Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 11 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
# Changelog

## [v3.8.3-rc.2] - 2026-08-26

## [v3.8.3] - 2026-08-20
### Wrapper release

- **v3.8.3-rc.2** — security/maintenance RC; bump indirect **`github.com/gorilla/websocket` v1.5.3** (was v1.5.0) to fix GO-2026-6278 (weak PRNG for WebSocket mask key). No wrapper, Go, or SDK version change.

### CI and release

- **`Dockerfile`**: refresh digest pins for `ubi9/ubi-minimal` and `ubi9/ubi`.
- **`Dockerfile.edge`**: refresh digest pins for `debian:trixie` and `debian:trixie-slim`.

## [v3.8.3-rc.1] - 2026-08-20

### Wrapper release

Expand Down
6 changes: 3 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# registry.access.redhat.com/ubi9/ubi-minimal:latest — pin manifest list digest
FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:8eb2830d0936237fc13a1f2f7e45aecf90d69043380ad167fad0343632937f41 AS builder
FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:580752f96d36c4132bffd30f9c34865bf4bd87f6aa161c969d117f21732e50f7 AS builder

# upgrade first to avoid fixable vulnerabilities
# do this in builder as well as in buildee, so builder does not have different pkg versions from buildee image
Expand All @@ -20,11 +20,11 @@
# Clone skupper-router 3.5.2 so repo contents are in /build (not /build/skupper-router)
RUN git clone --depth 1 --branch 3.5.2 https://github.com/skupperproject/skupper-router.git .
ENV PROTON_VERSION=e5d5c2badb964684bf41ba509a110bf06a24712a
ENV PROTON_SOURCE_URL=${PROTON_SOURCE_URL:-https://github.com/apache/qpid-proton/archive/${PROTON_VERSION}.tar.gz}

Check warning on line 23 in Dockerfile

View workflow job for this annotation

GitHub Actions / Docker smoke (amd64)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$PROTON_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/

Check warning on line 23 in Dockerfile

View workflow job for this annotation

GitHub Actions / Docker smoke (arm64)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$PROTON_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/
ENV LWS_VERSION=v4.3.3
ENV LIBUNWIND_VERSION=v1.8.1
ENV LWS_SOURCE_URL=${LWS_SOURCE_URL:-https://github.com/warmcat/libwebsockets/archive/refs/tags/${LWS_VERSION}.tar.gz}

Check warning on line 26 in Dockerfile

View workflow job for this annotation

GitHub Actions / Docker smoke (amd64)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$LWS_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/

Check warning on line 26 in Dockerfile

View workflow job for this annotation

GitHub Actions / Docker smoke (arm64)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$LWS_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/
ENV LIBUNWIND_SOURCE_URL=${LIBUNWIND_SOURCE_URL:-https://github.com/libunwind/libunwind/archive/refs/tags/${LIBUNWIND_VERSION}.tar.gz}

Check warning on line 27 in Dockerfile

View workflow job for this annotation

GitHub Actions / Docker smoke (amd64)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$LIBUNWIND_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/

Check warning on line 27 in Dockerfile

View workflow job for this annotation

GitHub Actions / Docker smoke (arm64)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$LIBUNWIND_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/
ENV PKG_CONFIG_PATH=/usr/local/lib/pkgconfig

ARG VERSION=0.0.0
Expand All @@ -40,7 +40,7 @@
RUN mkdir /image/licenses && cp ./LICENSE /image/licenses

# registry.access.redhat.com/ubi9/ubi:latest — pin manifest list digest
FROM registry.access.redhat.com/ubi9/ubi@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 AS packager
FROM registry.access.redhat.com/ubi9/ubi@sha256:b8c53f907b7ea8934d6bb23b319ca7b5ab567e61a0806ffc80170631cabc7563 AS packager

RUN dnf -y --setopt=install_weak_deps=0 --nodocs \
--installroot /output install \
Expand Down Expand Up @@ -69,7 +69,7 @@
RUN GOOS=${TARGETOS} GOARCH=${TARGETARCH} go build -trimpath -ldflags="-s -w" -o bin/router .

# registry.access.redhat.com/ubi9/ubi-minimal:latest — pin manifest list digest
FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:8eb2830d0936237fc13a1f2f7e45aecf90d69043380ad167fad0343632937f41 AS tz
FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:580752f96d36c4132bffd30f9c34865bf4bd87f6aa161c969d117f21732e50f7 AS tz
RUN microdnf install -y tzdata && microdnf reinstall -y tzdata

FROM scratch
Expand Down
6 changes: 3 additions & 3 deletions Dockerfile.edge
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
# UBI Dockerfile handles amd64/arm64; this file mirrors /image layout → scratch.

# debian:trixie — pin manifest list digest
FROM debian:trixie@sha256:34cd9e9fd437c0a095ec39cb2e73422c9f30821b0d0848ed74fd0d43bae4d958 AS builder
FROM debian:trixie@sha256:f324c7ff54321e8d9c588493a20244965938ce0aa50bbd1022d38010e9ffc4b1 AS builder

RUN apt-get update && apt-get install -y --no-install-recommends \
gcc g++ make cmake pkg-config \
Expand All @@ -18,11 +18,11 @@
RUN git clone --depth 1 --branch 3.5.2 https://github.com/skupperproject/skupper-router.git .

