From 702b58caf2892e28988b23e106bb965828723f9a Mon Sep 17 00:00:00 2001 From: inkme9 Date: Tue, 14 Apr 2026 03:58:19 +0000 Subject: [PATCH] chore(marketplace): build minio with fixed go toolchain --- ...psreview.yaml => depsreview.yaml.disabled} | 0 .../{go-cross.yml => go-cross.yml.disabled} | 0 ...go-healing.yml => go-healing.yml.disabled} | 0 .../{go-lint.yml => go-lint.yml.disabled} | 0 ...iliency.yml => go-resiliency.yml.disabled} | 0 .github/workflows/{go.yml => go.yml.disabled} | 0 .../{helm-lint.yml => helm-lint.yml.disabled} | 0 ...ns.yaml => iam-integrations.yaml.disabled} | 0 .../{issues.yaml => issues.yaml.disabled} | 0 .../workflows/{lock.yml => lock.yml.disabled} | 0 .../workflows/{mint.yml => mint.yml.disabled} | 0 ...ication.yaml => replication.yaml.disabled} | 0 ...-disable.yml => root-disable.yml.disabled} | 0 .github/workflows/sbom.yml | 40 +++++++++++++++++++ .../{shfmt.yml => shfmt.yml.disabled} | 0 .../{typos.yml => typos.yml.disabled} | 0 ...ci-cd.yaml => upgrade-ci-cd.yaml.disabled} | 0 .../{vulncheck.yml => vulncheck.yml.disabled} | 0 Dockerfile.marketplace | 37 +++++++++++++++++ go.mod | 2 +- 20 files changed, 78 insertions(+), 1 deletion(-) rename .github/workflows/{depsreview.yaml => depsreview.yaml.disabled} (100%) rename .github/workflows/{go-cross.yml => go-cross.yml.disabled} (100%) rename .github/workflows/{go-healing.yml => go-healing.yml.disabled} (100%) rename .github/workflows/{go-lint.yml => go-lint.yml.disabled} (100%) rename .github/workflows/{go-resiliency.yml => go-resiliency.yml.disabled} (100%) rename .github/workflows/{go.yml => go.yml.disabled} (100%) rename .github/workflows/{helm-lint.yml => helm-lint.yml.disabled} (100%) rename .github/workflows/{iam-integrations.yaml => iam-integrations.yaml.disabled} (100%) rename .github/workflows/{issues.yaml => issues.yaml.disabled} (100%) rename .github/workflows/{lock.yml => lock.yml.disabled} (100%) rename .github/workflows/{mint.yml => mint.yml.disabled} (100%) rename .github/workflows/{replication.yaml => replication.yaml.disabled} (100%) rename .github/workflows/{root-disable.yml => root-disable.yml.disabled} (100%) create mode 100644 .github/workflows/sbom.yml rename .github/workflows/{shfmt.yml => shfmt.yml.disabled} (100%) rename .github/workflows/{typos.yml => typos.yml.disabled} (100%) rename .github/workflows/{upgrade-ci-cd.yaml => upgrade-ci-cd.yaml.disabled} (100%) rename .github/workflows/{vulncheck.yml => vulncheck.yml.disabled} (100%) create mode 100644 Dockerfile.marketplace diff --git a/.github/workflows/depsreview.yaml b/.github/workflows/depsreview.yaml.disabled similarity index 100% rename from .github/workflows/depsreview.yaml rename to .github/workflows/depsreview.yaml.disabled diff --git a/.github/workflows/go-cross.yml b/.github/workflows/go-cross.yml.disabled similarity index 100% rename from .github/workflows/go-cross.yml rename to .github/workflows/go-cross.yml.disabled diff --git a/.github/workflows/go-healing.yml b/.github/workflows/go-healing.yml.disabled similarity index 100% rename from .github/workflows/go-healing.yml rename to .github/workflows/go-healing.yml.disabled diff --git a/.github/workflows/go-lint.yml b/.github/workflows/go-lint.yml.disabled similarity index 100% rename from .github/workflows/go-lint.yml rename to .github/workflows/go-lint.yml.disabled diff --git a/.github/workflows/go-resiliency.yml b/.github/workflows/go-resiliency.yml.disabled similarity index 100% rename from .github/workflows/go-resiliency.yml rename to .github/workflows/go-resiliency.yml.disabled diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml.disabled similarity index 100% rename from .github/workflows/go.yml rename to .github/workflows/go.yml.disabled diff --git a/.github/workflows/helm-lint.yml b/.github/workflows/helm-lint.yml.disabled similarity index 100% rename from .github/workflows/helm-lint.yml rename to .github/workflows/helm-lint.yml.disabled diff --git a/.github/workflows/iam-integrations.yaml b/.github/workflows/iam-integrations.yaml.disabled similarity index 100% rename from .github/workflows/iam-integrations.yaml rename to .github/workflows/iam-integrations.yaml.disabled diff --git a/.github/workflows/issues.yaml b/.github/workflows/issues.yaml.disabled similarity index 100% rename from .github/workflows/issues.yaml rename to .github/workflows/issues.yaml.disabled diff --git a/.github/workflows/lock.yml b/.github/workflows/lock.yml.disabled similarity index 100% rename from .github/workflows/lock.yml rename to .github/workflows/lock.yml.disabled diff --git a/.github/workflows/mint.yml b/.github/workflows/mint.yml.disabled similarity index 100% rename from .github/workflows/mint.yml rename to .github/workflows/mint.yml.disabled diff --git a/.github/workflows/replication.yaml b/.github/workflows/replication.yaml.disabled similarity index 100% rename from .github/workflows/replication.yaml rename to .github/workflows/replication.yaml.disabled diff --git a/.github/workflows/root-disable.yml b/.github/workflows/root-disable.yml.disabled similarity index 100% rename from .github/workflows/root-disable.yml rename to .github/workflows/root-disable.yml.disabled diff --git a/.github/workflows/sbom.yml b/.github/workflows/sbom.yml new file mode 100644 index 000000000..85102dda7 --- /dev/null +++ b/.github/workflows/sbom.yml @@ -0,0 +1,40 @@ +name: SBOM & Vulnerability Scan + +on: + push: + branches: ["release/*"] + pull_request: + branches: ["release/*"] + workflow_dispatch: + +jobs: + sbom: + name: Generate SBOM and scan + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - name: Build image + run: | + docker build -t minio:marketplace -f Dockerfile.marketplace . + + - name: Generate SBOM (Syft) + uses: anchore/sbom-action@v0 + with: + image: minio:marketplace + format: cyclonedx-json + output-file: sbom.cdx.json + + - name: Scan vulnerabilities (Grype) + uses: anchore/scan-action@v6 + with: + image: minio:marketplace + fail-build: false + output-format: table + + - name: Upload SBOM + uses: actions/upload-artifact@v4 + with: + name: sbom-minio + path: sbom.cdx.json + retention-days: 90 diff --git a/.github/workflows/shfmt.yml b/.github/workflows/shfmt.yml.disabled similarity index 100% rename from .github/workflows/shfmt.yml rename to .github/workflows/shfmt.yml.disabled diff --git a/.github/workflows/typos.yml b/.github/workflows/typos.yml.disabled similarity index 100% rename from .github/workflows/typos.yml rename to .github/workflows/typos.yml.disabled diff --git a/.github/workflows/upgrade-ci-cd.yaml b/.github/workflows/upgrade-ci-cd.yaml.disabled similarity index 100% rename from .github/workflows/upgrade-ci-cd.yaml rename to .github/workflows/upgrade-ci-cd.yaml.disabled diff --git a/.github/workflows/vulncheck.yml b/.github/workflows/vulncheck.yml.disabled similarity index 100% rename from .github/workflows/vulncheck.yml rename to .github/workflows/vulncheck.yml.disabled diff --git a/Dockerfile.marketplace b/Dockerfile.marketplace new file mode 100644 index 000000000..aa4c24f13 --- /dev/null +++ b/Dockerfile.marketplace @@ -0,0 +1,37 @@ +FROM golang:1.25.9-alpine AS build + +ARG RELEASE_VERSION=2025-10-15T17-29-55Z +ARG COMMIT_ID=9e49d5e7a648f00e26f2246f4dc28e6b07f8c84a +ARG SHORT_COMMIT_ID=9e49d5e7a648 + +ENV CGO_ENABLED=0 \ + GOTOOLCHAIN=local \ + MINIO_RELEASE=RELEASE + +WORKDIR /src +COPY . . + +RUN set -eux; \ + ldflags="-s -w"; \ + ldflags="${ldflags} -X github.com/minio/minio/cmd.Version=${RELEASE_VERSION}"; \ + ldflags="${ldflags} -X github.com/minio/minio/cmd.CopyrightYear=2025"; \ + ldflags="${ldflags} -X github.com/minio/minio/cmd.ReleaseTag=RELEASE.${RELEASE_VERSION}"; \ + ldflags="${ldflags} -X github.com/minio/minio/cmd.CommitID=${COMMIT_ID}"; \ + ldflags="${ldflags} -X github.com/minio/minio/cmd.ShortCommitID=${SHORT_COMMIT_ID}"; \ + ldflags="${ldflags} -X github.com/minio/minio/cmd.GOPATH=/go"; \ + ldflags="${ldflags} -X github.com/minio/minio/cmd.GOROOT=/usr/local/go"; \ + GOOS=linux GOARCH=amd64 go build -tags kqueue -trimpath --ldflags "${ldflags}" -o /out/minio . + +FROM alpine:3.23 + +RUN apk add --no-cache ca-certificates && \ + chmod -R 777 /usr/bin + +COPY --from=build /out/minio /usr/bin/minio +COPY dockerscripts/docker-entrypoint.sh /usr/bin/docker-entrypoint.sh + +EXPOSE 9000 +VOLUME ["/data"] + +ENTRYPOINT ["/usr/bin/docker-entrypoint.sh"] +CMD ["minio"] diff --git a/go.mod b/go.mod index a95708523..2c224f019 100644 --- a/go.mod +++ b/go.mod @@ -2,7 +2,7 @@ module github.com/minio/minio go 1.24.0 -toolchain go1.24.8 +toolchain go1.25.9 // Install tools using 'go install tool'. tool (