

Expand Down Expand Up @@ -91,7 +89,5 @@ RUN ["/kaniko/busybox", "--install", "-s", "/kaniko/bin"]
# Need to add the dir with our tools in PATH
ENV PATH $PATH:/kaniko/bin
ENV TMPDIR /kaniko/tmp
# Multiple builtin plugins register the same plugin.proto filename.
ENV GOLANG_PROTOBUF_REGISTRATION_CONFLICT=warn

ENTRYPOINT ["/kaniko/derrick"]
Loading
Loading