Skip to content

Commit 430a0fd

Browse files
committed
Scan Go stdlib at the patched 1.26.x toolchain
The go directive in the three go.mod files must stay 1.26.0 until netdata, which vendors this source, raises its own Go toolchain. osv-scanner keys stdlib CVEs to that directive (69 code scanning alerts, red Supply Chain Security) and the Static Analysis workflow installed exactly go 1.26.0 via go-version-file, so govulncheck reported reachable stdlib vulnerabilities fixed in later patches. Add osv-scanner.toml with GoVersionOverride next to each go.mod and switch the Static Analysis setup-go to the latest 1.26.x patch release. CI and developers build with the patched stdlib; go.mod is untouched so the vendored source still accepts netdata's toolchain. Inline comments state the removal condition. Tracked as SOW-0019.
1 parent 4d81eb8 commit 430a0fd

5 files changed

Lines changed: 163 additions & 1 deletion

File tree

Lines changed: 140 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,140 @@
1+
# SOW-0019 - Go stdlib CVE scanner policy while go.mod is pinned for netdata
2+
3+
## Status
4+
5+
Status: completed
6+
7+
Sub-state: scanner configuration shipped; constraint recorded; committed with this SOW.
8+
9+
## Requirements
10+
11+
### Purpose
12+
13+
Keep CI green and GitHub Code Scanning meaningful while the Go module directive must stay at `go 1.26.0` for netdata vendoring compatibility.
14+
15+
### User Request
16+
17+
"do not change go.mod because netdata is 1.26 and when vendored it breaks netdata. We wait for netdata to increase it. Do the others." — 2026-06-10. Followed by "ci OSV fails".
18+
19+
### Assistant Understanding
20+
21+
Facts:
22+
23+
- The three Go modules (`src/go`, `bench/drivers/go`, `tests/fixtures/go`) declare `go 1.26.0`. Raising the directive would make the vendored source require a newer toolchain than netdata currently builds with.
24+
- osv-scanner keys Go stdlib vulnerabilities to the `go.mod` directive: 23 CVEs × 3 modules = 69 GitHub Code Scanning alerts and a red Supply Chain Security workflow.
25+
- govulncheck scans with the installed toolchain's stdlib; CI's `setup-go` used `go-version-file: go.mod`, installing exactly 1.26.0, so the two reachable stdlib vulns (GO-2026-4971, GO-2026-4602) failed all three Static Analysis Go jobs.
26+
- The `go` directive is a minimum language version: building/testing with a newer 1.26.x patch toolchain is fully compatible and does not affect the vendored source.
27+
28+
Unknowns:
29+
30+
- None.
31+
32+
### Acceptance Criteria
33+
34+
- go.mod files unchanged.
35+
- OSV-Scanner and govulncheck pass with the patched 1.26.x toolchain.
36+
- The waiver is documented in-line where it is configured, with the removal condition.
37+
38+
## Analysis
39+
40+
Sources checked: `.github/workflows/supply-chain-security.yml` (osv job), `.github/workflows/static-analysis.yml` (Go matrix setup-go), local `osv-scanner 2.3.8` and `govulncheck` runs, GitHub Code Scanning alert list (69 osv alerts).
41+
42+
Risk accepted by user: anyone building the vendored source with a Go 1.26.0-1.26.3 toolchain (today: netdata) gets the vulnerable stdlib. This is netdata's pending toolchain bump; tracked as the removal condition below.
43+
44+
## Pre-Implementation Gate
45+
46+
Status: ready
47+
48+
Problem / root-cause model: scanner findings are keyed to the go.mod directive (osv-scanner) or the installed toolchain (govulncheck), while the directive is pinned for downstream vendoring compatibility — the findings do not describe this repo's own CI/test artifacts when built with the patched toolchain.
49+
50+
Evidence reviewed: see Analysis; local runs reproduced both the failure and the fix.
51+
52+
Affected contracts and surfaces: CI workflows and scanner configs only; no library code, no go.mod.
53+
54+
Existing patterns to reuse: `supply-chain-security.yml` already uses `go-version: "1.26.x"`; osv-scanner's documented per-lockfile-directory `osv-scanner.toml` with `GoVersionOverride`.
55+
56+
Risk and blast radius: scanner-config only. The override masks stdlib findings for the 1.26.0-directive interpretation; mitigated by in-file comments stating the removal condition.
57+
58+
Sensitive data handling plan: none involved; configs contain only version numbers and public CVE context.
59+
60+
Implementation plan: (1) `osv-scanner.toml` with `GoVersionOverride = "1.26.4"` next to each go.mod; (2) `static-analysis.yml` setup-go switched from `go-version-file` to `go-version: "1.26.x"` with a comment.
61+
62+
Validation plan: local `osv-scanner scan --recursive .` from repo root (config pickup), local `govulncheck` per module with 1.26.4, `actionlint`, then CI on push.
63+
64+
Artifact impact plan: AGENTS.md unaffected; no runtime skills; specs unaffected (no product behavior); operator docs unaffected; SOW completed+committed together.
65+
66+
Open-source reference evidence: osv-scanner documented configuration option `GoVersionOverride` (google/osv-scanner, verified against local v2.3.8 behavior).
67+
68+
Open decisions: none — user decided the go.mod freeze and accepted the waiting period.
69+
70+
## Implications And Decisions
71+
72+
1. go.mod stays at `go 1.26.0` until netdata raises its Go toolchain (user decision).
73+
2. Scanner noise is suppressed via toolchain-version override, not per-CVE ignores (assistant choice: one knob, self-describing, removed together with the constraint).
74+
75+
## Plan
76+
77+
1. Add the three osv-scanner.toml files; switch Static Analysis toolchain; validate; commit; push.
78+
79+
## Execution Log
80+
81+
### 2026-06-10
82+
83+
- Added `osv-scanner.toml` (`GoVersionOverride = "1.26.4"` with removal-condition comment) to `src/go/`, `bench/drivers/go/`, `tests/fixtures/go/`.
84+
- `static-analysis.yml`: setup-go `go-version-file` → `go-version: "1.26.x"` with explanatory comment.
85+
86+
## Validation
87+
88+
Acceptance criteria evidence:
89+
90+
- go.mod files untouched (`git diff` contains only workflow + toml changes).
91+
- Local `osv-scanner scan --recursive .` from repo root: "No issues found" (was 23 stdlib CVEs/module).
92+
- Local `govulncheck ./...` with go1.26.4 in `src/go` and `tests/fixtures/go`: "No vulnerabilities found."
93+
- `actionlint`: clean.
94+
95+
Tests or equivalent validation: scanner runs above; CI verification on push (remote evidence recorded in Followup if divergent).
96+
97+
Real-use evidence: the scanners themselves are the runnable path; both executed locally pre-push.
98+
99+
Reviewer findings: external reviewers not run — scanner configuration change, validated by running the scanners.
100+
101+
Same-failure scan: searched workflows for other `go-version-file` uses — none remain; coverage and supply-chain workflows already use `1.26.x`.
102+
103+
Sensitive data gate: no secrets or sensitive data in configs, SOW, or comments.
104+
105+
Artifact maintenance gate:
106+
107+
- AGENTS.md: no update — no workflow-for-assistants change.
108+
- Runtime project skills: none exist.
109+
- Specs: no update — no product/protocol behavior change.
110+
- End-user/operator docs: no update — CI-internal configuration.
111+
- End-user/operator skills: no update — integrator skill unaffected.
112+
- SOW lifecycle: completed and committed with the change; removal condition tracked in Followup.
113+
114+
Specs update: not needed (see gate). Project skills update: not needed. End-user/operator docs update: not needed. End-user/operator skills update: not needed.
115+
116+
Lessons:
117+
118+
- When a dependency floor is frozen by a downstream consumer, configure scanners to evaluate the toolchain actually used and document the waiver inline with its removal condition, instead of accumulating per-CVE ignores.
119+
120+
Follow-up mapping:
121+
122+
- When netdata raises its Go toolchain: bump the `go` directive in the three go.mod files, delete the three `osv-scanner.toml` files, and revert `static-analysis.yml` to `go-version-file`. The inline comments state this condition at every touch point.
123+
124+
## Outcome
125+
126+
CI scanner failures caused by the frozen `go 1.26.0` directive are resolved without touching go.mod: osv-scanner and govulncheck now evaluate the stdlib at the patched 1.26.x toolchain CI actually builds with. The 69 stdlib CVE alerts close on the next clean OSV upload. The waiver and its removal condition are documented inline.
127+
128+
## Lessons Extracted
129+
130+
See Lessons under Validation.
131+
132+
## Followup
133+
134+
- Remove the override (three `osv-scanner.toml` files) and restore `go-version-file` once netdata moves past Go 1.26.0 and the go.mod directives are bumped.
135+
136+
## Regression Log
137+
138+
None yet.
139+
140+
Append regression entries here only after this SOW was completed or closed and later testing or use found broken behavior. Use a dated `## Regression - YYYY-MM-DD` heading at the end of the file. Never prepend regression content above the original SOW narrative.

