Skip to content

deps(patch): update golang:1.27.1-alpine docker digest to 8a5910f - #11

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/docker-digests
Sep 21, 2026
Merged

renovate[bot] merged 1 commit into
masterfrom
renovate/docker-digests

Conversation

@renovate

@renovate renovate Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
golang (source) stage digest 4cb7ac9 → 8a5910f

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the renovate Automated action from Renovate label Sep 21, 2026
@renovate
renovate Bot enabled auto-merge (squash) September 21, 2026 21:56
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the golang builder image digest to 8a5910f in the Dockerfile. While the change itself is straightforward and meets the acceptance criteria, the synthesis reveals that the Dockerfile lacks a non-root user configuration for the final execution stage, posing a security risk. Furthermore, there is no verification that the Dockerfile builds successfully with the new digest. These items should be addressed to ensure both security and functional stability.

1 comment outside of the diff
cmd/dashboardctl/Dockerfile

line 23-24000 🔴 HIGH RISK
The final stage of this Dockerfile (starting at line 19) runs the application as the root user. To follow the principle of least privilege and mitigate potential container escape vulnerabilities, you should create a dedicated non-privileged user and switch to it using the 'USER' instruction.

Try running the following prompt in your IDE agent:

Update the final Alpine stage in cmd/dashboardctl/Dockerfile to create a non-root system user named 'appuser'. Use 'adduser -D -g "" appuser' to create the user, and add the 'USER appuser' instruction before the ENTRYPOINT. Ensure the binary at /usr/bin/dashboardctl remains executable.

Test suggestions

  • Verify the Dockerfile builds successfully with the updated base image digest
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify the Dockerfile builds successfully with the updated base image digest

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

@renovate
renovate Bot merged commit f031bf1 into master Sep 21, 2026
8 checks passed
@renovate
renovate Bot deleted the renovate/docker-digests branch September 21, 2026 21:59
@cloudpunks

cloudpunks Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.1.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

@cloudpunks cloudpunks Bot added the released label Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

released renovate Automated action from Renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants