Skip to content

docker alpine: update base images to Alpine 3.24 (2.7.x) - #2299

Merged
drakkan merged 1 commit into
drakkan:2.7.xfrom
evoludigit:2.7.x-alpine3.24
Sep 26, 2026
Merged

drakkan merged 1 commit into
drakkan:2.7.xfrom
evoludigit:2.7.x-alpine3.24

Conversation

@evoludigit

Copy link
Copy Markdown

Checklist for Pull Requests


Problem

On the 2.7.x branch, Dockerfile.alpine builds from golang:1.26-alpine3.22. That tag is no longer updated on Docker Hub (last push 2026-06-03) and is stuck at Go 1.26.4. As a result every 2.7.x-alpine / v2.7.6-alpine image, including the 2026-09-24 rebuild, ships a binary linked with Go 1.26.4, while Go 1.26.8 is available.

Trivy flags 9 HIGH Go stdlib CVEs on drakkan/sftpgo:2.7.x-alpine because of this (CVE-2026-33818, CVE-2026-39821, CVE-2026-39822, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862).

Change

Use Alpine 3.24 for both stages, as main already does:

  • golang:1.26-alpine3.22 → golang:1.26-alpine3.24 (currently Go 1.26.8)
  • alpine:3.22 → alpine:3.24

Both lines move together because the binary is built with CGO: the builder and the final image should share the same musl (3.22 ships musl 1.2.5, 3.24 ships 1.2.6).

Testing

Built locally from 2.7.x with this change:

  • sftpgo -v → SFTPGo 2.7.6-…, binary linked with go1.26.8
  • container starts with the default config: /healthz returns 200, web admin setup page returns 200, SFTP banner SSH-2.0-SFTPGo_2.7.6
  • startup logs identical to the current 2.7.x-alpine image
  • Trivy (CRITICAL/HIGH, fixed only): 10 findings → 1. The remaining one is CVE-2026-84445 in google.golang.org/grpc v1.84.0, which needs a dependency update and is out of scope here.

Thanks for maintaining the 2.7.x branch!

golang:1.26-alpine3.22 is no longer updated upstream (last push
2026-06-03) and is stuck at Go 1.26.4, so every 2.7.x alpine build
links an outdated Go toolchain. Use Alpine 3.24 for both the builder
and the final image, as on main: builder and runtime must share the
same musl version since the binary is built with CGO.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@evoludigit
evoludigit requested a review from drakkan as a code owner September 25, 2026 21:10
@CLAassistant

CLAassistant commented Sep 25, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@drakkan
drakkan merged commit 182d590 into drakkan:2.7.x Sep 26, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants