Repository navigation
fix(runtime): update shared Go and Rust security dependencies - #2231
Conversation
Rebuild Bazel Go consumers with the patched standard library. Update the central toolchain, matching workspace declaration, and generated SDK checksums. Dependency: Go 1.26.5 -> 1.26.8 (BSD-3-Clause). Relates to #2230 Signed-off-by: Stephanie Baum <sbaum@nvidia.com>
Use the same immutable multi-architecture runtime in Bazel and Stargate. Verified libc6 2.41-12+deb13u4 in both amd64 and arm64 base manifests. Dependency: NVIDIA distroless cc v4.1.2 -> v4.1.4. Relates to #2230 Signed-off-by: Stephanie Baum <sbaum@nvidia.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: NVIDIA/nvcf/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 10 remain after this review. 📝 WalkthroughWalkthroughThe pull request updates a pinned distroless image digest, changes the Stargate runtime base image, and updates Go version declarations. ChangesRuntime image pins
Go version declarations
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to No actionable merge-blocking defect is established. Confirm the pinned image contents and complete the reported image validation and security scans before release. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 golangci-lint (2.13.2)level=error msg="Running error: context loading failed: no go files to analyze: running Comment |
|
🎉 This PR is included in src/libraries/rust/stargate/v0.19.9 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
|
This PR is included in version 1.29.2. The release is available on GitHub release. |
|
This PR is included in version 1.69.1. The release is available on GitHub release. |
|
This PR is included in version 1.25.1. The release is available on GitHub release. |
|
This PR is included in version 1.14.2. The release is available on GitHub release. |
|
This PR is included in version 1.10.1. The release is available on GitHub release. |
|
This PR is included in version 0.5.1. The release is available on GitHub release. |
|
This PR is included in version 0.9.1. The release is available on GitHub release. |
TL;DR
Refresh the shared Go toolchain and Rust runtime base so rebuilt service images receive the patched Go standard library and glibc. Go moves from 1.26.5 to 1.26.8. NVIDIA distroless cc moves from v4.1.2 to v4.1.4, with the same immutable multi-architecture digest in Bazel and Stargate's Dockerfile.
Additional Details
The central toolchain file and matching
go.work.bazeldeclaration move together.MODULE.bazel.lockwas regenerated by Bazel. The Go change affects all consumers of the root SDK, and the cc change affects consumers of the shared Rust base, including function-autoscaler and http-invocation. Stargate's Dockerfile publishing path is updated explicitly.Package metadata extracted from the runtime layers confirms libc6 changes from
2.41-12+deb13u3to2.41-12+deb13u4on the inspected current/candidate amd64 images. The candidate arm64 image also contains2.41-12+deb13u4.This is the dependency stage of #2230. Every affected producer still needs a verified published image before chart image pins change. Shared root changes do not automatically trigger all path-scoped semantic releases. Chart updates follow image publication; stack pins follow chart publication. No future version is assumed here.
The commits separate the Go and libc updates for later maintenance backports. Record the final merge commit as well; regenerate the Bazel lock on each maintenance branch instead of copying unrelated main dependencies. The 1.0.x delivery must repeat the image -> chart -> stack sequence using its retained service trains.
For the Reviewer
Review the central SDK declaration, generated lock changes, and agreement between the Bazel and Dockerfile runtime digests. #2161 separately updates NVCA gRPC and distroless/go; this PR preserves that work's scope. #1952 and #2019 are downstream chart/stack bump PRs to reconcile after patched images exist.
Dependency licenses: Go remains BSD-3-Clause. The runtime is a patch update of the existing base, with its existing package attributions. No new vendored source or repository NOTICE paths are introduced.
For QA
tools/ci/check-go-versionandgit diff --check.TestStop_noWaitForSplaywall-clock assertion failed during the concurrent build; its test target then passed all three isolated reruns.bazel test //...; it stopped on the byoo-otel-collector genrule's missing host Go prerequisite, before completing the full suite. The collector's separate host-toolchain contract is unchanged.Linux image build/startup validation and replacement security scans are still required before consuming the new releases. This pin-only change adds no implementation tests; existing service suites and artifact checks validate it.
Issues
Relates to #2230
References: Go release history, Debian glibc fix.
Summary by CodeRabbit