Skip to content

Bump github.com/containerd/containerd from 1.7.33 to 1.7.35 - #515

Merged
LouisLotter merged 3 commits into
stackstate-7.78.2from
dependabot/go_modules/github.com/containerd/containerd-1.7.35
Sep 15, 2026
Merged

LouisLotter merged 3 commits into
stackstate-7.78.2from
dependabot/go_modules/github.com/containerd/containerd-1.7.35

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown

Update containerd to 1.7.35 for CVE-2026-53495 and reconcile the Go/Bazel dependency manifests. Unrelated E2E upgrades are excluded.

Rebased onto the current stackstate-7.78.2 base, preserving all three signed commits. The dependency changes are unchanged; the updated base includes integrations 7.78.2-6. Prior-head independent source review found no reproducible source blocker, and all three manual CI workflows passed, including amd64/arm64 binaries, DEBs and image validation. Fresh PR checks are required on the rebased head before merge.

Tracking: https://github.com/StackVista/cve-reporter/issues/29

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 10, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/containerd/containerd-1.7.35 branch from 7d6cb8c to 5d02d81 Compare September 10, 2026 06:15
@ai-collaboration-app

Copy link
Copy Markdown

Independent review at 5d02d81d013cbf4e01be874a15ee5dd045f42052: source and CI correction required. OTel status's go mod tidy -diff fails on an unused google.golang.org/genproto checksum while the default module passes. Reconcile the OTel manifest changes with the repository sync/tidy procedure. Workspace and standalone tests pass; containerd release graphs and the cancellation regression are correct, but packaged binaries remain unverified.

All three exact-head workflows still fail; empty registry credentials block prerequisites. Restore the authorized CI credential path and reconcile the held writer claim before source work, then obtain green checks, architecture-specific artifact evidence and independent review of the changed head. Reviewer and exact tidy diff; coordination. Critical curl work and #511's human disposition remain separate.

@ai-collaboration-app

Copy link
Copy Markdown

Recovery checkpoint 2026-09-15: signed head 536f2eef02ee5bcaeb2942d193f43b8b63c54b8f removes the accepted unused OTel genproto checksum. The replacement Pod retained no prior local changes/logs/processes; none of the interrupted checks is counted as passing. Refreshed default c0bda9dbc8d278a9d8a1ae88517aefa6d4574b43 changes only the unrelated integrations pin since the candidate base.

Full repository Bazel sync/tidy is running; focused validation and production artifact evidence remain pending. Python 3.12 DDA setup succeeds; pinned golangci-lint installation is underway. New PR runs: lint 34933126075, binary 34933125774, DEB 34933125714, all initially queued at this exact head. No old run was rerun and no manual dispatch/publication initiated.

Coordination: https://github.com/StackVista/cve-reporter/issues/29. Curl/Python/#511 remain deferred. Final independent review remains required.

@ai-collaboration-app

Copy link
Copy Markdown

Source correction complete at signed head d3ee2125353a725a227053ab0dc3b18542b6a8c4 (signature verified; existing history preserved). Final diff versus the PR base: go.mod, go.sum, deps/go.MODULE.bazel only. Removed unrelated E2E upgrades that caused 319-file workspace propagation; restored the OTel graph and tidied its sums.

Validation completed: repository Bazel mod tidy → Go work sync → all-module tidy → Bazel mod tidy → Gazelle; all 186 workspace modules subsequently pass go mod tidy -diff; focused containerd package tests and OTel workspace/standalone tests pass. Upstream TestDrainExecSyncIO passes all four cases. amd64/arm64 workspace and standalone graphs select containerd v1.7.35. Gazelle warns about missing inherited dyninst fixtures. Focused golangci-lint v2.9.0 fails on the same unused logExtractionError helper reproduced on current default c0bda9dbc8d278a9d8a1ae88517aefa6d4574b43.

Final-head automatic runs are terminal cancelled: lint 34934247095, binary 34934247145, DEB 34934247098. They were cancelled while queued to prevent their shared dependency-cache publication prerequisite. Earlier checkpoint runs 34933126075, 34933125774, 34933125714 were also cancelled; their roll-up checks fail closed. No old Dependabot runs were retried. Local branded production build is in progress in the existing amd64 builder, pinned to sha256:dc780241316f6e41d8b6e283564d37679e91faada41c4b279d3b8d141aed29db; no candidate binary/DEB/image readiness is yet claimed.

Coordination: https://github.com/StackVista/cve-reporter/issues/29. Final independent review remains required; curl/Python/#511 and delivery scan are unchanged/outside scope.

@ai-collaboration-app

Copy link
Copy Markdown

Local amd64 production agent build succeeded from signed head d3ee2125353a725a227053ab0dc3b18542b6a8c4, using the repository branding and rtloader build in the pinned existing CI builder. Runtime agent version succeeds and reports commit d3ee212535, Agent 3.78.2, Go 1.26.6. Binary metadata confirms github.com/containerd/containerd v1.7.35 and API v1.9.0, GOARCH=amd64.

Agent binary SHA-256: f79183645c98820c6d96becf97d40f0a24f146f6bac019a2d8b15fb7387c2abe. This is a local production binary, not a DEB or published/runtime image. Cluster-agent compilation and the local DEB attempt remain pending. Arm64 production/runtime evidence and image scanners remain absent; no scan has been started. Source/test and cancelled-CI evidence remains in the previous checkpoint. Independent review is still required.

@ai-collaboration-app

Copy link
Copy Markdown

Bounded correction complete at signed head d3ee2125353a725a227053ab0dc3b18542b6a8c4; prior history preserved. Final diff: go.mod, go.sum, deps/go.MODULE.bazel. OTel/E2E manifest drift is reconciled without retaining unrelated E2E upgrades.

Passed: full repository Bazel sync/tidy/Gazelle; subsequent tidy-diff checks for all 186 workspace modules; containerd package tests; OTel workspace and standalone tests; all four upstream cancellation regression cases; amd64/arm64 workspace and standalone graphs selecting containerd 1.7.35. Focused lint fails on the unchanged unused logExtractionError helper, reproduced on current default. Gazelle reports inherited missing dyninst fixtures.

Local artifacts from this head:

Artifact Result / SHA-256
amd64 production agent Built and runtime passed; f79183645c98820c6d96becf97d40f0a24f146f6bac019a2d8b15fb7387c2abe
amd64 production cluster-agent Built and runtime passed; 51905080c45f8616b40a01ba2ea8f7fe636d263d77d8a6ecdb7d7bd9c7e28c40
amd64 DEB stackstate-agent_3.78.2.git.172.d3ee212-1_amd64.deb Full Omnibus command exited 0, health/stripping/assembly passed, unsigned; e6adb890185ad6cc80997a4e4e1b847a9c77fd7da1eb073fde7721cad4d5173c
arm64 cluster-agent Production-tag CGO cross-build passed; AArch64 ELF, not run natively; 18542fcd4193b910ace74ead8977f350367036a29546d54647709c7bbbe78480

The stripped agent extracted from the DEB has SHA-256 2e3ec2fd4f1b9ee42589f7878c34d3218281a10b79890e1f3c534f48392d2298, embeds containerd 1.7.35 / API 1.9.0, and runs on BCI Micro base sha256:3e35921219f3156fe67d59c17db0d85b2afa22e706585f214d80dc773b83cba3 with the extracted payload bind-mounted. This is payload runtime evidence, not a completed candidate image. The existing amd64 builder was pinned to sha256:dc780241316f6e41d8b6e283564d37679e91faada41c4b279d3b8d141aed29db.

Remaining blockers: image export failed twice on Docker's same content-writer lock (moby/1/z2eqc0qfjubxaejvxxnssc2rh); no candidate image digest exists. All Dockerfile steps completed. The one retry followed inactive/reclaimable-cache evidence; no daemon/shared settings were changed. Native arm64 agent/DEB/runtime evidence remains missing. Trivy vulnerability, separate all-severity secrets, and Grype evidence remain absent; no scan was started under this recovery scope.

Final-head runs are terminal cancelled, zero artifacts: lint 34934247095, binary 34934247145, DEB 34934247098. Cancelled while queued to prevent dependency-cache publication. Earlier checkpoint runs 34933126075, 34933125774, 34933125714 were also cancelled; their roll-ups fail closed. Old Dependabot failures were not rerun; their secret-boundary diagnosis is unchanged.

Specific next action: independent review of this exact head, plus an approved native amd64/arm64 validation environment. Existing lint-and-unit-tests.yml, build-binaries.yml, and build-deb.yml support workflow_dispatch with no inputs, ref dependabot/go_modules/github.com/containerd/containerd-1.7.35 (verify it still resolves to the SHA above). These paths skip push-only product publication but can publish dependency-cache images, so dispatch needs separate approval of that prerequisite or an approved nonpublishing path. Computed cache tags: godeps-amd64-07858241e1fb0a85 and godeps-arm64-b331d9a9412c0c6c in quay.io/stackstate/stackstate-agent-godeps-cache. Do not treat these as published artifacts.

Coordination: https://github.com/StackVista/cve-reporter/issues/29; prior body update verified. Supervisor handoff: source progress is pushed; remaining environment/publication-boundary decisions warrant To triage, not In review. Curl/Python/#511 remain held; verified scan identity and unavailable Elasticsearch coverage gap are unchanged. No merge, publication, deployment, new scan, or exception decision occurred. No readiness or closure claim.

dependabot Bot and others added 3 commits September 15, 2026 10:50
Bumps [github.com/containerd/containerd](https://github.com/containerd/containerd) from 1.7.33 to 1.7.35.
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v1.7.33...v1.7.35)

---
updated-dependencies:
- dependency-name: github.com/containerd/containerd
  dependency-version: 1.7.35
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Full Bazel sync/tidy/Gazelle completed; all 186 workspace modules pass tidy -diff. Restore OTel graph requirements and remove unused checksums. Keep containerd release dependencies, remove unrelated E2E dependency increases that propagated through the workspace. Production artifact validation remains pending.
@LouisLotter
LouisLotter force-pushed the dependabot/go_modules/github.com/containerd/containerd-1.7.35 branch from d3ee212 to 0ef66af Compare September 15, 2026 08:51
@LouisParkin
LouisParkin requested a balanced review from Copilot September 15, 2026 12:21

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The security dependency update affects cross-platform container integrations and still requires fresh CI validation on the rebased head.

Pull request overview

Updates containerd to 1.7.35 to address CVE-2026-53495 and synchronizes Go/Bazel dependency metadata.

Changes:

  • Upgrades containerd and its API module.
  • Reconciles transitive Go dependencies and checksums.
  • Exposes the Prometheus repository to Bazel.
File summaries
File Description
go.mod Updates containerd and reconciles transitive versions.
go.sum Updates dependency checksums.
deps/go.MODULE.bazel Adds the required Prometheus Bazel repository.
Review details
  • Files reviewed: 2/3 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@LouisParkin LouisParkin left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 0ef66af48b6793c640dfc0af56d98a2f453c9279 against stackstate-7.78.2: no blocking findings. The earlier OTel tidy and CI blockers are resolved on this head.

Checked the upstream security fix, dependency graph, Go/Bazel reconciliation, and the agent’s containerd consumers. The additional dependency changes reconcile existing workspace/test requirements; the compatibility replacements for cgroups/runtime-spec remain intact.

Validation:

  • Local containerd utility, container check, and workload metadata collector tests pass with Go 1.26.6. Standalone OTel status go mod tidy -diff passes. Workspace and standalone resolution select containerd 1.7.35/API 1.9.0 for both architectures.
  • All three current-head PR workflows pass, including module tidiness, branded/unbranded tests, native binaries, DEBs, branding checks, and image smoke tests.
  • Independently inspected both DEBs from run 34949251810: both agent binaries embed containerd 1.7.35/API 1.9.0 and identify merge commit c50e919bd7, whose parents are this PR head and base c0bda9dbc8.

Image vulnerability scans are report-only; this is not a clean-image or deployment claim. Signing/publication correctly remain skipped on PR runs. This library update does not upgrade the monitored nodes’ containerd daemon.

@LouisLotter
LouisLotter added this pull request to the merge queue Sep 15, 2026
Merged via the queue into stackstate-7.78.2 with commit 78b0a7e Sep 15, 2026
57 of 59 checks passed
@LouisLotter
LouisLotter deleted the dependabot/go_modules/github.com/containerd/containerd-1.7.35 branch September 15, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants