Skip to content

fix: update all dependencies and base images (Alpine 3.24.2, distroless); require Go 1.26 - #2681

Merged
kgala2 merged 3 commits into
GoogleCloudPlatform:mainfrom
kgala2:deps/alpine-3.24.2
Sep 25, 2026
Merged

kgala2 merged 3 commits into
GoogleCloudPlatform:mainfrom
kgala2:deps/alpine-3.24.2

Conversation

@kgala2

@kgala2 kgala2 commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Important

⚠️ Building the proxy now requires Go 1.26

This PR raises the go directive in go.mod from 1.25.8 to 1.26.0. The updated golang.org/x/crypto (v0.57.0, which fixes GO-2026-6354 and GO-2026-6355), golang.org/x/net, cloud.google.com/go/* and gax-go all require Go 1.26.

  • Released binaries and container images are not affected. They are built with the golang:1 / golang:1-alpine images, which are already Go 1.27.
  • Building from source (go install github.com/GoogleCloudPlatform/cloud-sql-proxy/v2@latest) now requires Go 1.26 or later.
  • CI: GitHub workflows move from go-version: "1.25" to "1.26". v1-periodic.yaml is left at 1.25 because it builds the v1 branch.
  • Release notes: please call this out in the next release (v2.25.5).

Update all dependencies and container base images so that published proxy images have no fixable vulnerabilities.

Container base images

Dockerfile Base image Old digest New digest
Dockerfile.alpine alpine:3 79ff19e9… (Alpine 3.24.1, linux/amd64-only manifest) 294b683c… (Alpine 3.24.2, multi-arch index)
Dockerfile gcr.io/distroless/static:nonroot 23795be0… (linux/amd64-only manifest) e2e927ec… (multi-arch index)

Both old pins were single-platform (amd64) manifest digests, which is what ./build.sh deps writes. This PR switches both to the multi-arch image index digest, the same form Renovate uses (e.g. #2585). Renovate has not proposed these bumps itself because the "container images" group is rate-limited on the Dependency Dashboard (#437): prConcurrentLimit: 3 is used up by the stale PRs #2412, #2545 and #2679.

The Alpine bump fixes the following OpenSSL CVEs (libssl3/libcrypto3 3.5.7-r0 → 3.5.8-r0, per the Alpine secdb):

The proxy binary is static (CGO_ENABLED=0) and does not use OpenSSL, so it cannot reach these CVEs. Customer image scanners (e.g. JFrog Xray) still flag them as critical/high.

The Alpine bump also updates apk-tools/libapk 3.0.8, ca-certificates 20260909 and fuse-common 3.18.3.

Go modules

Updated with go get -u -t ./... followed by go mod tidy. Two modules are held back:

  • google.golang.org/genproto (monolith) stays at its current version. Upgrading it removes googleapis/devtools/cloudtrace/v2 and googleapis/monitoring/v3, which contrib.go.opencensus.io/exporter/stackdriver still imports, and the build breaks.
  • google.golang.org/grpc stays at v1.83.2 instead of v1.84.0. v1.84.0 is affected by GO-2026-6443 / CVE-2026-84445 (server panic via missing :authority). The fix is only in 1.82.2, 1.83.2 and an unreleased 1.85.0-dev. Staying on v1.83.2 also keeps google.golang.org/api at v0.298.0 instead of v0.299.0.
Module Old New
golang.org/x/crypto v0.55.0 v0.57.0 (fixes GO-2026-6354 and GO-2026-6355, i.e. CVE-2026-56855 and CVE-2026-78662)
golang.org/x/net v0.58.0 v0.59.0
golang.org/x/oauth2 v0.36.0 v0.37.0
golang.org/x/sync / sys / text / time v0.22 / v0.47 / v0.41 / v0.15 v0.23 / v0.48 / v0.42 / v0.16
google.golang.org/api v0.294.0 v0.298.0
google.golang.org/genproto/googleapis/{api,rpc} 2026-07/08 20260921155816
cloud.google.com/go/auth v0.23.2 v0.24.0
cloud.google.com/go/auth/oauth2adapt v0.2.8 v0.3.0
cloud.google.com/go/compute/metadata v0.9.0 v0.10.0
cloud.google.com/go/monitoring / trace / sql v1.30.0 / v1.16.0 / v0.1.0 v1.31.0 / v1.17.0 / v0.2.0
github.com/googleapis/gax-go/v2 v2.24.0 v2.26.0
github.com/googleapis/enterprise-certificate-proxy v0.3.20 v0.3.22
github.com/google/s2a-go v0.1.9 v0.1.10
github.com/jackc/pgx/v5 v5.10.0 v5.11.0
github.com/go-sql-driver/mysql v1.10.0 v1.10.1
github.com/microsoft/go-mssqldb v1.11.0 v1.11.2
go.opentelemetry.io/otel{,/metric,/trace} v1.44.0 v1.46.0
go.opentelemetry.io/contrib/.../otelgrpc, otelhttp v0.69.0 v0.71.0
github.com/prometheus/{client_model,common,procfs,statsd_exporter} v0.6.2 / v0.70.1 / v0.21.1 / v0.30.0 v0.6.3 / v0.71.0 / v0.22.0 / v0.31.0

cloud.google.com/go/cloudsqlconn stays at v1.25.2, which is its latest release.

Minimum Go version. The go directive moves from 1.25.8 to 1.26.0, because the updated cloud.google.com/go/*, gax-go, x/crypto and x/net modules now require Go 1.26. The GitHub workflows are updated from go-version: "1.25" to "1.26" to match. v1-periodic.yaml checks out the v1 branch, so it is left at 1.25.

Verification

  • go build ./... and go vet pass.
  • go test -short passes for cmd, internal/gcloud, internal/healthcheck and internal/proxy.
  • govulncheck ./...: 0 vulnerabilities affecting the code. Three remain in dependencies. None is called and none has a fix upstream:
    • GO-2026-5932 in x/crypto
    • GO-2022-0646 and GO-2022-0635 in aws-sdk-go v1.55.8
  • Trivy (--pkg-types os,library) results on images built locally from this branch:
Image OS OS package vulns Go binary vulns
Published 2.25.4-alpine Alpine 3.24.1 20 (10 OpenSSL CVEs × 2 pkgs) 3
This PR, Dockerfile.alpine Alpine 3.24.2 0 1 (GO-2026-5932, no fix available)
This PR, Dockerfile (distroless) Debian 13.7 0 1 (GO-2026-5932, no fix available)
  • In the Alpine image, apk list -u is empty: no package has a newer version available. All 22 installed packages have no unpatched entries in the Alpine 3.24 secdb.

A patch release (2.25.5) is needed to publish the fixed images.

@kgala2 kgala2 changed the title deps: update alpine:3 Docker digest to 294b683 (Alpine 3.24.2) deps: update all dependencies and container base images (Alpine 3.24.2, distroless) Sep 24, 2026
@kgala2 kgala2 changed the title deps: update all dependencies and container base images (Alpine 3.24.2, distroless) deps: update all dependencies and base images (Alpine 3.24.2, distroless); require Go 1.26 Sep 24, 2026
@kgala2
kgala2 marked this pull request as ready for review September 24, 2026 21:45
@kgala2
kgala2 requested a review from a team as a code owner September 24, 2026 21:45
@kgala2
kgala2 requested a review from hessjcg September 24, 2026 21:45
@kgala2

kgala2 commented Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

/gcbrun

panavenue
panavenue previously approved these changes Sep 25, 2026
- alpine:3 -> 294b683 (Alpine 3.24.2, OpenSSL 3.5.8-r0), multi-arch index digest
- gcr.io/distroless/static:nonroot -> e2e927e, multi-arch index digest
- go get -u -t ./... (genproto monolith held; grpc held at v1.83.2 to avoid GO-2026-6443 in v1.84.0)
- x/crypto v0.57.0 fixes GO-2026-6354, GO-2026-6355
- go directive 1.26.0 (required by updated deps); CI go-version 1.26
@kgala2 kgala2 changed the title deps: update all dependencies and base images (Alpine 3.24.2, distroless); require Go 1.26 fix: update all dependencies and base images (Alpine 3.24.2, distroless); require Go 1.26 Sep 25, 2026
- tests.yaml: replace 'permissions: read-all' with 'contents: read'
- govulncheck.yaml: correct the version comment on the pinned govulncheck-action SHA (v1.0.4)
@kgala2
kgala2 merged commit 85d63dd into GoogleCloudPlatform:main Sep 25, 2026
19 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants