Build the image with Go 1.26.9
The Dockerfile builder was still golang:1.25-alpine, which resolves to
Go 1.25.14, so eb63e5e moved CI and the release workflow to 1.26.9 but the
published binary kept the standard library it was meant to leave. v0.44.0's
image scan reported CVE-2026-78667, CVE-2026-78669 and CVE-2026-97031 in
it, all fixed in 1.26.9. Pin the builder to the same version the
workflows use.
Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
This commit is contained in:
+1
-1
@@ -4,7 +4,7 @@
|
||||
# in per platform. The CI runner has no binfmt registration and no way to get one (the
|
||||
# JS action that used to install it cannot run there), so this is not just an
|
||||
# optimisation -- it is what makes the arm64 image buildable at all.
|
||||
FROM --platform=$BUILDPLATFORM golang:1.25-alpine AS builder
|
||||
FROM --platform=$BUILDPLATFORM golang:1.26.9-alpine AS builder
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
Reference in New Issue
Block a user