ENV PROTON_VERSION=e5d5c2badb964684bf41ba509a110bf06a24712a
ENV PROTON_SOURCE_URL=${PROTON_SOURCE_URL:-https://github.com/apache/qpid-proton/archive/${PROTON_VERSION}.tar.gz}

Check warning on line 21 in Dockerfile.edge

View workflow job for this annotation

GitHub Actions / Docker smoke (armv7)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$PROTON_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/

Check warning on line 21 in Dockerfile.edge

View workflow job for this annotation

GitHub Actions / Docker smoke (riscv64)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$PROTON_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/
ENV LWS_VERSION=v4.3.3
ENV LIBUNWIND_VERSION=v1.8.1
ENV LWS_SOURCE_URL=${LWS_SOURCE_URL:-https://github.com/warmcat/libwebsockets/archive/refs/tags/${LWS_VERSION}.tar.gz}

Check warning on line 24 in Dockerfile.edge

View workflow job for this annotation

GitHub Actions / Docker smoke (armv7)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$LWS_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/

Check warning on line 24 in Dockerfile.edge

View workflow job for this annotation

GitHub Actions / Docker smoke (riscv64)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$LWS_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/
ENV LIBUNWIND_SOURCE_URL=${LIBUNWIND_SOURCE_URL:-https://github.com/libunwind/libunwind/archive/refs/tags/${LIBUNWIND_VERSION}.tar.gz}

Check warning on line 25 in Dockerfile.edge

View workflow job for this annotation

GitHub Actions / Docker smoke (armv7)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$LIBUNWIND_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/

Check warning on line 25 in Dockerfile.edge

View workflow job for this annotation

GitHub Actions / Docker smoke (riscv64)

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$LIBUNWIND_SOURCE_URL' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/
ENV PKG_CONFIG_PATH=/usr/local/lib/pkgconfig
ENV PIP_BREAK_SYSTEM_PACKAGES=1
ENV CFLAGS="-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fstack-protector-strong"
Expand Down Expand Up @@ -58,7 +58,7 @@
RUN mkdir /image/licenses && cp ./LICENSE /image/licenses

# debian:trixie — pin manifest list digest
FROM debian:trixie@sha256:34cd9e9fd437c0a095ec39cb2e73422c9f30821b0d0848ed74fd0d43bae4d958 AS packager
FROM debian:trixie@sha256:f324c7ff54321e8d9c588493a20244965938ce0aa50bbd1022d38010e9ffc4b1 AS packager

# UBI installroot analogue: download only runtime .debs + hard deps, extract to /output.
ENV ROOTFS=/output
Expand Down Expand Up @@ -101,7 +101,7 @@
fi

# debian:trixie-slim — pin manifest list digest
FROM debian:trixie-slim@sha256:3a39a0592364683e6bab97937b72cad5a8fa6dcbbee90edb3bb48c7f8e94f258 AS tz
FROM debian:trixie-slim@sha256:d7e12182ce18b85b93007c1dedf31f2d29e01ccf3182cc4017c709b6259bc132 AS tz
RUN apt-get update && apt-get install -y --no-install-recommends tzdata \
&& rm -rf /var/lib/apt/lists/*

Expand Down
2 changes: 1 addition & 1 deletion go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ require (
github.com/Azure/go-autorest/autorest/validation v0.3.2 // indirect
github.com/fortytw2/leaktest v1.3.0 // indirect
github.com/google/go-cmp v0.6.0 // indirect
github.com/gorilla/websocket v1.5.0 // indirect
github.com/gorilla/websocket v1.5.3 // indirect
github.com/pkg/errors v0.9.1 // indirect
golang.org/x/crypto v0.28.0 // indirect
golang.org/x/sys v0.46.0 // indirect
Expand Down
4 changes: 2 additions & 2 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,8 @@ github.com/golang-jwt/jwt/v4 v4.5.0/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w
github.com/google/go-cmp v0.4.0/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
github.com/google/go-cmp v0.6.0 h1:ofyhxvXcZhMsU5ulbFiLKl/XBFqE1GSq7atu8tAmTRI=
github.com/google/go-cmp v0.6.0/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY=
github.com/gorilla/websocket v1.5.0 h1:PPwGk2jz7EePpoHN/+ClbZu8SPxiqlu12wZP/3sWmnc=
github.com/gorilla/websocket v1.5.0/go.mod h1:YR8l580nyteQvAITg2hZ9XVh4b55+EU/adAjf1fMHhE=
github.com/gorilla/websocket v1.5.3 h1:saDtZ6Pbx/0u+bgYQ3q96pZgCzfhKXGPqt7kZ72aNNg=
github.com/gorilla/websocket v1.5.3/go.mod h1:YR8l580nyteQvAITg2hZ9XVh4b55+EU/adAjf1fMHhE=
github.com/interconnectedcloud/go-amqp v0.12.6-0.20200506124159-f51e540008b5 h1:n3J6cCOpmsEXSEEFpXszM5kNsqtb7XiX3Q2bxeplWeQ=
github.com/interconnectedcloud/go-amqp v0.12.6-0.20200506124159-f51e540008b5/go.mod h1:laGtnFhRcIocSgShx6P6FqnRqQoaXGEz87QpNXSnPS8=
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
Expand Down
Loading