From b4f3ca0434679040d0c44e2c05e0714ca912eee5 Mon Sep 17 00:00:00 2001 From: Kim-YeongHyeon <107521762+Kim-YeongHyeon@users.noreply.github.com> Date: Tue, 15 Sep 2026 12:32:29 +0900 Subject: [PATCH 1/4] fix(marketplace): report our own commit and ship the licence files The image reported commit-id 9e49d5e7, the upstream release it derives from, while the binary was built from this fork. Anyone following that pointer to the corresponding source landed on a tree that is not the one they were given. SOURCE_COMMIT replaces the hardcoded pair and has no default, so a build that cannot say which commit it came from fails instead of repeating the wrong answer. The runtime stage carried no labels and no licence text either. LICENSE and CREDITS now ship at the same paths Dockerfile.release uses, and OCI labels name the source repository, revision and licence. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01UhANRtjScVEw6pGs3uGaGC --- .github/workflows/sbom.yml | 3 ++- Dockerfile.marketplace | 24 ++++++++++++++++++++---- 2 files changed, 22 insertions(+), 5 deletions(-) diff --git a/.github/workflows/sbom.yml b/.github/workflows/sbom.yml index 85102dda7..b84e5fb11 100644 --- a/.github/workflows/sbom.yml +++ b/.github/workflows/sbom.yml @@ -16,7 +16,8 @@ jobs: - name: Build image run: | - docker build -t minio:marketplace -f Dockerfile.marketplace . + docker build -t minio:marketplace -f Dockerfile.marketplace \ + --build-arg SOURCE_COMMIT="${{ github.event.pull_request.head.sha || github.sha }}" . - name: Generate SBOM (Syft) uses: anchore/sbom-action@v0 diff --git a/Dockerfile.marketplace b/Dockerfile.marketplace index 43fd25054..f5edb1a78 100644 --- a/Dockerfile.marketplace +++ b/Dockerfile.marketplace @@ -5,8 +5,10 @@ FROM --platform=$BUILDPLATFORM golang:1.26.5-alpine AS build ARG TARGETARCH ARG RELEASE_VERSION=2025-10-15T17-29-55Z -ARG COMMIT_ID=9e49d5e7a648f00e26f2246f4dc28e6b07f8c84a -ARG SHORT_COMMIT_ID=9e49d5e7a648 +# The commit this tree was built from. Required and deliberately without a +# default: a modified build whose reported commit points at upstream sends +# anyone looking for the corresponding source to a tree that is not this one. +ARG SOURCE_COMMIT ENV CGO_ENABLED=0 \ GOTOOLCHAIN=local \ @@ -16,12 +18,14 @@ WORKDIR /src COPY . . RUN set -eux; \ + test -n "${SOURCE_COMMIT}" || { echo "SOURCE_COMMIT build-arg is required"; exit 1; }; \ + short_commit=$(echo "${SOURCE_COMMIT}" | cut -c1-12); \ ldflags="-s -w"; \ ldflags="${ldflags} -X github.com/minio/minio/cmd.Version=${RELEASE_VERSION}"; \ ldflags="${ldflags} -X github.com/minio/minio/cmd.CopyrightYear=2025"; \ ldflags="${ldflags} -X github.com/minio/minio/cmd.ReleaseTag=RELEASE.${RELEASE_VERSION}"; \ - ldflags="${ldflags} -X github.com/minio/minio/cmd.CommitID=${COMMIT_ID}"; \ - ldflags="${ldflags} -X github.com/minio/minio/cmd.ShortCommitID=${SHORT_COMMIT_ID}"; \ + ldflags="${ldflags} -X github.com/minio/minio/cmd.CommitID=${SOURCE_COMMIT}"; \ + ldflags="${ldflags} -X github.com/minio/minio/cmd.ShortCommitID=${short_commit}"; \ ldflags="${ldflags} -X github.com/minio/minio/cmd.GOPATH=/go"; \ ldflags="${ldflags} -X github.com/minio/minio/cmd.GOROOT=/usr/local/go"; \ GOOS=linux GOARCH=${TARGETARCH} go build -tags kqueue -trimpath --ldflags "${ldflags}" -o /out/minio . @@ -37,6 +41,18 @@ RUN apk add --no-cache ca-certificates "libcrypto3>=3.5.7-r0" "libssl3>=3.5.7-r0 COPY --from=build /out/minio /usr/bin/minio COPY dockerscripts/docker-entrypoint.sh /usr/bin/docker-entrypoint.sh +# Same paths Dockerfile.release ships them at. +COPY LICENSE /licenses/LICENSE +COPY CREDITS /licenses/CREDITS + +# Last in the stage on purpose: an ARG invalidates the cache of everything +# after it, and the commit changes on every build. +ARG SOURCE_COMMIT +LABEL org.opencontainers.image.title="MinIO (CryptoLab build)" \ + org.opencontainers.image.description="MinIO built from CryptoLabInc/minio, a modified fork of minio/minio" \ + org.opencontainers.image.source="https://github.com/CryptoLabInc/minio" \ + org.opencontainers.image.revision="${SOURCE_COMMIT}" \ + org.opencontainers.image.licenses="AGPL-3.0-only" EXPOSE 9000 VOLUME ["/data"] From 9991f085abe1cce060423f303df054fcec56f78d Mon Sep 17 00:00:00 2001 From: Kim-YeongHyeon <107521762+Kim-YeongHyeon@users.noreply.github.com> Date: Tue, 15 Sep 2026 12:50:46 +0900 Subject: [PATCH 2/4] docs(marketplace): trim the SOURCE_COMMIT comment Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01UhANRtjScVEw6pGs3uGaGC --- Dockerfile.marketplace | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/Dockerfile.marketplace b/Dockerfile.marketplace index f5edb1a78..57e779e31 100644 --- a/Dockerfile.marketplace +++ b/Dockerfile.marketplace @@ -5,9 +5,7 @@ FROM --platform=$BUILDPLATFORM golang:1.26.5-alpine AS build ARG TARGETARCH ARG RELEASE_VERSION=2025-10-15T17-29-55Z -# The commit this tree was built from. Required and deliberately without a -# default: a modified build whose reported commit points at upstream sends -# anyone looking for the corresponding source to a tree that is not this one. +# No default on purpose: a build that cannot name its commit should fail. ARG SOURCE_COMMIT ENV CGO_ENABLED=0 \ From 573c099f3f8ea56302330a6d76e7b193a3436a17 Mon Sep 17 00:00:00 2001 From: Kim-YeongHyeon <107521762+Kim-YeongHyeon@users.noreply.github.com> Date: Tue, 15 Sep 2026 13:35:56 +0900 Subject: [PATCH 3/4] ci: run the SBOM scan on main main is the default branch now, so a PR against it matched no trigger. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01UhANRtjScVEw6pGs3uGaGC --- .github/workflows/sbom.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/sbom.yml b/.github/workflows/sbom.yml index b84e5fb11..9eef1a2b4 100644 --- a/.github/workflows/sbom.yml +++ b/.github/workflows/sbom.yml @@ -2,9 +2,9 @@ name: SBOM & Vulnerability Scan on: push: - branches: ["release/*"] + branches: ["main", "release/*"] pull_request: - branches: ["release/*"] + branches: ["main", "release/*"] workflow_dispatch: jobs: From 09b86f9768a02aba2c8d38a4f2c643fc14604452 Mon Sep 17 00:00:00 2001 From: Kim-YeongHyeon <107521762+Kim-YeongHyeon@users.noreply.github.com> Date: Tue, 15 Sep 2026 13:53:51 +0900 Subject: [PATCH 4/4] fix(marketplace): actually upgrade openssl instead of pinning a floor alpine:3.23 preinstalls libcrypto3/libssl3 3.5.7-r0, which already satisfies ">=3.5.7-r0", so apk did nothing and the image shipped the version 3.5.8-r0 fixes. --upgrade makes the upgrade happen; the floor stays so a stale mirror fails the build rather than shipping quietly. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01UhANRtjScVEw6pGs3uGaGC --- Dockerfile.marketplace | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/Dockerfile.marketplace b/Dockerfile.marketplace index 57e779e31..c24d09e85 100644 --- a/Dockerfile.marketplace +++ b/Dockerfile.marketplace @@ -30,11 +30,10 @@ RUN set -eux; \ FROM alpine:3.23 -# Upgrade the base openssl libs (libcrypto3/libssl3) to pick up security fixes -# regardless of the cached base image layer. alpine:3.23 ships these -# transitively (busybox ssl_client), and pinning >=3.5.7-r0 clears CVE-2026-34182 -# (CMS AuthEnvelopedData, CVSS 9.1) plus the sibling openssl CVEs fixed in 3.5.7-r0. -RUN apk add --no-cache ca-certificates "libcrypto3>=3.5.7-r0" "libssl3>=3.5.7-r0" && \ +# --upgrade because the preinstalled version satisfies any floor on its own, so +# apk would keep it; the floor then fails the build if latest is still older. +RUN apk add --no-cache --upgrade ca-certificates \ + "libcrypto3>=3.5.8-r0" "libssl3>=3.5.8-r0" && \ chmod -R 777 /usr/bin COPY --from=build /out/minio /usr/bin/minio