Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
40 changes: 40 additions & 0 deletions .github/workflows/sbom.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
name: SBOM & Vulnerability Scan

on:
push:
branches: ["release/*"]
pull_request:
branches: ["release/*"]
workflow_dispatch:

jobs:
sbom:
name: Generate SBOM and scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: Build image
run: |
docker build -t minio:marketplace -f Dockerfile.marketplace .

- name: Generate SBOM (Syft)
uses: anchore/sbom-action@v0
with:
image: minio:marketplace
format: cyclonedx-json
output-file: sbom.cdx.json

- name: Scan vulnerabilities (Grype)
uses: anchore/scan-action@v6
with:
image: minio:marketplace
fail-build: false
output-format: table

- name: Upload SBOM
uses: actions/upload-artifact@v4
with:
name: sbom-minio
path: sbom.cdx.json
retention-days: 90
File renamed without changes.
File renamed without changes.
37 changes: 37 additions & 0 deletions Dockerfile.marketplace
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
FROM golang:1.25.9-alpine AS build

ARG RELEASE_VERSION=2025-10-15T17-29-55Z
ARG COMMIT_ID=9e49d5e7a648f00e26f2246f4dc28e6b07f8c84a
ARG SHORT_COMMIT_ID=9e49d5e7a648

ENV CGO_ENABLED=0 \
GOTOOLCHAIN=local \
MINIO_RELEASE=RELEASE

WORKDIR /src
COPY . .

RUN set -eux; \
ldflags="-s -w"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.Version=${RELEASE_VERSION}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.CopyrightYear=2025"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.ReleaseTag=RELEASE.${RELEASE_VERSION}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.CommitID=${COMMIT_ID}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.ShortCommitID=${SHORT_COMMIT_ID}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.GOPATH=/go"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.GOROOT=/usr/local/go"; \
GOOS=linux GOARCH=amd64 go build -tags kqueue -trimpath --ldflags "${ldflags}" -o /out/minio .

FROM alpine:3.23

RUN apk add --no-cache ca-certificates && \
chmod -R 777 /usr/bin

COPY --from=build /out/minio /usr/bin/minio
COPY dockerscripts/docker-entrypoint.sh /usr/bin/docker-entrypoint.sh

EXPOSE 9000
VOLUME ["/data"]

ENTRYPOINT ["/usr/bin/docker-entrypoint.sh"]
CMD ["minio"]
2 changes: 1 addition & 1 deletion go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ module github.com/minio/minio

go 1.24.0

toolchain go1.24.8
toolchain go1.25.9

// Install tools using 'go install tool'.
tool (
Expand Down
Loading