From 34070085f8064030d942c0f0ca955f5d672b58cc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Emirhan=20Durmu=C5=9F?= Date: Thu, 20 Aug 2026 16:42:14 +0300 Subject: [PATCH 1/2] chore(release): v3.8.3 - Go 1.26.6, skupper-router 3.5.2, refresh image digest pins --- .github/workflows/ci.yml | 2 +- .github/workflows/govulncheck.yml | 2 +- .github/workflows/release.yml | 2 +- .golangci.yaml | 2 +- CHANGELOG.md | 19 +++++++++++++++++++ Dockerfile | 14 +++++++------- Dockerfile.dev | 4 ++-- Dockerfile.edge | 12 ++++++------ README.md | 2 +- go.mod | 6 +++--- go.sum | 8 ++++---- 11 files changed, 46 insertions(+), 27 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 1c55704..4440bea 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -18,7 +18,7 @@ on: permissions: read-all env: - GO_VERSION: '1.26.5' + GO_VERSION: '1.26.6' jobs: lint: diff --git a/.github/workflows/govulncheck.yml b/.github/workflows/govulncheck.yml index 5d265f7..182e87c 100644 --- a/.github/workflows/govulncheck.yml +++ b/.github/workflows/govulncheck.yml @@ -8,7 +8,7 @@ on: permissions: read-all env: - GO_VERSION: '1.26.5' + GO_VERSION: '1.26.6' jobs: govulncheck: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2c095dc..71b6f93 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -6,7 +6,7 @@ on: - 'v*' env: - GO_VERSION: '1.26.5' + GO_VERSION: '1.26.6' permissions: read-all diff --git a/.golangci.yaml b/.golangci.yaml index ab09136..cfb2a84 100644 --- a/.golangci.yaml +++ b/.golangci.yaml @@ -1,5 +1,5 @@ # golangci-lint configuration for router wrapper -# Target: Go 1.26.5, module github.com/eclipse-iofog/router +# Target: Go 1.26.6, module github.com/eclipse-iofog/router version: "2" diff --git a/CHANGELOG.md b/CHANGELOG.md index 635598c..b192f95 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,24 @@ # Changelog + +## [v3.8.3] - 2026-08-20 + +### Wrapper release + +- **v3.8.3** — security/maintenance patch; Go toolchain **1.26.6** (was 1.26.5) to pick up stdlib fixes (GO-2026-6218, GO-2026-6090, GO-2026-5972, GO-2026-5026). No wrapper change. +- Bump iofog-go-sdk to **iofog-go-sdk v3.8.3-rc.1** + +### Embedded skupper-router + +- Pin and compile upstream **skupper-router 3.5.2** (was 3.5.1; separate from wrapper semver). + +### CI and release + +- **`ci.yml`**, **`release.yml`**, **`govulncheck.yml`**: Go **1.26.6** in workflow env. +- **`Dockerfile`**, **`Dockerfile.dev`**, **`Dockerfile.edge`**: `golang:1.26.6-alpine` builder image (digest-pinned in prod/edge). +- **`Dockerfile`**: refresh digest pins for `ubi9/ubi-minimal` and `ubi9/ubi`; compile skupper-router **3.5.2**. +- **`Dockerfile.edge`**: refresh digest pins for `debian:trixie` and `debian:trixie-slim`; compile skupper-router **3.5.2**. + ## [v3.8.2] - 2026-07-25 ### Wrapper release diff --git a/Dockerfile b/Dockerfile index 5656d65..8a5677f 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # registry.access.redhat.com/ubi9/ubi-minimal:latest — pin manifest list digest -FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:2e8edce823a48e51858f1fad3ff4cbf6875ce8a3f86b9eecf298bc2050c8652a AS builder +FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:8eb2830d0936237fc13a1f2f7e45aecf90d69043380ad167fad0343632937f41 AS builder # upgrade first to avoid fixable vulnerabilities # do this in builder as well as in buildee, so builder does not have different pkg versions from buildee image @@ -17,8 +17,8 @@ RUN microdnf -y --setopt=install_weak_deps=0 --setopt=tsflags=nodocs install \ && microdnf clean all -y WORKDIR /build -# Clone skupper-router 3.5.1 so repo contents are in /build (not /build/skupper-router) -RUN git clone --depth 1 --branch 3.5.1 https://github.com/skupperproject/skupper-router.git . +# Clone skupper-router 3.5.2 so repo contents are in /build (not /build/skupper-router) +RUN git clone --depth 1 --branch 3.5.2 https://github.com/skupperproject/skupper-router.git . ENV PROTON_VERSION=e5d5c2badb964684bf41ba509a110bf06a24712a ENV PROTON_SOURCE_URL=${PROTON_SOURCE_URL:-https://github.com/apache/qpid-proton/archive/${PROTON_VERSION}.tar.gz} ENV LWS_VERSION=v4.3.3 @@ -40,7 +40,7 @@ RUN if [ "$PLATFORM" = "ppc64le" ]; then tar zxpf /qpid-proton-image.tar.gz -C / RUN mkdir /image/licenses && cp ./LICENSE /image/licenses # registry.access.redhat.com/ubi9/ubi:latest — pin manifest list digest -FROM registry.access.redhat.com/ubi9/ubi@sha256:2a6bd6971e6026177b2439655282660519198870e9063c4a03a208de88be2e9e AS packager +FROM registry.access.redhat.com/ubi9/ubi@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 AS packager RUN dnf -y --setopt=install_weak_deps=0 --nodocs \ --installroot /output install \ @@ -56,8 +56,8 @@ RUN dnf -y --setopt=install_weak_deps=0 --nodocs \ RUN [ -d /usr/share/buildinfo ] && cp -a /usr/share/buildinfo /output/usr/share/buildinfo ||: RUN [ -d /root/buildinfo ] && cp -a /root/buildinfo /output/root/buildinfo ||: -# golang:1.26.5-alpine — pin manifest list digest -FROM golang:1.26.5-alpine@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2 AS go-builder +# golang:1.26.6-alpine — pin manifest list digest +FROM golang:1.26.6-alpine@sha256:3889b425f035be855a72fb4755265311293b6d414521f0a519d819df32222d83 AS go-builder ARG TARGETOS ARG TARGETARCH @@ -69,7 +69,7 @@ RUN go fmt ./... RUN GOOS=${TARGETOS} GOARCH=${TARGETARCH} go build -trimpath -ldflags="-s -w" -o bin/router . # registry.access.redhat.com/ubi9/ubi-minimal:latest — pin manifest list digest -FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:2e8edce823a48e51858f1fad3ff4cbf6875ce8a3f86b9eecf298bc2050c8652a AS tz +FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:8eb2830d0936237fc13a1f2f7e45aecf90d69043380ad167fad0343632937f41 AS tz RUN microdnf install -y tzdata && microdnf reinstall -y tzdata FROM scratch diff --git a/Dockerfile.dev b/Dockerfile.dev index 1278918..638d96e 100644 --- a/Dockerfile.dev +++ b/Dockerfile.dev @@ -1,4 +1,4 @@ -FROM golang:1.26.5-alpine AS go-builder +FROM golang:1.26.6-alpine AS go-builder ARG TARGETOS ARG TARGETARCH @@ -12,7 +12,7 @@ RUN GOOS=${TARGETOS} GOARCH=${TARGETARCH} go build -trimpath -ldflags="-s -w" - FROM registry.access.redhat.com/ubi9/ubi-minimal:latest AS tz RUN microdnf install -y tzdata && microdnf reinstall -y tzdata -FROM quay.io/skupper/skupper-router:3.5.1 +FROM quay.io/skupper/skupper-router:3.5.2 COPY LICENSE /licenses/LICENSE COPY --from=go-builder /go/src/github.com/eclipse-iofog/router/bin/router /home/skrouterd/bin/router COPY scripts/launch.sh /home/skrouterd/bin/launch.sh diff --git a/Dockerfile.edge b/Dockerfile.edge index ea39230..e74c6a4 100644 --- a/Dockerfile.edge +++ b/Dockerfile.edge @@ -2,7 +2,7 @@ # UBI Dockerfile handles amd64/arm64; this file mirrors /image layout → scratch. # debian:trixie — pin manifest list digest -FROM