Skip to content

Float the base images and update packages at build time (release-2.12) - #2

Merged
aaaaaaaalex merged 4 commits into
release-2.12from
cve/image-build-hardening-2.12
Sep 30, 2026
Merged

aaaaaaaalex merged 4 commits into
release-2.12from
cve/image-build-hardening-2.12

Conversation

@aaaaaaaalex

@aaaaaaaalex aaaaaaaalex commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

📝 Links

📝 Description

The same image remediation as #1, for the release-2.12 line, which builds the plugin for OpenShift consoles up to 4.21. Landing it here means release branches cut from release-2.12 pick it up.

  • Bases move to maintained images. Neither base on this branch is rebuilt any more: nodejs-18 was last built in June 2025 and nginx-122 in January. The builder moves to ubi9/nodejs-22:latest and the web server to ubi9/nginx-126:latest. nodejs-18 also cannot install this branch's lockfile, which needs node 20 or later, so the branch did not build before this change.
  • Runtime packages are updated at build time, with /var/log/nginx ownership re-applied afterwards: updating nginx resets it to root:root 0711, and without restoring it the container crash-loops as uid 1001.
  • The update re-runs on every build, via BUILD_DATE declared ahead of it, rather than being served from the build cache.
  • Non-breaking dependency security fixes (npm audit fix). Shipped dependencies go from 1 high + 7 moderate to 5 moderate. The remaining five are only fixed by console SDK 4.22 or react-router 7, both of which need React 18, and consoles up to 4.21 provide React 17 — so they cannot be fixed on this line.

Only build/Containerfile and package-lock.json change.

🎥 Demo

Built and run locally with VERSION=2.12.0:

  • Runs as uid 1001 with no restarts; /var/log/nginx owned by 1001:0; RHEL 9.8, nginx 1.26.3; plugin-manifest.json served (HTTP 200).
  • Entry script keeps the ≤4.21 loader, with the ID matching the manifest version: loadPluginEntry("forklift-console-plugin@2.12.0", …).
  • No package updates pending in the built image.

Not yet loaded in a live 4.21 console.

📝 CC://

🤖 Generated with Claude Code

aaaaaaaalex and others added 4 commits September 28, 2026 12:52
Neither base is rebuilt any more: nodejs 18 was last built in June 2025
and nginx 1.22 in January, so floating them would gain nothing. Move to
the nodejs 22 and nginx 1.26 images. nodejs 18 also cannot install this
branch's lockfile, which needs node 20 or later.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>
A floating base only helps once the registry rebuilds it; updating at
build time also picks up errata released since. The update reverts
/var/log/nginx to the nginx package's root:root ownership, so the base
image's chown is re-applied before dropping back to uid 1001.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>
The update layer was served from the build cache whenever the base image
was unchanged, so the image could ship updates days old. Declaring
BUILD_DATE ahead of the update makes it re-run when the build passes a
new value.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

BUILD_DATE does not invalidate the update layer, allowing stale runtime packages to remain cached.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates release-2.12 container bases, runtime packages, and npm dependencies.

Changes:

  • Moves build and runtime images to maintained UBI versions.
  • Adds runtime package updates and restores nginx log permissions.
  • Refreshes audited dependency versions.
File Summary
package-lock.json Applies dependency security updates.
build/​Containerfile Updates base images and runtime package handling.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread build/Containerfile
Comment on lines +27 to +29
ARG BUILD_DATE=unknown
RUN dnf -y update && \
dnf -y clean all
@aaaaaaaalex
aaaaaaaalex merged commit ec8f24a into release-2.12 Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants