Skip to content

Pin Go toolchain image in BATS CI task #1631

Description

@dudejas

Summary

The ci/bats/ Dockerfile references the Go toolchain image without a tag or digest, so Docker resolves it to latest at build time. This is a mutable reference — the image can silently change between runs.

This matters here because the BATS task runs after exporting BOSH admin credentials, meaning a compromised or unreviewed image has access to sensitive values.

Suggested Fix

Pin to a specific version tag or digest:

# instead of
FROM golang

# use
FROM golang:1.23.8
# or a reviewed digest
FROM golang@sha256:<digest>

Broader Context

This pattern exists across github.com/cloudfoundry repos. Per Aram's feedback on the PR where this was flagged, it should be addressed consistently at the org level rather than in one repo in isolation.

Scope

Audit FROM references for mutable toolchain images (Go, Ruby, etc.) across cloudfoundry org repos
Establish a consistent pinning practice (version tag at minimum, digest preferred)
Document the convention so new CI tasks follow it

References

CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Originally flagged by CodeRabbit in bosh-openstack-cpi-release

cc @aramprice

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions