Skip to content

chore: Pin build tooling - #1682

Open
dervoeti wants to merge 11 commits into
mainfrom
chore/pin-build-tooling
Open

dervoeti wants to merge 11 commits into
mainfrom
chore/pin-build-tooling

Conversation

@dervoeti

Copy link
Copy Markdown
Member

Description

Some build tooling is invoked without a pinned version, so it could change between two builds of the same image version. This could cause builds to break and also introduce malicious packages dependencies in the supply chain.
This PR pins or restricts it.

Maven:
mvn versions:set invokes the plugin by prefix. Unless the project POM pins it, Maven resolves the latest release on every build. It is now pinned to 2.22.0, the version that resolves today.

npm global installs:
The global installs (like cdxgen or yarn) pin the top-level version, but their transitive dependencies float.
I decided against vendoring lockfiles for these to keep it simple (we can do that once we have a good solution for Renovate updates) and just hardened the installation used two flags instead:

  • --ignore-scripts: install scripts of the package and its dependencies no longer run. They are a common way npm malware executes.
  • --before=<now - 7 days>: npm only resolves versions, including transitive ones, that were published at least 7 days ago, so a freshly published malicious version is not picked up before it is taken down.

As a consequence, a pinned version must be at least 7 days old, otherwise the install fails.

Superset npm:
nvm install --latest-npm installed whatever npm version was newest at build time. npm is now pinned via npm-version in boil-config.toml (10.9.9 for both versions, the newest release compatible with both Node versions) and installed with the same flags.

Definition of Done Checklist

Note

Not all of these items are applicable to all PRs, the author should update this template to only leave the boxes in that are relevant.

Please make sure all these things are done and tick the boxes

  • Changes are OpenShift compatible
  • All added packages (via microdnf or otherwise) have a comment on why they are added
  • Things not downloaded from Red Hat repositories should be mirrored in the Stackable repository and downloaded from there
  • All packages should have (if available) signatures/hashes verified
  • Add an entry to the CHANGELOG.md file
  • Integration tests ran successfully
TIP: Running integration tests with a new product image

The image can be built and uploaded to the kind cluster with the following commands:

boil build <IMAGE> --image-version <RELEASE_VERSION> --strip-architecture --load
kind load docker-image <MANIFEST_URI> --name=<name-of-your-test-cluster>

See the output of boil to retrieve the image manifest URI for <MANIFEST_URI>.

@dervoeti
dervoeti force-pushed the chore/pin-build-tooling branch from 94a25c1 to 13e189e Compare September 30, 2026 09:14
@dervoeti dervoeti self-assigned this Sep 30, 2026
@dervoeti
dervoeti force-pushed the chore/pin-build-tooling branch from 13e189e to 66608ac Compare September 30, 2026 13:07
@dervoeti dervoeti moved this to Development: Waiting for Review in Stackable Engineering Sep 30, 2026
@StefanFl
StefanFl self-requested a review October 8, 2026 08:42
@StefanFl

StefanFl commented Oct 8, 2026

Copy link
Copy Markdown
Member

It looks good to me, but Claude found a few things to consider:

Suggested changes

  1. java-devel/Dockerfile:75,78,81: remove the quotes from the three ENV *_VERSION="…" values.
    The org regex manager (_VERSION=(?<currentValue>.+?)\s) would capture "2.22.0" with the quotes, which isn't a valid Maven version.
    stackable-devel/Dockerfile uses unquoted values. Caveat: Renovate hasn't committed to this repo since 2022, so the annotation probably does nothing either way. MAVEN_VERSION on line 15 has the same issue already.
  2. superset/boil-config.toml (6.1.0 block): give the real reason in the comment, i.e. superset-frontend engines.npm is ^10.8.1. The npm 12/Node 22.22.2 reasoning doesn't explain why npm 11.x wasn't picked.
  3. PR description: also mention the help/dependency plugin pins (the changelog already does).

Not blockers, possible follow-ups (same class of problem)

  • superset/Dockerfile:145 and testing-tools/Dockerfile:86: pip install --upgrade pip is unpinned.
  • airflow/Dockerfile:174: uv tool install hatch is unpinned.

@dervoeti

dervoeti commented Oct 8, 2026

Copy link
Copy Markdown
Member Author

It looks good to me, but Claude found a few things to consider:

Suggested changes

  1. java-devel/Dockerfile:75,78,81: remove the quotes from the three ENV *_VERSION="…" values.
    The org regex manager (_VERSION=(?<currentValue>.+?)\s) would capture "2.22.0" with the quotes, which isn't a valid Maven version.
    stackable-devel/Dockerfile uses unquoted values. Caveat: Renovate hasn't committed to this repo since 2022, so the annotation probably does nothing either way. MAVEN_VERSION on line 15 has the same issue already.
  2. superset/boil-config.toml (6.1.0 block): give the real reason in the comment, i.e. superset-frontend engines.npm is ^10.8.1. The npm 12/Node 22.22.2 reasoning doesn't explain why npm 11.x wasn't picked.
  3. PR description: also mention the help/dependency plugin pins (the changelog already does).

Not blockers, possible follow-ups (same class of problem)

  • superset/Dockerfile:145 and testing-tools/Dockerfile:86: pip install --upgrade pip is unpinned.
  • airflow/Dockerfile:174: uv tool install hatch is unpinned.

Valid points, I addressed the first two in 2511e5a
PR description update isn't necessary I think.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Development: In Review

Development

Successfully merging this pull request may close these issues.

2 participants