debian:trixie@sha256:fac46bff2e02f51425b6e33b0e1169f55dfb053d83511ca28aa50c09fd5ed7a4 AS builder +FROM debian:trixie@sha256:34cd9e9fd437c0a095ec39cb2e73422c9f30821b0d0848ed74fd0d43bae4d958 AS builder RUN apt-get update && apt-get install -y --no-install-recommends \ gcc g++ make cmake pkg-config \ @@ -15,7 +15,7 @@ RUN apt-get update && apt-get install -y --no-install-recommends \ && rm -rf /var/lib/apt/lists/* WORKDIR /build -RUN git clone --depth 1 --branch 3.5.1 https://github.com/skupperproject/skupper-router.git . +RUN git clone --depth 1 --branch 3.5.2 https://github.com/skupperproject/skupper-router.git . ENV PROTON_VERSION=e5d5c2badb964684bf41ba509a110bf06a24712a ENV PROTON_SOURCE_URL=${PROTON_SOURCE_URL:-https://github.com/apache/qpid-proton/archive/${PROTON_VERSION}.tar.gz} @@ -58,7 +58,7 @@ RUN mkdir -p /image \ RUN mkdir /image/licenses && cp ./LICENSE /image/licenses # debian:trixie — pin manifest list digest -FROM debian:trixie@sha256:fac46bff2e02f51425b6e33b0e1169f55dfb053d83511ca28aa50c09fd5ed7a4 AS packager +FROM debian:trixie@sha256:34cd9e9fd437c0a095ec39cb2e73422c9f30821b0d0848ed74fd0d43bae4d958 AS packager # UBI installroot analogue: download only runtime .debs + hard deps, extract to /output. ENV ROOTFS=/output @@ -84,8 +84,8 @@ RUN rm -rf \ && find "${ROOTFS}/usr/lib" -name 'libapt*.so*' -delete \ && find "${ROOTFS}/usr/lib" -path '*/python3*' -type d \( -name test -o -name idlelib -o -name tkinter -o -name ensurepip \) -exec rm -rf {} + 2>/dev/null || true -# golang:1.26.5-alpine — pin manifest list digest -FROM golang:1.26.5-alpine@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2 AS go-builder +# golang:1.26.6-alpine — pin manifest list digest +FROM golang:1.26.6-alpine@sha256:3889b425f035be855a72fb4755265311293b6d414521f0a519d819df32222d83 AS go-builder ARG TARGETOS ARG TARGETARCH @@ -101,7 +101,7 @@ RUN if [ "$TARGETARCH" = "arm" ]; then \ fi # debian:trixie-slim — pin manifest list digest -FROM debian:trixie-slim@sha256:020c0d20b9880058cbe785a9db107156c3c75c2ac944a6aa7ab59f2add76a7bd AS tz +FROM debian:trixie-slim@sha256:3a39a0592364683e6bab97937b72cad5a8fa6dcbbee90edb3bb48c7f8e94f258 AS tz RUN apt-get update && apt-get install -y --no-install-recommends tzdata \ && rm -rf /var/lib/apt/lists/* diff --git a/README.md b/README.md index 09945a4..e2f2b46 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,7 @@ [![CI](https://github.com/eclipse-iofog/router/actions/workflows/ci.yml/badge.svg?branch=develop)](https://github.com/eclipse-iofog/router/actions/workflows/ci.yml) [![Release](https://github.com/eclipse-iofog/router/actions/workflows/release.yml/badge.svg)](https://github.com/eclipse-iofog/router/actions/workflows/release.yml) -[![Go](https://img.shields.io/badge/Go-1.26.5-00ADD8?logo=go&logoColor=white)](https://go.dev/) +[![Go](https://img.shields.io/badge/Go-1.26.6-00ADD8?logo=go&logoColor=white)](https://go.dev/) Go wrapper image for **[skupper-router](https://github.com/skupperproject/skupper-router)** used by **Eclipse ioFog** and **Datasance PoT** edge fleets. The wrapper supervises embedded **`skrouterd`** with config watch and AMQP hot reload. diff --git a/go.mod b/go.mod index c9c3257..dcb5eb4 100644 --- a/go.mod +++ b/go.mod @@ -1,9 +1,9 @@ module github.com/eclipse-iofog/router -go 1.26.5 +go 1.26.6 require ( - github.com/eclipse-iofog/iofog-go-sdk/v3 v3.8.1 + github.com/eclipse-iofog/iofog-go-sdk/v3 v3.8.3-rc.1 github.com/fsnotify/fsnotify v1.7.0 github.com/interconnectedcloud/go-amqp v0.12.6-0.20200506124159-f51e540008b5 gotest.tools/v3 v3.5.2 @@ -21,5 +21,5 @@ require ( github.com/gorilla/websocket v1.5.0 // indirect github.com/pkg/errors v0.9.1 // indirect golang.org/x/crypto v0.28.0 // indirect - golang.org/x/sys v0.45.0 // indirect + golang.org/x/sys v0.46.0 // indirect ) diff --git a/go.sum b/go.sum index 0df12cf..0a7691a 100644 --- a/go.sum +++ b/go.sum @@ -21,8 +21,8 @@ github.com/Azure/go-autorest/tracing v0.6.0 h1:TYi4+3m5t6K48TGI9AUdb+IzbnSxvnvUM github.com/Azure/go-autorest/tracing v0.6.0/go.mod h1:+vhtPC754Xsa23ID7GlGsrdKBpUA79WCAKPPZVC2DeU= github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= -github.com/eclipse-iofog/iofog-go-sdk/v3 v3.8.1 h1:bjy4FvkEcKS+td/1zIVgWUjJFQVxkXiI6P/JCXrXlRA= -github.com/eclipse-iofog/iofog-go-sdk/v3 v3.8.1/go.mod h1:yuTviLS8Z4MM7glAugZV+gwzjSxKFiKPDLA74GxFba4= +github.com/eclipse-iofog/iofog-go-sdk/v3 v3.8.3-rc.1 h1:3D3eklSjFqQ/0G4/BDiQAz0X8jORrm/glcAvqIsW7gc= +github.com/eclipse-iofog/iofog-go-sdk/v3 v3.8.3-rc.1/go.mod h1:16CjC/B5xwOc76nzCsoXS3EdD/MHeusxbsUGS/Wi1UI= github.com/fortytw2/leaktest v1.3.0 h1:u8491cBMTQ8ft8aeV+adlcytMZylmA5nnwwkRZjI8vw= github.com/fortytw2/leaktest v1.3.0/go.mod h1:jDsjWgpAGjm2CA7WthBh/CdZYEPF31XHquHwclZch5g= github.com/fsnotify/fsnotify v1.7.0 h1:8JEhPFa5W2WU7YfeZzPNqzMP6Lwt7L2715Ggo0nosvA= @@ -74,8 +74,8 @@ golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBc golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.15.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= -golang.org/x/sys v0.45.0 h1:dO4czNzziLiiXplLQgBCEpCvXQ3dnkn0SdaZSYdQ+FY= -golang.org/x/sys v0.45.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= +golang.org/x/sys v0.46.0 h1:noSf2Fq6F8DBgS+LysIkx7rIExoNHJsxOAtPp4rthXw= +golang.org/x/sys v0.46.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8= golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k= From 04b32ceff7996f3e78b581272bd13e0943c2f6ca Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Emirhan=20Durmu=C5=9F?= Date: Thu, 20 Aug 2026 16:46:01 +0300 Subject: [PATCH 2/2] readme wrapper notice update --- CONTRIBUTING.md | 4 ++-- README.md | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index bfebcc4..3f83485 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -29,9 +29,9 @@ Do **not** use the legacy **`iofog/merge`** branch — it is abandoned in favor ## Development setup -- **Go 1.26.5** (see `go.mod`). +- **Go 1.26.6** (see `go.mod`). - `make test`, `make fmt-check`, `make security-code` before pushing. -- Local wrapper overlay: `Dockerfile.dev` (upstream `quay.io/skupper/skupper-router:3.5.1` image). +- Local wrapper overlay: `Dockerfile.dev` (upstream `quay.io/skupper/skupper-router:3.5.2` image). Module import path is always **`github.com/eclipse-iofog/router`**, even when cloning the Datasance mirror. diff --git a/README.md b/README.md index e2f2b46..af3a921 100644 --- a/README.md +++ b/README.md @@ -8,8 +8,8 @@ Go wrapper image for **[skupper-router](https://github.com/skupperproject/skuppe | Component | Version | |-----------|---------| -| Wrapper release | **v3.8.0** | -| Embedded skupper-router | **3.5.1** (compiled from upstream tag pin) | +| Wrapper release | **v3.8.3** | +| Embedded skupper-router | **3.5.2** (compiled from upstream tag pin) | Edgelet workload label: **`iofog-router`**.