Skip to content

ci: update lint tooling and image security - #25

Merged
appleboy merged 5 commits into
mainfrom
ci/update-actions-security-scan
Sep 12, 2026
Merged

appleboy merged 5 commits into
mainfrom
ci/update-actions-security-scan

Conversation

@appleboy

@appleboy appleboy commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

Update Dockerfile linting from hadolint/[email protected] to v3.5.0 and update golangci-lint from v2.6 to the shared v2.13 release line, which resolves to the latest 2.13.x patch. The lint configuration now ignores repeated test fixture strings, uses the current gofumpt setting, and records narrow gosec exceptions for the documented caller-selected file and URL loading features. The runtime image upgrades Alpine packages during build and uses numeric UID/GID 1000:1000, clearing the vulnerabilities and lint rule surfaced by the new checks. The existing Trivy action remains on the latest v0.36.0 release.

Related issues

  • Jira: N/A
  • GitHub: N/A

AI authorship

  • No AI was used
  • AI was used
    • Tool / model: Codex (GPT-6)
    • AI-authored files: .github/workflows/testing.yml, .golangci.yml, prompt_loader.go, Dockerfile
    • Human line-by-line reviewed: None — not yet reviewed by a human.

Change classification

  • Leaf change
  • Core change

The workflow gates repository changes; a broken action reference can block CI.

Plan reference

Goal and scope: update stale GitHub Actions references while preserving the existing Trivy security policy. No runtime code or action metadata is changed.

Verification

Setup

  • Checkout target / working directory: ci/update-actions-security-scan, repository root
  • Prerequisites: Go with network access for downloading actionlint
  • Prepare: git checkout ci/update-actions-security-scan

Automated checks

Command Behavior covered / expected success Status Observed result
GOPATH=/tmp/codex-go GOMODCACHE=/tmp/codex-go/pkg/mod GOCACHE=/tmp/codex-go/cache go run github.com/rhysd/actionlint/cmd/actionlint@latest .github/workflows/testing.yml The edited workflow passes GitHub Actions static validation with no diagnostics Passed actionlint v1.7.12 exited 0 with no diagnostics
golangci-lint config verify && golangci-lint run using the current v2.13.2 binary resolved by the v2.13 line The current config is valid and production lint rules pass Passed Exited 0 with 0 issues
GOPATH=/tmp/codex-test-go GOMODCACHE=/tmp/codex-test-go/pkg/mod GOCACHE=/tmp/codex-test-go/cache go test ./... Repository behavior and tests remain valid Passed Package passed in 0.442s
docker run --rm -i ghcr.io/hadolint/hadolint:v2.15.1-debian < Dockerfile Dockerfile passes the Hadolint version bundled by action v3.5.0 Passed Exited 0 with no findings
docker build -t llm-action:codex-scan . The hardened runtime image builds successfully Passed Image built successfully with OpenSSL upgraded to 3.5.8-r0
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock aquasec/trivy:0.70.0 image --severity HIGH,CRITICAL --exit-code 1 llm-action:codex-scan Built image has no high or critical vulnerabilities Passed Alpine packages and Go binary both reported 0 vulnerabilities
git diff --check main...HEAD The committed patch has no whitespace errors Passed Exited 0
rg 'hadolint/[email protected]' .github/workflows/testing.yml Dockerfile linting uses the current action release Passed One matching workflow reference
rg 'version: v2.13' .github/workflows/testing.yml golangci-lint follows the shared v2.13 release line Passed One matching tool version
rg 'aquasecurity/[email protected]' .github/workflows/trivy.yml Existing Trivy security scan remains enabled on the latest release Passed Filesystem scan references present

Behavioral scenario: Repository linting

  • Acceptance condition: The testing workflow invokes Hadolint v3.5.0 and the latest golangci-lint v2.13.x patch without the old Go-version panic.
  • Starting state: Branch pushed to GitHub with Actions enabled.
Step Action Expected observable result
1 Trigger the testing workflow by pushing the branch GitHub resolves hadolint/[email protected] and installs the latest golangci-lint v2.13.x patch
2 Inspect the lint job golangci-lint runs with stable Go without the file requires newer Go version panic, then Hadolint checks the existing Dockerfile input
  • Execution status: Passed
  • Observed result: GitHub-hosted Lint and Testing run 34692070911 passed both jobs; Docker Image run 34692070962 passed its build and Trivy image scan.
  • Cleanup: N/A; GitHub disposes the hosted runner.

Security check

  • N/A - no external or security-sensitive interface changed

Risk and rollback

  • Risk: The reviewed gosec exceptions rely on workflow authors controlling the documented file path and URL inputs; untrusted event data should not be passed directly into these inputs. The image build now installs the latest packages available in Alpine 3.22.
  • Rollback: Revert the related commits to restore the previous lint versions, lint configuration, and runtime image build.

Reviewer guide

  • Read carefully: Confirm both lint versions, the four narrow gosec exceptions, and the runtime package upgrade match the intended security posture.
  • Spot-check: Confirm .github/workflows/trivy.yml is unchanged and remains enabled.

- Upgrade Dockerfile linting to the latest Hadolint action release
Copilot AI lite review requested due to automatic review settings September 12, 2026 10:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved issues were identified.

Pull request overview

Updates the Dockerfile linting GitHub Action to Hadolint v3.5.0 while preserving existing CI and Trivy scanning.

Changes:

  • Upgraded Hadolint from v3.3.0 to v3.5.0.
  • Retained the existing Dockerfile lint configuration.
File summaries
File Summary
.github/workflows/testing.yml Uses Hadolint action v3.5.0 for Dockerfile linting.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

- Use a lint binary compatible with the stable Go toolchain
@appleboy appleboy changed the title ci: update hadolint action to v3.5.0 ci: update lint tooling to latest releases Sep 12, 2026
- Ignore repeated test fixture strings in goconst
- Mark documented file and URL loaders as reviewed gosec exceptions
- Migrate gofumpt to its current extra-rules setting
- Upgrade Alpine packages before installing runtime certificates
- Run the image with the existing numeric user and group IDs
- Document why the certificate package intentionally tracks security updates
@appleboy appleboy changed the title ci: update lint tooling to latest releases ci: update lint tooling and image security Sep 12, 2026
- Follow the latest patch release in the shared v2.13 line
@appleboy
appleboy merged commit ecc12ec into main Sep 12, 2026
9 checks passed
@appleboy
appleboy deleted the ci/update-actions-security-scan branch September 12, 2026 12:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants