Skip to content

fix(nvca): bump grpc and distroless/go base image to remediate container OSS vuln SLA failures - #2161

Open
apartha-nv wants to merge 2 commits into
mainfrom
fix/nvca-main-container-oss-vulns-sla-v2
Open

apartha-nv wants to merge 2 commits into
mainfrom
fix/nvca-main-container-oss-vulns-sla-v2

Conversation

@apartha-nv

@apartha-nv apartha-nv commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Ports the fixes from the release-src/compute-plane-services/nvca/v3.2 backport line (#2118, #2129) forward to main.

  • govulncheck identified google.golang.org/grpc@v1.79.3 as the only code-reachable vulnerable dependency:
    • GO-2026-6348: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
    • GO-2026-6061: xDS RBAC authorization engine and HTTP/2 transport server vulnerabilities
  • Bumped to google.golang.org/grpc@v1.83.1 (fixes both). govulncheck now reports 0 code-reachable vulnerabilities for cmd/nvca.
  • Also bumped the shared distroless_go base image pin in the root MODULE.bazel: v4.1.2 → v4.1.4 (latest, same family). Main was already fairly current here so the diff is small, but this affects all Go services building against this pin, not just nvca — flagging for visibility.

Notes for reviewers

  • vendor/ regenerated via go mod vendor; BUILD.bazel gaps were fixed by hand and iteratively validated against bazel build (gazelle doesn't cleanly scope to just this vendor tree from this environment).
  • Verified locally: bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator} succeeds cleanly with no missing-dependency errors.

Test plan

  • go build succeeds for nvca, nvca-operator, cluster-validator
  • bazel build succeeds for the same three targets
  • govulncheck ./cmd/nvca/... reports 0 vulnerabilities
  • gofmt clean (no new formatting issues)

Summary by CodeRabbit

  • Chores
    • Updated the base container image and several underlying components to newer versions.

…ner OSS vuln SLA failures

Ports the fixes from the release-src/compute-plane-services/nvca/v3.2
backport line (#2118, #2129) forward to main.

govulncheck identified google.golang.org/grpc@v1.79.3 as the only
code-reachable vulnerable dependency:

- GO-2026-6348: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame
  Fragmentation
- GO-2026-6061: xDS RBAC authorization engine and HTTP/2 transport
  server vulnerabilities

Bumped to google.golang.org/grpc@v1.83.1 (fixes both). govulncheck now
reports 0 code-reachable vulnerabilities for cmd/nvca.

Also bumped the shared distroless_go base image pin in the root
MODULE.bazel v4.1.2 -> v4.1.4 (latest, same family; already fairly
current on main, so the diff is small). This picks up newer libc6,
libssl3t64/openssl-provider-fips, and tzdata patch versions, which
appear to resolve nSpect's raw-NVD container-oss-vulns-out-of-sla
false positives on the base OS layer, per the same investigation done
on the v3.2 backport line. Note this pin is shared by all Go services
on main, not just nvca.

vendor/ and BUILD.bazel regenerated via `go mod vendor` (this vendor
tree isn't gazelle-scoped cleanly from this environment, so BUILD.bazel
gaps were fixed by hand, iteratively validated against `bazel build`).
Verified with `bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator}`,
which succeeds cleanly with no missing-dependency errors.

Closes NO-REF
@apartha-nv
apartha-nv requested review from a team as code owners September 29, 2026 13:00
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

We couldn't safely recover the incremental review. No full review was started, and the last reviewed checkpoint was preserved. Retry later, or explicitly request a full review by commenting @coderabbitai full review.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉


📝 Walkthrough

Walkthrough

The pull request updates the pinned distroless Go image digest and indirect dependencies in the NVCA Go module.

Changes

Container image pin

Layer / File(s) Summary
Update distroless Go image digest
MODULE.bazel
The distroless_go image digest changes. Its image name and amd64/arm64 platform configuration remain unchanged.

NVCA Go dependencies

Layer / File(s) Summary
Update indirect Go dependencies
src/compute-plane-services/nvca/go.mod
The indirect cel.dev/expr dependency changes to v0.25.2. The Google genproto API and RPC dependencies change to the May 2026 revision, and indirect gRPC changes to v1.83.1.

Priority: ⬆️ High

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to d843d

No actionable risk from these updates is established; the PR is mergeable after normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title follows Conventional Commits syntax with the scoped type fix(nvca):. It accurately describes the dependency and base-image updates that remediate vulnerability SLA failures.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@sbaum1994
sbaum1994 enabled auto-merge October 2, 2026 15:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants