Skip to content

chore: roll up security dependency bumps (#525 to #532) - #534

Draft
stirby wants to merge 3 commits into
mainfrom
stirby/security-rollup
Draft

stirby wants to merge 3 commits into
mainfrom
stirby/security-rollup

Conversation

@stirby

@stirby stirby commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Combines the security dependency bumps from #525, #526, #527, #528, #529, #530, #531 and #532 on current main and supersedes them. Most of them conflict with main after #533 and with each other on go.sum, so this resolves all targets in one go get + go mod tidy instead of merging branches.

govulncheck (source mode, reachable findings): 26 on main, 7 on this branch. The 7 remaining are already on main and need a kaniko fork migration (buildkit, moby/go-archive) or have no upstream fix (docker/docker, docker-credential-acr-env). They are out of scope here.

Commits:

  1. Rollup. Every module is at or above its PR's target. otel resolves to v1.45.0 (chore: bump google.golang.org/grpc to 1.83.1 and otel to 1.44.0 #525 asked for v1.44.0) and x/net to v0.58.0 (chore: bump golang.org/x/crypto to 0.56.0 and golang.org/x/net to 0.57.0 #532 asked for v0.57.0) because coder/coder v2.37.3 requires them. Includes the code changes from chore: bump github.com/coder/coder/v2 from 2.26.5 to 2.37.3 #526 (slog v3, agentsdk.WithFixedToken, osfs.WithBoundOS in tests) and chore: bump github.com/DataDog/dd-trace-go/v2 from 2.0.0 to 2.8.1 #529 (unset _DD_ROOT_GO_SESSION_ID).
  2. otel exporters and log SDK. coder/coder v2.37.3 pulls these in at vulnerable versions (GO-2026-6505, GO-2026-6508, GO-2026-6615). Not in any of the original PRs.
  3. Empty env values stay unset. serpent v0.15.0 (fix: allow empty environment variable values to override defaults serpent#32) makes ENVBUILDER_X="" override the option default. That broke TestEnvOptionParsing/bool/empty (also failing on chore: bump github.com/coder/coder/v2 from 2.26.5 to 2.37.3 #526) and would change ENVBUILDER_WORKSPACE_BASE_DIR="" from /workspaces to empty. options.ParseEnviron drops empty values before parsing, which restores the previous behavior. The only difference from serpent v0.10: when both ENVBUILDER_X="" and HOMEBREW_ENVBUILDER_X=value are set, the Homebrew value now applies.

Validation:

  • make test: all packages pass, including 83 integration tests and a new regression test for an empty WORKSPACE_BASE_DIR.
  • make -j lint, ./scripts/check_fmt.sh, and make docs/env-variables.md with a clean diff.
  • End to end on dogfood: a Docker workspace built envbuilder from this branch and built coder/coder main's devcontainer. The agent connected and code-server was healthy. A workspace on released 1.3.0 built the same repo for comparison.

Not covered yet: the layer cache push and probe path, private repos over SSH, and customer devcontainers.

Companion provider PR: coder/terraform-provider-envbuilder#137, pinned to this branch's commit.

Decision log
  • One resolution instead of 8 merges. 6 of 8 PRs conflict on go.mod/go.sum. Resolving them in one pass is equivalent to merging all of them and avoids hand-merging go.sum.
  • Version floors, not exact pins. Pinning otel to v1.44.0 and x/net to v0.57.0 fails because coder/coder v2.37.3 needs newer versions, so those take the higher version.
  • Restore empty-env behavior instead of updating the test. Accepting serpent's new behavior would silently change templates that pass empty strings for options with non-empty defaults (WORKSPACE_BASE_DIR, GIT_CLONE_THINPACK). Templates often build env lists with conditionals that yield "", so filtering in envbuilder keeps every existing template unchanged.
  • Out of scope: buildkit v0.31.1 and moby/go-archive v0.3.0 need docker/docker v29 or moby/moby, which coder/kaniko does not support yet. grpc v1.83.2 (GO-2026-6443) is not included. gopkg.in/DataDog/dd-trace-go.v1 v1.74.0 is marked retracted by its author; it comes from coder/coder, which uses the same version, and govulncheck reports no advisory for it.

Generated by Coder Agents on behalf of @stirby.

stirby added 3 commits October 3, 2026 01:29
Combines #525 #526 #527 #528 #529 #530 #531 #532 on top of main.
otel resolved to v1.45.0 and x/net to v0.58.0 because coder/coder v2.37.3 requires them.
…508, GO-2026-6615

coder/coder v2.37.3 pulls these in at vulnerable versions.
serpent v0.15.0 (via coder/coder v2.37.3) makes an empty environment
variable override an option's default. Filter empty values before option
parsing so templates that pass empty strings keep their defaults, for
example ENVBUILDER_WORKSPACE_BASE_DIR stays /workspaces.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant