Skip to content

Support alpine for CloudRun#70

Merged
maxday merged 2 commits into
mainfrom
maxday/build-alpine
Jul 5, 2022
Merged

Support alpine for CloudRun#70
maxday merged 2 commits into
mainfrom
maxday/build-alpine

Conversation

@maxday

@maxday maxday commented Jul 4, 2022

Copy link
Copy Markdown
Contributor

This PR adds alpine support for CloudRun

Note: In a next PR, the 3 Dockerfiles could be better organized (classic, alpine, race) since they share some common code

@maxday
maxday requested a review from a team as a code owner July 4, 2022 22:05

# keep the smallest possible docker image
FROM scratch
COPY --from=compresser /extensions/datadog_extension.zip /

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the difference between the alpine binary, and the non-alpine binary?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alpine is not using the standard libC but the musl version, that’s why the binary is not working on alpine (ref : https://alpinelinux.org/posts/Alpine-Linux-has-switched-to-musl-libc.html)

@maxday
maxday merged commit 547ab57 into main Jul 5, 2022
@maxday
maxday deleted the maxday/build-alpine branch July 5, 2022 19:14
jchrostek-dd added a commit that referenced this pull request Apr 15, 2026
## Summary

Resolves all **24 open Dependabot security alerts** (2 critical, 6 high,
14 medium, 2 low) across three ecosystems by updating vulnerable
dependencies in test infrastructure.

**Note:** All affected dependencies are in test infrastructure
(`integration-tests/`, `local_tests/`), not the production Rust
extension (`bottlecap/`).

## Changes

### npm (`integration-tests/`)
- **axios** `^1.6.7` → `^1.15.0` — fixes SSRF bypass via NO_PROXY
hostname normalization (CVE-2025-62718, critical)

### Go (`local_tests/golang/`)
- **golang.org/x/net** `v0.2.0` → `v0.52.0` — fixes 8 alerts: HTTP/2
rapid reset, uncontrolled resource consumption, XSS, IPv6 zone ID proxy
bypass, excessive memory growth, stream cancellation, improper text
rendering
- **google.golang.org/grpc** `v1.50.1` → `v1.80.0` — fixes 2 alerts:
authorization bypass via missing leading slash (CVE-2026-33186,
critical), HTTP/2 rapid reset
- **google.golang.org/protobuf** `v1.28.1` → `v1.36.11` — fixes infinite
loop in protojson.Unmarshal
- **github.com/golang/glog** `v1.0.0` → `v1.2.5` — fixes insecure
temporary file usage

### Python (`local_tests/serverless-init/`)
- **Flask** `2.1.2` → `3.1.3` — fixes session cookie disclosure, missing
Vary:Cookie header
- **Werkzeug** `2.2.2` → `3.1.8` — fixes 9 alerts: debugger RCE,
safe_join Windows device name bypasses, multipart form DoS, resource
exhaustion, nameless cookie bypass

## Reviewer Notes

⚠️ **Go minimum version**: The `go` directive in
`local_tests/golang/go.mod` was auto-upgraded from `go 1.22` to `go
1.25.0` (required by `golang.org/x/net v0.52.0`). This only affects the
test Lambda function, not CI build toolchains for the main extension.

⚠️ **Flask/Werkzeug major version jump**: Flask 2.x → 3.x and Werkzeug
2.x → 3.x are major version bumps. The test app (`app.py`) uses minimal
Flask APIs and was reviewed for compatibility. However, `ddtrace==1.4.1`
compatibility with Flask 3.x should be verified in CI.

## Alert Breakdown

| Severity | Count | Alerts |
|----------|-------|--------|
| Critical | 2 | #128 (axios SSRF), #104 (gRPC auth bypass) |
| High | 6 | #52, #43, #40, #38, #37, #20 |
| Medium | 14 | #88, #74, #73, #70, #68, #65, #60, #59, #53, #51, #49,
#45, #41, #36 |
| Low | 2 | #89, #39 |

Co-authored-by: Claude Opus 4.6 (1M context) <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants