Skip to content

fix(nvca): bump distroless/go base image to v4.1.4 on v3.2 - #2129

Merged
apartha-nv merged 1 commit into
release-src/compute-plane-services/nvca/v3.2from
fix/nvca-v3.2-base-image-bump
Sep 28, 2026
Merged

apartha-nv merged 1 commit into
release-src/compute-plane-services/nvca/v3.2from
fix/nvca-v3.2-base-image-bump

Conversation

@apartha-nv

Copy link
Copy Markdown
Contributor

Summary

  • nvca, nvca-operator, and cluster-validator 3.2.25 images all fail the nSpect LaunchAPI container-oss-vulns-out-of-sla gate with an identical 9 count.
  • govulncheck shows 0 code-reachable Go vulnerabilities (post fix(nvca): bump grpc to remediate container OSS vuln SLA failures on v3.2 #2118 grpc bump).
  • trivy, scanning the distroless/go:v4.0.8 base image SBOM against Debian's own vendor security tracker, also shows 0 vulnerabilities across all 9 packages.
  • Since the count is identical across all three images (including cluster-validator, which doesn't use grpc), this points to the shared base OS layer — most likely raw-NVD version matching flagging Debian backport patches (+deb13uN) that vendor-aware scanners already treat as fixed.

Change

  • Bump distroless_go base image pin from v4.0.8 → v4.1.4 (latest, same family). Picks up newer libc6, libssl3t64/openssl-provider-fips, and tzdata patch versions, which may shift past whatever version nSpect's NVD matcher is keying on.
  • trivy scan of the v4.1.4 SBOM also reports 0 vulnerabilities.

Test plan

  • bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator} succeeds
  • Re-run nSpect LaunchAPI on the next cut tag to confirm the SLA gate clears

The nvca, nvca-operator, and cluster-validator 3.2.25 images all
report the same 9 out-of-SLA vulnerabilities on the nSpect LaunchAPI
container-oss-vulns-out-of-sla gate, despite:

- govulncheck showing 0 code-reachable Go vulnerabilities (nvca,
  cluster-validator)
- trivy, scanning the base image's own SBOM against Debian's vendor
  security tracker, showing 0 vulnerabilities for all 9 packages in
  nvcr.io/nvidia/distroless/go:v4.0.8

The identical count across all three images (including
cluster-validator, which doesn't depend on grpc) points to a shared,
non-application-specific source on the base OS layer -- likely raw
NVD version-string matching against Debian's backport patch versions,
which vendor-aware scanners already treat as patched.

Bumping to v4.1.4 (latest available, same distroless family) picks up
newer patch versions of libc6, libssl3t64/openssl-provider-fips, and
tzdata, which may shift past whatever version nSpect's matcher is
keying on. trivy scan of the v4.1.4 SBOM also reports 0 vulnerabilities.

Verified with a full bazel build of the nvca, nvca-operator, and
cluster-validator targets.

Closes NO-REF
@apartha-nv
apartha-nv requested a review from a team as a code owner September 28, 2026 10:12
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

🗂️ Base branches to auto review (1)
  • main

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: NVIDIA/nvcf/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: f7d23871-f8e8-4886-8939-a46213d33158

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@apartha-nv
apartha-nv merged commit 7a5e56f into release-src/compute-plane-services/nvca/v3.2 Sep 28, 2026
18 checks passed
@apartha-nv
apartha-nv deleted the fix/nvca-v3.2-base-image-bump branch September 28, 2026 14:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants