Skip to content

[1.1] fix(ci): add .dockerignore to keep the build context limited to tracked files (#508) - #517

Merged
Jan-Kazlouski-elastic merged 1 commit into
1.1from
backport/1.1/pr-508
Oct 5, 2026
Merged

Jan-Kazlouski-elastic merged 1 commit into
1.1from
backport/1.1/pr-508

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Backports the following commits to 1.1:

… BC CVE cluster status (#508)

## Summary

**Verification:** the fix for this Bouncy Castle CVE cluster is already
on
`main` (commit a19c933, "fix(deps): bump jruby-openssl to 0.16.2 for BC
1.85 CVE cluster", 2026-08-27):
- `Dockerfile`/`Dockerfile.wolfi` strip the JRuby-stdlib-bundled BC jars
  (1.79, from jruby-openssl 0.15.3 shipped inside JRuby 9.4.12.0 itself)
  after install.
- `Gemfile`/`Gemfile.lock` pin `jruby-openssl` to `0.16.2` (bundles BC
1.85).
- `Jarfile`/`Jars.lock` pin `org.bouncycastle:*` directly to `1.85`.

**The gap:** the last published release tag `v0.1.0` predates this fix
(`git merge-base --is-ancestor a19c933 v0.1.0` → not an ancestor). The
published `docker.elastic.co/integrations/crawler` image Snyk has been
scanning was built before the fix landed — cutting a new release/tag
from
current `main` and republishing is still needed (not something this PR
does).

**Real fix included:** added a `.dockerignore` (none existed before).
`Dockerfile`/`Dockerfile.wolfi` both do `COPY . /home/app`. Gems/jars
install fresh inside the build (`script/bundle` -> `/usr/local/bundle`,
`script/vendor_jars` -> `vendor/jars`), so nothing under the gitignored
`vendor/bundle`, `vendor/ruby`, `vendor/jruby`, etc. is actually needed
from the build context. Without a `.dockerignore`, a developer's stale
local build state sitting in one of those gitignored directories would
get copied verbatim into the image by `COPY . /home/app` — harmless at
runtime, but still flaggable by filesystem-based scanners like Snyk
(matching some of the `/home/app/vendor/...` paths in the original
findings). Verified the Docker build still succeeds and produces a clean
image with only the pinned `bcprov-jdk18on` 1.85 and `jruby-openssl`
0.16.2 present, no stray BC versions.

Mirrors the `ent-search` fix in elastic/ent-search#8755 — same class of
risk (stale local build state leaking into a shipped artifact),
different
packaging mechanism.

## related issues

elastic/search-team#15610

elastic/search-team#15613

elastic/search-team#15614

elastic/search-team#15615

elastic/search-team#15616

elastic/search-team#15617

elastic/search-team#15618

elastic/search-team#15619

elastic/search-team#15620

elastic/search-team#15621

elastic/search-team#15622

elastic/search-team#15623

elastic/search-team#15624

elastic/search-team#15625

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co>
@github-actions
github-actions Bot requested a review from a team as a code owner October 5, 2026 18:54
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic enabled auto-merge (squash) October 5, 2026 19:00
@Jan-Kazlouski-elastic Jan-Kazlouski-elastic changed the title [1.1] fix(ci): add .dockerignore to prevent stale local build state; verify BC CVE cluster status (#508) [1.1] fix(ci): add .dockerignore to keep the build context limited to tracked files (#508) Oct 5, 2026
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic merged commit b8e9db3 into 1.1 Oct 5, 2026
2 checks passed
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic deleted the backport/1.1/pr-508 branch October 5, 2026 19:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants