-
Notifications
You must be signed in to change notification settings - Fork 2.4k
Add CI image step to pre-fetch Go modules instead of vendoring #84186
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
kabirbhartiRH
wants to merge
1
commit into
openshift:main
Choose a base branch
from
kabirbhartiRH:main
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+63
−1
Open
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: openshift/release
Length of output: 248
🏁 Script executed:
Repository: openshift/release
Length of output: 50373
🌐 Web query:
Go command GONOSUMDB wildcard checksum database go.sum behavior official documentation💡 Result:
In the Go programming language, the GONOSUMDB environment variable is used to define a list of module path prefixes that should be excluded from checksum database verification [1][2]. When a module's path matches a pattern listed in GONOSUMDB, the go command skips querying the checksum database for that module [3][4]. Key behaviors regarding GONOSUMDB and wildcards: 1. Pattern Matching: The GONOSUMDB variable accepts a comma-separated list of glob patterns [1][2]. The matching logic follows the syntax of Go's path.Match function [1]. 2. Skipping Database Lookups: If a module path matches a pattern in the list, the go command treats it as exempt from checksum database verification [3][5]. Instead of relying on the checksum database, the go command calculates the checksum locally from the downloaded source and records it in the go.sum file [6]. 3. Security Purpose: This mechanism is primarily designed to prevent private module paths from being sent to public checksum databases (such as sum.golang.org), which would otherwise leak potentially sensitive import paths [2][7]. 4. Configuration: You can set multiple patterns using commas, for example: GONOSUMDB="github.com/mycompany/,example.com/private/" [2][8]. 5. Precedence: When a module is excluded via GONOSUMDB, the go command does not stop the build, but it assumes responsibility for verifying the module's integrity locally [6]. If a module is not excluded and the checksum database cannot verify it, the build will fail [2][6]. For more information, you can refer to the official Go documentation on private modules and the Go module reference [9][1].
Citations:
🏁 Script executed:
Repository: openshift/release
Length of output: 1057
Do not disable checksum-database verification for all modules.
GONOSUMDB="*"makesgo mod downloadskip the public checksum database for every module. ScopeGONOSUMDBto private module-path prefixes, if required, so public modules retain checksum-database verification.🤖 Prompt for AI Agents
Source: MCP tools