fix(nvca): bump grpc and distroless/go base image to remediate container OSS vuln SLA failures - #2161
apartha-nv wants to merge 2 commits into
Conversation
…ner OSS vuln SLA failures Ports the fixes from the release-src/compute-plane-services/nvca/v3.2 backport line (#2118, #2129) forward to main. govulncheck identified google.golang.org/grpc@v1.79.3 as the only code-reachable vulnerable dependency: - GO-2026-6348: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation - GO-2026-6061: xDS RBAC authorization engine and HTTP/2 transport server vulnerabilities Bumped to google.golang.org/grpc@v1.83.1 (fixes both). govulncheck now reports 0 code-reachable vulnerabilities for cmd/nvca. Also bumped the shared distroless_go base image pin in the root MODULE.bazel v4.1.2 -> v4.1.4 (latest, same family; already fairly current on main, so the diff is small). This picks up newer libc6, libssl3t64/openssl-provider-fips, and tzdata patch versions, which appear to resolve nSpect's raw-NVD container-oss-vulns-out-of-sla false positives on the base OS layer, per the same investigation done on the v3.2 backport line. Note this pin is shared by all Go services on main, not just nvca. vendor/ and BUILD.bazel regenerated via `go mod vendor` (this vendor tree isn't gazelle-scoped cleanly from this environment, so BUILD.bazel gaps were fixed by hand, iteratively validated against `bazel build`). Verified with `bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator}`, which succeeds cleanly with no missing-dependency errors. Closes NO-REF
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important Review skippedWe couldn't safely recover the incremental review. No full review was started, and the last reviewed checkpoint was preserved. Retry later, or explicitly request a full review by commenting You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 📝 WalkthroughWalkthroughThe pull request updates the pinned distroless Go image digest and indirect dependencies in the NVCA Go module. ChangesContainer image pin
NVCA Go dependencies
Priority: ⬆️ High Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to No actionable risk from these updates is established; the PR is mergeable after normal checks. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Summary
Ports the fixes from the
release-src/compute-plane-services/nvca/v3.2backport line (#2118, #2129) forward tomain.govulncheckidentifiedgoogle.golang.org/grpc@v1.79.3as the only code-reachable vulnerable dependency:GO-2026-6348: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame FragmentationGO-2026-6061: xDS RBAC authorization engine and HTTP/2 transport server vulnerabilitiesgoogle.golang.org/grpc@v1.83.1(fixes both).govulnchecknow reports 0 code-reachable vulnerabilities forcmd/nvca.distroless_gobase image pin in the rootMODULE.bazel: v4.1.2 → v4.1.4 (latest, same family). Main was already fairly current here so the diff is small, but this affects all Go services building against this pin, not just nvca — flagging for visibility.Notes for reviewers
vendor/regenerated viago mod vendor;BUILD.bazelgaps were fixed by hand and iteratively validated againstbazel build(gazelle doesn't cleanly scope to just this vendor tree from this environment).bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator}succeeds cleanly with no missing-dependency errors.Test plan
go buildsucceeds fornvca,nvca-operator,cluster-validatorbazel buildsucceeds for the same three targetsgovulncheck ./cmd/nvca/...reports 0 vulnerabilitiesgofmtclean (no new formatting issues)Summary by CodeRabbit