fix(oauth2-proxy.github.io): update Go build dependency - #14531
Open
brandon-julio-t wants to merge 1 commit into
Open
brandon-julio-t wants to merge 1 commit into
brandon-julio-t wants to merge 1 commit into
Conversation
OAuth2 Proxy v7.15.5 upgrades its release toolchain to Go 1.26.8, but Pantry's published Linux bottles still embed Go 1.26.0. The old 1.22.4 build dependency allows automatic toolchain selection to satisfy only the module's 1.26.0 minimum, missing the intended runtime patch level. Select Go ~1.26.8 so rebuilt packages include that runtime patch level and can pick up subsequent patches in the same Go release line. Release: https://github.com/oauth2-proxy/oauth2-proxy/releases/tag/v7.15.5
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
1.22.4to~1.26.8.go 1.26.0; automatic toolchain selection satisfies that minimum without ensuring the release's newer patch toolchain. Selecting the compiler in the recipe preserves the release's intended runtime patch level and permits subsequent Go 1.26 patch updates.Please rebuild the existing v7.15.5 bottles when landing this change. A recipe update alone cannot change bottles already on the CDN.
Searched open and closed
pkgxdevissues/PRs and discussions for OAuth2 Proxy before submitting; the only package-specific result was the original addition, #7319. This follows the targeted Go dependency updates in #12190.Reproduce the published-bottle mismatch
Prerequisites: Bash, curl, tar with xz support, sha256sum, and Go on PATH. This inspects embedded build metadata; it does not execute either downloaded binary, so both architectures can be checked on one host.
Observed on re-download during this review:
Expected: rebuilt v7.15.5 bottles embed Go 1.26.8 or a later Go 1.26 patch, matching the release's toolchain baseline. These hashes identify the observed archives; replacement bottles should change them.
The concrete defect established here is the compiler/runtime patch-level mismatch. The recipe's old compiler constraint plus the module's
go 1.26.0minimum explains how automatic toolchain selection can produce it; historical publisher build logs were not inspected. This report does not establish exploitability or attribute every advisory in the application release notes to this compiler mismatch.Reproduce the patched build
With pkgx installed and GitHub API access configured as described in the repository README, fetch this PR into a fresh checkout:
The last command must run on the build host's architecture. The local Linux aarch64 build reported
oauth2-proxy 2df061b-dirty (built with go1.26.8). The application version text is existing recipe behavior; the relevant before/after evidence is the embedded Go version. The commands above express the same isolated-prefix build procedure with portable paths.Acceptance: platform build/test/audit succeeds, then replacement v7.15.5 bottles are published and their embedded Go version is rechecked. Merging the recipe alone does not complete the CDN remediation.
AI Intent
Risk Assessment
Rollback Plan
Validation
Local validation on Linux aarch64 with pkgx 2.11.0 / Brewkit 1.23.2:
bk build oauth2-proxy.github.io@7.15.5— passed with the edited recipe and an isolated package prefix; resulting binary reportsbuilt with go1.26.8.bk test oauth2-proxy.github.io@7.15.5— passed.bk audit oauth2-proxy.github.io@7.15.5— passed./pingreturned 200;/oauth2/authwithout a session returned 401. No external identity-provider login was tested.git diff --check— passed.go1.26.0viago version <binary>.Brewkit emitted a nonfatal
patchelfwarning about a missing.dynamicsection; both the existing and rebuilt ARM64 binaries are statically linked. Build, test, and audit all exited 0. The existing recipe's Git-derived application version string remains unchanged in behavior.CI checks expected: Pantry's platform build/audit/test matrix. macOS and native x86-64 execution were not tested locally.
Internal/Public Boundary Check