Skip to content

fix(ci): add .dockerignore to keep the build context limited to tracked files - #508

Merged
Jan-Kazlouski-elastic merged 3 commits into
mainfrom
rfojta/fix-org-bouncycastle-bcprov-jdk18on
Oct 5, 2026
Merged

Jan-Kazlouski-elastic merged 3 commits into
mainfrom
rfojta/fix-org-bouncycastle-bcprov-jdk18on

Conversation

@rfojta-elastic

@rfojta-elastic rfojta-elastic commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Adds a .dockerignore, which the repo did not have.

Dockerfile and Dockerfile.wolfi both do COPY . /home/app. Gems and jars install
fresh inside the build (script/bundle → /usr/local/bundle, script/vendor_jars →
vendor/jars), so nothing under the gitignored vendor/bundle, vendor/ruby,
vendor/jruby etc. is needed from the build context. Without a .dockerignore, a
developer's stale local build state in one of those directories would be copied
verbatim into a locally built image — harmless at runtime, but still visible to
filesystem-based scanners.

The list mirrors the corresponding sections of .gitignore.

Scope

This is build-context hygiene for local builds. It does not change the published
images: CI builds from a fresh Buildkite checkout, so there is no local state to leak
there.

It also does not address the Bouncy Castle findings tracked in elastic/search-team#15610
and elastic/search-team#15613 … #15625. Those come from two places that .dockerignore
cannot influence:

  • /opt/jruby/lib/ruby/stdlib/org/bouncycastle/... — JRuby's own stdlib inside the
    base image, which COPY . never writes. Already removed explicitly in both
    Dockerfiles.
  • Snyk projects created from long-superseded image builds (paths under /app/..., from
    before WORKDIR moved to /home/app, referencing BC 1.69 / 1.76 / 1.78 / 1.79).

Those need Snyk project hygiene, not a code change. The dependency fix itself landed in
a19c933 (jruby-openssl 0.16.2 → BC 1.85) and ships in the published 1.1.0 image.

Verification

docker build succeeds and the resulting image contains only the pinned
bcprov-jdk18on 1.85 and jruby-openssl 0.16.2 — no stray Bouncy Castle versions.

rfojta-elastic and others added 2 commits October 2, 2026 13:39
…ation

No new code change required beyond what's already on main. The vulnerable
Bouncy Castle versions (1.78/1.79, flagged across multiple CVEs including
CVE-2026-8763, CVSS 9.3 critical) found in published
docker.elastic.co/integrations/crawler images come from:

- JRuby 9.4.12.0's own stdlib-bundled jruby-openssl 0.15.3 (BC 1.79) at
  /opt/jruby/lib/ruby/stdlib/org/bouncycastle/...
- An older jruby-openssl pin (BC 1.78/1.84 depending on vintage)

This was already fixed on main via commit a19c933 ("fix(deps): bump
jruby-openssl to 0.16.2 for BC 1.85 CVE cluster", 2026-08-27):
- Dockerfile / Dockerfile.wolfi now strip the stdlib-bundled BC jars after
  JRuby install.
- Gemfile/Gemfile.lock pin jruby-openssl to 0.16.2 (bundles BC 1.85).
- Jarfile/Jars.lock pin org.bouncycastle:* directly to 1.85.

However, the last published release tag (v0.1.0) predates this fix
(`git merge-base --is-ancestor a19c933 v0.1.0` confirms it is NOT an
ancestor). The published docker.elastic.co/integrations/crawler image
Snyk is scanning is therefore stale relative to main.

Action needed: cut a new crawler release/tag from current main (or later)
and republish the Docker image so Snyk rescans reflect the fix.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Dockerfile and Dockerfile.wolfi both do `COPY . /home/app`. Gems and jars
install fresh inside the build (script/bundle -> /usr/local/bundle,
script/vendor_jars -> vendor/jars), so nothing under vendor/bundle,
vendor/ruby, vendor/jruby, etc. is actually needed from the build context
or loaded at runtime.

Without a .dockerignore, a developer's local, gitignored build state (e.g.
a vendor/bundle left over from before a jruby-openssl version bump) would
get copied verbatim into the image. It wouldn't affect runtime behavior,
but it could still ship stale/vulnerable jars that a filesystem-based
scanner like Snyk flags, matching some of the /home/app/vendor paths seen
in the Snyk findings for this BC CVE cluster.

Verified: `docker build` still succeeds and produces a clean image with
only the pinned bcprov-jdk18on 1.85 (vendor/jars) and jruby-openssl 0.16.2
(/usr/local/bundle) present - no stray or duplicate Bouncy Castle versions.

Mirrors the ent-search fix in elastic/ent-search#8755 (bundle clean
--force before Warbler packages the WAR) - same class of risk, different
packaging mechanism.

Related: elastic/search-team#15610, #15613-#15625

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@rfojta-elastic
rfojta-elastic requested a review from a team as a code owner October 2, 2026 12:25
@rfojta-elastic rfojta-elastic changed the title docs: track CVE-2026-8763 / Bouncy Castle CVE cluster verification fix(ci): add .dockerignore to prevent stale local build state; verify BC CVE cluster status Oct 2, 2026

@Jan-Kazlouski-elastic Jan-Kazlouski-elastic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two notes on the description before merge:

  • The last published release is v1.0.0 (11 May 2026), not v0.1.0.
  • The "action needed — cut a new release and republish" is already done: 1.1.0
    was published on 22 Sep from main, which contains a19c933.

@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic enabled auto-merge (squash) October 5, 2026 18:42
@Jan-Kazlouski-elastic Jan-Kazlouski-elastic changed the title fix(ci): add .dockerignore to prevent stale local build state; verify BC CVE cluster status fix(ci): add .dockerignore to keep the build context limited to tracked files Oct 5, 2026
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic merged commit 3ebe361 into main Oct 5, 2026
2 checks passed
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic deleted the rfojta/fix-org-bouncycastle-bcprov-jdk18on branch October 5, 2026 18:52
Jan-Kazlouski-elastic added a commit that referenced this pull request Oct 5, 2026
… tracked files (#508) (#516)

Backports the following commits to 1.0:
- fix(ci): add .dockerignore to prevent stale local build state; verify
BC CVE cluster status (#508)

Co-authored-by: Richard Fojta <richard.fojta@elastic.co>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co>
Jan-Kazlouski-elastic added a commit that referenced this pull request Oct 5, 2026
… tracked files (#508) (#517)

Backports the following commits to 1.1:
- fix(ci): add .dockerignore to prevent stale local build state; verify
BC CVE cluster status (#508)

Co-authored-by: Richard Fojta <richard.fojta@elastic.co>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants