|
| 1 | +# SOW-0019 - Go stdlib CVE scanner policy while go.mod is pinned for netdata |
| 2 | + |
| 3 | +## Status |
| 4 | + |
| 5 | +Status: completed |
| 6 | + |
| 7 | +Sub-state: scanner configuration shipped; constraint recorded; committed with this SOW. |
| 8 | + |
| 9 | +## Requirements |
| 10 | + |
| 11 | +### Purpose |
| 12 | + |
| 13 | +Keep CI green and GitHub Code Scanning meaningful while the Go module directive must stay at `go 1.26.0` for netdata vendoring compatibility. |
| 14 | + |
| 15 | +### User Request |
| 16 | + |
| 17 | +"do not change go.mod because netdata is 1.26 and when vendored it breaks netdata. We wait for netdata to increase it. Do the others." — 2026-06-10. Followed by "ci OSV fails". |
| 18 | + |
| 19 | +### Assistant Understanding |
| 20 | + |
| 21 | +Facts: |
| 22 | + |
| 23 | +- The three Go modules (`src/go`, `bench/drivers/go`, `tests/fixtures/go`) declare `go 1.26.0`. Raising the directive would make the vendored source require a newer toolchain than netdata currently builds with. |
| 24 | +- osv-scanner keys Go stdlib vulnerabilities to the `go.mod` directive: 23 CVEs × 3 modules = 69 GitHub Code Scanning alerts and a red Supply Chain Security workflow. |
| 25 | +- govulncheck scans with the installed toolchain's stdlib; CI's `setup-go` used `go-version-file: go.mod`, installing exactly 1.26.0, so the two reachable stdlib vulns (GO-2026-4971, GO-2026-4602) failed all three Static Analysis Go jobs. |
| 26 | +- The `go` directive is a minimum language version: building/testing with a newer 1.26.x patch toolchain is fully compatible and does not affect the vendored source. |
| 27 | + |
| 28 | +Unknowns: |
| 29 | + |
| 30 | +- None. |
| 31 | + |
| 32 | +### Acceptance Criteria |
| 33 | + |
| 34 | +- go.mod files unchanged. |
| 35 | +- OSV-Scanner and govulncheck pass with the patched 1.26.x toolchain. |
| 36 | +- The waiver is documented in-line where it is configured, with the removal condition. |
| 37 | + |
| 38 | +## Analysis |
| 39 | + |
| 40 | +Sources checked: `.github/workflows/supply-chain-security.yml` (osv job), `.github/workflows/static-analysis.yml` (Go matrix setup-go), local `osv-scanner 2.3.8` and `govulncheck` runs, GitHub Code Scanning alert list (69 osv alerts). |
| 41 | + |
| 42 | +Risk accepted by user: anyone building the vendored source with a Go 1.26.0-1.26.3 toolchain (today: netdata) gets the vulnerable stdlib. This is netdata's pending toolchain bump; tracked as the removal condition below. |
| 43 | + |
| 44 | +## Pre-Implementation Gate |
| 45 | + |
| 46 | +Status: ready |
| 47 | + |
| 48 | +Problem / root-cause model: scanner findings are keyed to the go.mod directive (osv-scanner) or the installed toolchain (govulncheck), while the directive is pinned for downstream vendoring compatibility — the findings do not describe this repo's own CI/test artifacts when built with the patched toolchain. |
| 49 | + |
| 50 | +Evidence reviewed: see Analysis; local runs reproduced both the failure and the fix. |
| 51 | + |
| 52 | +Affected contracts and surfaces: CI workflows and scanner configs only; no library code, no go.mod. |
| 53 | + |
| 54 | +Existing patterns to reuse: `supply-chain-security.yml` already uses `go-version: "1.26.x"`; osv-scanner's documented per-lockfile-directory `osv-scanner.toml` with `GoVersionOverride`. |
| 55 | + |
| 56 | +Risk and blast radius: scanner-config only. The override masks stdlib findings for the 1.26.0-directive interpretation; mitigated by in-file comments stating the removal condition. |
| 57 | + |
| 58 | +Sensitive data handling plan: none involved; configs contain only version numbers and public CVE context. |
| 59 | + |
| 60 | +Implementation plan: (1) `osv-scanner.toml` with `GoVersionOverride = "1.26.4"` next to each go.mod; (2) `static-analysis.yml` setup-go switched from `go-version-file` to `go-version: "1.26.x"` with a comment. |
| 61 | + |
| 62 | +Validation plan: local `osv-scanner scan --recursive .` from repo root (config pickup), local `govulncheck` per module with 1.26.4, `actionlint`, then CI on push. |
| 63 | + |
| 64 | +Artifact impact plan: AGENTS.md unaffected; no runtime skills; specs unaffected (no product behavior); operator docs unaffected; SOW completed+committed together. |
| 65 | + |
| 66 | +Open-source reference evidence: osv-scanner documented configuration option `GoVersionOverride` (google/osv-scanner, verified against local v2.3.8 behavior). |
| 67 | + |
| 68 | +Open decisions: none — user decided the go.mod freeze and accepted the waiting period. |
| 69 | + |
| 70 | +## Implications And Decisions |
| 71 | + |
| 72 | +1. go.mod stays at `go 1.26.0` until netdata raises its Go toolchain (user decision). |
| 73 | +2. Scanner noise is suppressed via toolchain-version override, not per-CVE ignores (assistant choice: one knob, self-describing, removed together with the constraint). |
| 74 | + |
| 75 | +## Plan |
| 76 | + |
| 77 | +1. Add the three osv-scanner.toml files; switch Static Analysis toolchain; validate; commit; push. |
| 78 | + |
| 79 | +## Execution Log |
| 80 | + |
| 81 | +### 2026-06-10 |
| 82 | + |
| 83 | +- Added `osv-scanner.toml` (`GoVersionOverride = "1.26.4"` with removal-condition comment) to `src/go/`, `bench/drivers/go/`, `tests/fixtures/go/`. |
| 84 | +- `static-analysis.yml`: setup-go `go-version-file` → `go-version: "1.26.x"` with explanatory comment. |
| 85 | + |
| 86 | +## Validation |
| 87 | + |
| 88 | +Acceptance criteria evidence: |
| 89 | + |
| 90 | +- go.mod files untouched (`git diff` contains only workflow + toml changes). |
| 91 | +- Local `osv-scanner scan --recursive .` from repo root: "No issues found" (was 23 stdlib CVEs/module). |
| 92 | +- Local `govulncheck ./...` with go1.26.4 in `src/go` and `tests/fixtures/go`: "No vulnerabilities found." |
| 93 | +- `actionlint`: clean. |
| 94 | + |
| 95 | +Tests or equivalent validation: scanner runs above; CI verification on push (remote evidence recorded in Followup if divergent). |
| 96 | + |
| 97 | +Real-use evidence: the scanners themselves are the runnable path; both executed locally pre-push. |
| 98 | + |
| 99 | +Reviewer findings: external reviewers not run — scanner configuration change, validated by running the scanners. |
| 100 | + |
| 101 | +Same-failure scan: searched workflows for other `go-version-file` uses — none remain; coverage and supply-chain workflows already use `1.26.x`. |
| 102 | + |
| 103 | +Sensitive data gate: no secrets or sensitive data in configs, SOW, or comments. |
| 104 | + |
| 105 | +Artifact maintenance gate: |
| 106 | + |
| 107 | +- AGENTS.md: no update — no workflow-for-assistants change. |
| 108 | +- Runtime project skills: none exist. |
| 109 | +- Specs: no update — no product/protocol behavior change. |
| 110 | +- End-user/operator docs: no update — CI-internal configuration. |
| 111 | +- End-user/operator skills: no update — integrator skill unaffected. |
| 112 | +- SOW lifecycle: completed and committed with the change; removal condition tracked in Followup. |
| 113 | + |
| 114 | +Specs update: not needed (see gate). Project skills update: not needed. End-user/operator docs update: not needed. End-user/operator skills update: not needed. |
| 115 | + |
| 116 | +Lessons: |
| 117 | + |
| 118 | +- When a dependency floor is frozen by a downstream consumer, configure scanners to evaluate the toolchain actually used and document the waiver inline with its removal condition, instead of accumulating per-CVE ignores. |
| 119 | + |
| 120 | +Follow-up mapping: |
| 121 | + |
| 122 | +- When netdata raises its Go toolchain: bump the `go` directive in the three go.mod files, delete the three `osv-scanner.toml` files, and revert `static-analysis.yml` to `go-version-file`. The inline comments state this condition at every touch point. |
| 123 | + |
| 124 | +## Outcome |
| 125 | + |
| 126 | +CI scanner failures caused by the frozen `go 1.26.0` directive are resolved without touching go.mod: osv-scanner and govulncheck now evaluate the stdlib at the patched 1.26.x toolchain CI actually builds with. The 69 stdlib CVE alerts close on the next clean OSV upload. The waiver and its removal condition are documented inline. |
| 127 | + |
| 128 | +## Lessons Extracted |
| 129 | + |
| 130 | +See Lessons under Validation. |
| 131 | + |
| 132 | +## Followup |
| 133 | + |
| 134 | +- Remove the override (three `osv-scanner.toml` files) and restore `go-version-file` once netdata moves past Go 1.26.0 and the go.mod directives are bumped. |
| 135 | + |
| 136 | +## Regression Log |
| 137 | + |
| 138 | +None yet. |
| 139 | + |
| 140 | +Append regression entries here only after this SOW was completed or closed and later testing or use found broken behavior. Use a dated `## Regression - YYYY-MM-DD` heading at the end of the file. Never prepend regression content above the original SOW narrative. |
0 commit comments