‎.github/workflows/static-analysis.yml‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -135,7 +135,11 @@ jobs:
135135
- name: Set up Go
136136
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
137137
with:
138-
go-version-file: ${{ matrix.module }}/go.mod
138+
# Latest 1.26 patch toolchain, NOT go-version-file: the go.mod
139+
# directive must stay 1.26.0 until netdata (which vendors this
140+
# source) raises its Go toolchain, but govulncheck must scan the
141+
# stdlib at the patched version CI actually builds with.
142+
go-version: "1.26.x"
139143
cache: false
140144

141145
- name: Install Go analysis tools

‎bench/drivers/go/osv-scanner.toml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
# CI/dev toolchains build with the latest Go 1.26.x patch release. The go
2+
# directive in go.mod must stay 1.26.0 until netdata (which vendors this
3+
# source) raises its own Go toolchain; bumping it would break netdata builds.
4+
# This override scans the stdlib at the toolchain version actually used.
5+
# Remove when netdata moves past Go 1.26.0 and go.mod is bumped.
6+
GoVersionOverride = "1.26.4"

‎src/go/osv-scanner.toml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
# CI/dev toolchains build with the latest Go 1.26.x patch release. The go
2+
# directive in go.mod must stay 1.26.0 until netdata (which vendors this
3+
# source) raises its own Go toolchain; bumping it would break netdata builds.
4+
# This override scans the stdlib at the toolchain version actually used.
5+
# Remove when netdata moves past Go 1.26.0 and go.mod is bumped.
6+
GoVersionOverride = "1.26.4"

‎tests/fixtures/go/osv-scanner.toml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
# CI/dev toolchains build with the latest Go 1.26.x patch release. The go
2+
# directive in go.mod must stay 1.26.0 until netdata (which vendors this
3+
# source) raises its own Go toolchain; bumping it would break netdata builds.
4+
# This override scans the stdlib at the toolchain version actually used.
5+
# Remove when netdata moves past Go 1.26.0 and go.mod is bumped.
6+
GoVersionOverride = "1.26.4"

0 commit comments

Comments
 (0)