mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-18 04:20:53 +02:00
* security: require go 1.26.6 and bump vulnerable deps A dependency scan of the 4.47 release flagged the bundled toolchain and modules: - github.com/golang/go < 1.26.6 (CVE-2026-39821, CVE-2026-56853, CVE-2026-56859, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865, CVE-2026-33818, CVE-2026-46600): raise the go directive to 1.26.6 so every built artifact requires the fixed toolchain. - google.golang.org/grpc (CVE-2026-84445, CVE-2026-84304): move to the fixed dev pseudo-version; released tags through v1.85.0-dev remain in the affected range. - github.com/pelletier/go-toml/v2 <= v2.4.2 (unbounded parser recursion): v2.4.3. - alpine libcrypto3/libssl3 < 3.5.8-r0 (CVE-2026-75803, CVE-2026-63073, CVE-2026-63075, CVE-2026-63076, CVE-2026-63072, CVE-2026-54874, CVE-2026-18798, CVE-2026-14456, CVE-2026-14457): the release images already apk-upgrade the final stage; extend the same to the telemetry and admin-integration images. Same bumps applied to the test/kafka, test/sftp, kafka-client-loadtest, and telemetry/server modules. * telemetry: send integration test report above the 10 GiB floor The collect endpoint keeps reports only when TotalDiskBytes >= proto.MinDiskBytes, but the integration test still sent 1 GiB, so the server counted the report and skipped storing it. No cluster_id series was ever created and /metrics lacked seaweedfs_telemetry_volume_servers. Send just above the floor (via proto.MinDiskBytes so it cannot silently drift again) so the expected per-cluster metrics are exported.
27 lines
580 B
Docker
27 lines
580 B
Docker
FROM golang:1.26-alpine AS builder
|
|
|
|
WORKDIR /app
|
|
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
WORKDIR /app
|
|
COPY . .
|
|
|
|
WORKDIR /app/telemetry/server
|
|
RUN CGO_ENABLED=0 GOOS=linux go build -a -installsuffix cgo -ldflags '-extldflags "-static"' -o telemetry-server .
|
|
|
|
FROM alpine:latest
|
|
RUN apk upgrade --no-cache \
|
|
&& apk --no-cache add ca-certificates libcrypto3 libssl3 \
|
|
&& addgroup -S appgroup \
|
|
&& adduser -S appuser -G appgroup
|
|
|
|
WORKDIR /home/appuser/
|
|
COPY --from=builder /app/telemetry/server/telemetry-server .
|
|
|
|
EXPOSE 8080
|
|
|
|
USER appuser
|
|
|
|
CMD ["./telemetry-server"] |