Skip to content

Security/trivy go runtime remediation - #90

Merged
imgk merged 7 commits into
imgk:mainfrom
upbeat-backbone-bose:security/trivy-go-runtime-remediation
Aug 7, 2026
Merged

imgk merged 7 commits into
imgk:mainfrom
upbeat-backbone-bose:security/trivy-go-runtime-remediation

Conversation

@upbeat-backbone-bose

Copy link
Copy Markdown
Contributor

Summary

Upgrade the project and Docker build toolchain to Go 1.25.12 to address Go standard library vulnerabilities detected by Trivy in the Caddy binary.

This change eliminates all HIGH and CRITICAL findings while continuing to use the official Caddy v2.11.4 release.

Changes

  • Upgrade the Go version in go.mod from 1.25.1 to 1.25.12
  • Upgrade the Docker builder image from golang:1.25.1-alpine to golang:1.25.12-alpine
  • GitHub Actions automatically uses Go 1.25.12 through go-version-file: go.mod
  • Keep the official Caddy v2.11.4 release
  • Keep cel-go v0.28.1 to avoid API incompatibility with Caddy v2.11.4

Security Impact

Trivy findings before the upgrade:

Severity Count
━━━━━━━━━━ ━━━━━━━
CRITICAL 1
────────── ───────
HIGH 14
────────── ───────
MEDIUM 22
────────── ───────
LOW 2
────────── ───────
UNKNOWN 1

Trivy findings after the upgrade:

Severity Count
━━━━━━━━━━ ━━━━━━━
CRITICAL 0
────────── ───────
HIGH 0
────────── ───────
MEDIUM 1
────────── ───────
LOW 0
────────── ───────
UNKNOWN 1

This upgrade removes all HIGH and CRITICAL Go standard library vulnerabilities.

Validation

Go Tests

go test ./...
go mod verify
govulncheck ./...

Results:

  • All Go tests pass
  • Go module verification passes
  • govulncheck reports 0 reachable vulnerabilities

Docker Build

docker build \
  --pull \
  --no-cache \
  --progress=plain \
  -t caddy-trojan:go-1.25.12-test \
  .

The image builds successfully with Caddy:

v2.11.4

### Module Validation

docker run --rm caddy-trojan:go-1.25.12-test \
  caddy list-modules | grep -E 'trojan|dns.providers.dnspod'

The following modules were confirmed to load successfully:

- admin.api.trojan
- caddy.listeners.trojan
- http.handlers.trojan
- trojan.proxy.*
- trojan.upstream.*
- dns.providers.dnspod

### Trivy Scan

trivy image \
  --scanners vuln \
  --severity HIGH,CRITICAL \
  --exit-code 1 \
  caddy-trojan:go-1.25.12-test

Results:

Alpine vulnerabilities: 0
Go binary vulnerabilities: 0

## Remaining Findings

A full-severity scan still reports two non-blocking findings.

### github.com/google/cel-go — MEDIUM

- Installed version: v0.28.1
- Fixed version: v0.29.0
- Caddy v2.11.4 depends on the older CEL API
- Forcing the upgrade causes Caddy compilation failures
- Resolution requires a future official Caddy release with an updated cel-go dependency

### golang.org/x/crypto/openpgp — UNKNOWN

- The openpgp package is unmaintained and has no fixed version
- govulncheck confirms that the vulnerable code is not reachable
- Trivy reports it based on Go binary module metadata

## Compatibility

- No application logic changes
- No Caddy version changes
- No public API changes
- No new direct dependencies
- Only the Go patch version is upgraded, resulting in low compatibility risk

## Checklist

- [x] Go toolchain upgraded to 1.25.12
- [x] Docker builder upgraded to 1.25.12
- [x] go test ./... passes
- [x] go mod verify passes
- [x] govulncheck reports no reachable vulnerabilities
- [x] Docker image builds successfully
- [x] Trojan and DNSPod modules load successfully
- [x] Trivy reports 0 HIGH vulnerabilities
- [x] Trivy reports 0 CRITICAL vulnerabilities

@imgk
imgk merged commit cd23e39 into imgk:main Aug 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants