Skip to content

fix(marketplace): report our own commit and ship the licence files - #5

Merged
Kim-YeongHyeon merged 4 commits into
mainfrom
fix/marketplace-agpl-source-attribution
Sep 15, 2026
Merged

Kim-YeongHyeon merged 4 commits into
mainfrom
fix/marketplace-agpl-source-attribution

Conversation

@Kim-YeongHyeon

@Kim-YeongHyeon Kim-YeongHyeon commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

문제

발행된 이미지가 자기 소스를 잘못 가리킵니다.

$ docker run --rm cryptolabinc/minio:2025-10-15-go1.25.9 minio --version
minio version RELEASE.2025-10-15T17-29-55Z (commit-id=9e49d5e7a648...)

9e49d5e7은 업스트림 minio/minio 커밋입니다. 실제 빌드 트리는 이 포크이고 업스트림보다 앞서 있습니다. 이미지 안에도 OCI 라벨과 LICENSE/CREDITS가 없어, 받은 사람이 가진 유일한 포인터가 대응하지 않는 트리를 가리킵니다 (AGPL-3.0 §6).

원인

Dockerfile.marketplace가 업스트림 커밋을 기본값으로 들고 있었습니다.

ARG COMMIT_ID=9e49d5e7a648f00e26f2246f4dc28e6b07f8c84a
ARG SHORT_COMMIT_ID=9e49d5e7a648

기본값이라 아무도 넘기지 않아도 빌드가 성공하고, 커밋이 쌓여도 값은 그대로 남습니다.

채택한 해결 방안

  1. 위 두 인자를 기본값 없는 SOURCE_COMMIT 하나로 대체. 짧은 해시는 여기서 파생하고, 값이 비면 빌드가 실패합니다.

  2. LICENSE, CREDITS를 Dockerfile.release와 같은 /licenses/ 경로로 포함.

  3. 소스 레포·리비전·라이선스를 OCI 라벨로 명시.

  4. sbom.yml이 유일한 호출부라 build-arg를 넘기도록 수정. PR 트리거에서는 github.sha가 조회 불가능한 merge 커밋이라 pull_request.head.sha를 우선합니다. 기본 브랜치가 main이 되면서 트리거에 main도 추가했습니다.

  5. openssl 업그레이드가 실제로 일어나게 수정. alpine:3.23이 libcrypto3/libssl3 3.5.7-r0을 미리 깔고 나오는데, 기존 >=3.5.7-r0 핀을 그게 이미 만족시켜서 apk가 아무것도 하지 않았습니다. 그 결과 3.5.8-r0이 고치는 Critical 4건을 그대로 싣고 있었습니다. --upgrade로 올리고, 하한선은 남겨 미러가 낡았을 때 조용히 넘어가지 않고 빌드가 실패하게 했습니다.

이 PR은 Dockerfile만 고칩니다. 이미 발행된 이미지는 재빌드·재push해야 반영됩니다.

The image reported commit-id 9e49d5e, the upstream release it derives
from, while the binary was built from this fork. Anyone following that
pointer to the corresponding source landed on a tree that is not the one
they were given. SOURCE_COMMIT replaces the hardcoded pair and has no
default, so a build that cannot say which commit it came from fails
instead of repeating the wrong answer.

The runtime stage carried no labels and no licence text either. LICENSE
and CREDITS now ship at the same paths Dockerfile.release uses, and OCI
labels name the source repository, revision and licence.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UhANRtjScVEw6pGs3uGaGC
@Kim-YeongHyeon Kim-YeongHyeon self-assigned this Sep 15, 2026
@Kim-YeongHyeon

Copy link
Copy Markdown
Contributor Author

리뷰어가 직접 봐야 하는 항목입니다. 판단은 하지 않았습니다.

1. 계획 항목 중 diff에 대응하는 변경이 없는 것

  • 이미 발행된 cryptolabinc/minio:2025-10-15-go1.25.9 이미지 자체. 이 PR은 Dockerfile만 고치고 재발행은 하지 않습니다.
  • 실제 push 파이프라인. 이 레포에 없어서 손대지 못했습니다 — 그쪽이 --build-arg SOURCE_COMMIT= 없이 docker build -f Dockerfile.marketplace .를 호출한다면 이 PR 이후 빌드가 실패합니다(조용히 틀린 값을 박는 것보다는 낫다고 판단했으나, 확인이 필요합니다).

2. 계획이나 PR 본문에 언급되지 않은 변경 파일

  • 없습니다. 변경은 Dockerfile.marketplace, .github/workflows/sbom.yml 둘뿐입니다 (27줄).

3. 변경된 공개 인터페이스 (빌드 인자)

변경
COMMIT_ID 제거
SHORT_COMMIT_ID 제거 (이제 SOURCE_COMMIT에서 파생)
SOURCE_COMMIT 신규, 필수, 기본값 없음

RELEASE_VERSION, TARGETARCH는 그대로입니다. 레포 전체 grep 결과 COMMIT_ID / SHORT_COMMIT_ID를 이름으로 참조하는 다른 곳은 없습니다.

추가로 확인이 필요한 것

이미지에 들어가는 CREDITS가 1.8MB입니다. Dockerfile.release가 이미 같은 파일을 같은 크기로 넣고 있어 전례는 있으나, marketplace 이미지 크기에 민감하다면 따져볼 지점입니다 (최종 123MB).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UhANRtjScVEw6pGs3uGaGC
@Kim-YeongHyeon
Kim-YeongHyeon changed the base branch from release/2025-10-15-go1.25.9 to main September 15, 2026 04:34
main is the default branch now, so a PR against it matched no trigger.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UhANRtjScVEw6pGs3uGaGC
@Kim-YeongHyeon
Kim-YeongHyeon force-pushed the fix/marketplace-agpl-source-attribution branch from 3372868 to 573c099 Compare September 15, 2026 04:42
@Kim-YeongHyeon
Kim-YeongHyeon marked this pull request as ready for review September 15, 2026 04:42
alpine:3.23 preinstalls libcrypto3/libssl3 3.5.7-r0, which already
satisfies ">=3.5.7-r0", so apk did nothing and the image shipped the
version 3.5.8-r0 fixes. --upgrade makes the upgrade happen; the floor
stays so a stale mirror fails the build rather than shipping quietly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UhANRtjScVEw6pGs3uGaGC
@Kim-YeongHyeon
Kim-YeongHyeon merged commit 3b08cb7 into main Sep 15, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant