diff --git a/Dockerfile.caddy b/Dockerfile.caddy index 6f1b656..e1b1156 100644 --- a/Dockerfile.caddy +++ b/Dockerfile.caddy @@ -5,10 +5,17 @@ FROM golang:1.26.5-alpine3.23@sha256:622e56dbc11a8cfe87cafa2331e9a201877271cbff9 ENV CGO_ENABLED=0 ENV GOTOOLCHAIN=local -RUN GOBIN=/out go install \ - -trimpath \ - -ldflags="-s -w -X github.com/caddyserver/caddy/v2.CustomVersion=v2.11.4" \ - github.com/caddyserver/caddy/v2/cmd/caddy@v2.11.4 +WORKDIR /src + +RUN go mod init who-need-help/caddy-build \ + && go get github.com/caddyserver/caddy/v2/cmd/caddy@v2.11.4 \ + && go get google.golang.org/grpc@v1.82.1 \ + && test "$(go list -m -f '{{.Version}}' google.golang.org/grpc)" = "v1.82.1" \ + && go build \ + -trimpath \ + -ldflags="-s -w -X github.com/caddyserver/caddy/v2.CustomVersion=v2.11.4-wnh-grpc1.82.1" \ + -o /out/caddy \ + github.com/caddyserver/caddy/v2/cmd/caddy RUN mkdir -p /rootfs/data/caddy /rootfs/config/caddy /rootfs/tmp \ && chown -R 1000:1000 /rootfs diff --git a/README.md b/README.md index da87986..9d52724 100644 --- a/README.md +++ b/README.md @@ -110,8 +110,9 @@ Compose starts Traefik, PostGIS, Mailpit, a migration runner, 2 web replicas, and 2 Oban worker replicas. It waits for readiness and verifies a PubSub message broadcast from a different BEAM node. Registration emails appear in Mailpit. The Traefik image is reproducibly built from the checksum-pinned upstream -`v3.7.8` source with `grpc-go 1.82.1`, because the latest upstream binary still -contains `grpc-go 1.81.1` affected by +`v3.7.8` source with `grpc-go 1.82.1`. The Caddy edge is built from upstream +`v2.11.4` with the same dependency pin. Both latest upstream dependency graphs +still contain older `grpc-go` versions affected by [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf). Four deployment settings in the ignored environment select the runtime without diff --git a/scripts/quality.sh b/scripts/quality.sh index 65305ff..d472aff 100755 --- a/scripts/quality.sh +++ b/scripts/quality.sh @@ -66,6 +66,7 @@ docker run --rm \ echo "Checking Dockerfiles with Hadolint 2.14.0" for dockerfile in Dockerfile Dockerfile.backup Dockerfile.minio \ Dockerfile.postgis Dockerfile.socket-proxy Dockerfile.traefik \ + Dockerfile.caddy \ android/Dockerfile e2e/Dockerfile ops/external-boundaries/Dockerfile; do docker run --rm --interactive "$HADOLINT_IMAGE" \ hadolint --failure-threshold warning - <"$dockerfile"