Summary
The ci/bats/ Dockerfile references the Go toolchain image without a tag or digest, so Docker resolves it to latest at build time. This is a mutable reference — the image can silently change between runs.
This matters here because the BATS task runs after exporting BOSH admin credentials, meaning a compromised or unreviewed image has access to sensitive values.
Suggested Fix
Pin to a specific version tag or digest:
# instead of
FROM golang
# use
FROM golang:1.23.8
# or a reviewed digest
FROM golang@sha256:<digest>
Broader Context
This pattern exists across github.com/cloudfoundry repos. Per Aram's feedback on the PR where this was flagged, it should be addressed consistently at the org level rather than in one repo in isolation.
Scope
Audit FROM references for mutable toolchain images (Go, Ruby, etc.) across cloudfoundry org repos
Establish a consistent pinning practice (version tag at minimum, digest preferred)
Document the convention so new CI tasks follow it
References
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Originally flagged by CodeRabbit in bosh-openstack-cpi-release
cc @aramprice
Summary
The
ci/bats/Dockerfile references the Go toolchain image without a tag or digest, so Docker resolves it tolatestat build time. This is a mutable reference — the image can silently change between runs.This matters here because the BATS task runs after exporting BOSH admin credentials, meaning a compromised or unreviewed image has access to sensitive values.
Suggested Fix
Pin to a specific version tag or digest:
Broader Context
This pattern exists across github.com/cloudfoundry repos. Per Aram's feedback on the PR where this was flagged, it should be addressed consistently at the org level rather than in one repo in isolation.
Scope
Audit FROM references for mutable toolchain images (Go, Ruby, etc.) across cloudfoundry org repos
Establish a consistent pinning practice (version tag at minimum, digest preferred)
Document the convention so new CI tasks follow it
References
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Originally flagged by CodeRabbit in bosh-openstack-cpi-release
cc @aramprice