Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions .github/workflows/sbom.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: SBOM & Vulnerability Scan

on:
push:
branches: ["release/*"]
branches: ["main", "release/*"]
pull_request:
branches: ["release/*"]
branches: ["main", "release/*"]
workflow_dispatch:

jobs:
Expand All @@ -16,7 +16,8 @@ jobs:

- name: Build image
run: |
docker build -t minio:marketplace -f Dockerfile.marketplace .
docker build -t minio:marketplace -f Dockerfile.marketplace \
--build-arg SOURCE_COMMIT="${{ github.event.pull_request.head.sha || github.sha }}" .

- name: Generate SBOM (Syft)
uses: anchore/sbom-action@v0
Expand Down
31 changes: 22 additions & 9 deletions Dockerfile.marketplace
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,8 @@ FROM --platform=$BUILDPLATFORM golang:1.26.5-alpine AS build

ARG TARGETARCH
ARG RELEASE_VERSION=2025-10-15T17-29-55Z
ARG COMMIT_ID=9e49d5e7a648f00e26f2246f4dc28e6b07f8c84a
ARG SHORT_COMMIT_ID=9e49d5e7a648
# No default on purpose: a build that cannot name its commit should fail.
ARG SOURCE_COMMIT

ENV CGO_ENABLED=0 \
GOTOOLCHAIN=local \
Expand All @@ -16,27 +16,40 @@ WORKDIR /src
COPY . .

RUN set -eux; \
test -n "${SOURCE_COMMIT}" || { echo "SOURCE_COMMIT build-arg is required"; exit 1; }; \
short_commit=$(echo "${SOURCE_COMMIT}" | cut -c1-12); \
ldflags="-s -w"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.Version=${RELEASE_VERSION}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.CopyrightYear=2025"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.ReleaseTag=RELEASE.${RELEASE_VERSION}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.CommitID=${COMMIT_ID}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.ShortCommitID=${SHORT_COMMIT_ID}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.CommitID=${SOURCE_COMMIT}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.ShortCommitID=${short_commit}"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.GOPATH=/go"; \
ldflags="${ldflags} -X github.com/minio/minio/cmd.GOROOT=/usr/local/go"; \
GOOS=linux GOARCH=${TARGETARCH} go build -tags kqueue -trimpath --ldflags "${ldflags}" -o /out/minio .

FROM alpine:3.23

# Upgrade the base openssl libs (libcrypto3/libssl3) to pick up security fixes
# regardless of the cached base image layer. alpine:3.23 ships these
# transitively (busybox ssl_client), and pinning >=3.5.7-r0 clears CVE-2026-34182
# (CMS AuthEnvelopedData, CVSS 9.1) plus the sibling openssl CVEs fixed in 3.5.7-r0.
RUN apk add --no-cache ca-certificates "libcrypto3>=3.5.7-r0" "libssl3>=3.5.7-r0" && \
# --upgrade because the preinstalled version satisfies any floor on its own, so
# apk would keep it; the floor then fails the build if latest is still older.
RUN apk add --no-cache --upgrade ca-certificates \
"libcrypto3>=3.5.8-r0" "libssl3>=3.5.8-r0" && \
chmod -R 777 /usr/bin

COPY --from=build /out/minio /usr/bin/minio
COPY dockerscripts/docker-entrypoint.sh /usr/bin/docker-entrypoint.sh
# Same paths Dockerfile.release ships them at.
COPY LICENSE /licenses/LICENSE
COPY CREDITS /licenses/CREDITS

# Last in the stage on purpose: an ARG invalidates the cache of everything
# after it, and the commit changes on every build.
ARG SOURCE_COMMIT
LABEL org.opencontainers.image.title="MinIO (CryptoLab build)" \
org.opencontainers.image.description="MinIO built from CryptoLabInc/minio, a modified fork of minio/minio" \
org.opencontainers.image.source="https://github.com/CryptoLabInc/minio" \
org.opencontainers.image.revision="${SOURCE_COMMIT}" \
org.opencontainers.image.licenses="AGPL-3.0-only"

EXPOSE 9000
VOLUME ["/data"]
Expand Down
Loading