Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Latest commit

 

History

History
History
112 lines (90 loc) · 3.72 KB

File metadata and controls

112 lines (90 loc) · 3.72 KB
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
# ==========================================
# 1. CADDY BUILD STAGE
# ==========================================
# FIXED: Upgraded from 2.11.3 to 2.11.4
FROM caddy:2.11.4-builder AS caddy-builder
# FIXED: Upgraded Go toolchain from 1.26.3 to 1.26.4
ENV GOTOOLCHAIN=go1.26.4
ENV CGO_ENABLED=0
# CVE-2026-46595, CVE-2026-39830–34, CVE-2026-42508 → x/crypto >= v0.52.0
# CVE-2026-39821 → x/net >= v0.55.0
# CVE-2026-34986 → go-jose/v3 >= v3.0.5 (v4 already at v4.1.4 via Caddy deps)
RUN xcaddy build \
--with github.com/mholt/caddy-l4@afd229714fb14a387f0736cab048afeb72b8946a \
--with github.com/go-jose/go-jose/v3@v3.0.5 \
--replace golang.org/x/crypto=golang.org/x/crypto@v0.52.0 \
--replace golang.org/x/net=golang.org/x/net@v0.55.0
# ==========================================
# 2. COREDNS BUILD STAGE
# ==========================================
FROM golang:1.26.4-alpine AS coredns-builder
WORKDIR /app
# Install build dependencies
RUN apk add --no-cache git make
# 1. Disable CGO to avoid native instruction mismatches
# 2. Set GOAMD64=v1 to use the most compatible instruction set (no AVX/AVX2)
ENV CGO_ENABLED=0
ENV GOAMD64=v1
# Clone and build CoreDNS with fanout plugin
# CVE-2026-40898 → Force upgrade transitive quic-go dependency to v0.59.1
RUN git clone https://github.com/coredns/coredns.git && \
cd coredns && \
git checkout v1.14.3 && \
go get golang.org/x/crypto@v0.52.0 golang.org/x/net@v0.55.0 github.com/quic-go/quic-go@v0.59.1 && \
go mod tidy && \
echo "fanout:github.com/networkservicemesh/fanout" >> plugin.cfg && \
make
# ==========================================
# 3. DOCKER CLI BUILD STAGE
# ==========================================
# FIXED: Upgraded Go version from 1.26.3 to 1.26.4
FROM golang:1.26.4-alpine AS docker-builder
RUN apk add --no-cache git make
RUN git clone --depth 1 --branch v27.5.1 https://github.com/docker/cli.git /go/src/github.com/docker/cli
WORKDIR /go/src/github.com/docker/cli
ENV CGO_ENABLED=0
RUN make binary && cp build/docker /usr/bin/docker
# ==========================================
# 4. WIREPORT BUILD STAGE
# ==========================================
# FIXED: Upgraded Go version from 1.26.3 to 1.26.4
FROM golang:1.26.4-alpine AS go-builder
WORKDIR /app
# Install build dependencies for SQLite
RUN apk add --no-cache gcc musl-dev
# Enable CGO for SQLite support
ENV CGO_ENABLED=1
ENV CGO_CFLAGS="-D_LARGEFILE64_SOURCE"
COPY ./app/ .
RUN go mod tidy && go get golang.org/x/crypto@v0.52.0 golang.org/x/net@v0.55.0
RUN go build -o wireport ./cmd/server/main.go
# ==========================================
# 5. FINAL RUNTIME STAGE
# ==========================================
FROM alpine:3.21.3
# Update base image with security patches and install only the minimal runtime
RUN apk --no-cache upgrade && \
apk add --no-cache --repository=http://dl-cdn.alpinelinux.org/alpine/edge/main \
"nghttp2>=1.68.1" \
"busybox>=1.37.0-r15" \
"libxml2>=2.13.9-r1" \
"libpcap>=1.10.6-r1" || apk add --no-cache busybox libxml2 && \
apk add --no-cache \
wireguard-tools \
iptables \
nano \
bind-tools \
tcpdump \
runit \
socat
# Copy clean binaries all generated uniformly from the secure Go toolchain
COPY --from=docker-builder /usr/bin/docker /usr/bin/docker
COPY --from=caddy-builder /usr/bin/caddy /usr/bin/caddy
COPY --from=coredns-builder /app/coredns/coredns /usr/bin/coredns
COPY --from=go-builder /app/wireport /usr/bin/wireport
VOLUME /app/wireport
COPY ./docker/fs/etc/service /etc/service
RUN mkdir -p /app/wireport/caddy/fs/data /app/wireport/caddy/fs/config /etc/coredns /etc/caddy /etc/service-disabled
COPY ./docker/fs/entry.sh /
RUN chmod +x /entry.sh
ENTRYPOINT ["/entry.sh"]
Morty Proxy This is a proxified and sanitized view of the page, visit original site.