[action] [PR:26676] fix: resolve April 2026 docker-ptf security vulnerabilities#26866
Open
mssonicbld wants to merge 1 commit intosonic-net:202511from
Open
[action] [PR:26676] fix: resolve April 2026 docker-ptf security vulnerabilities#26866mssonicbld wants to merge 1 commit intosonic-net:202511from
mssonicbld wants to merge 1 commit intosonic-net:202511from
Conversation
<!--
Please make sure you've read and understood our contributing guidelines:
https://github.com/Azure/SONiC/blob/gh-pages/CONTRIBUTING.md
** Make sure all your commits include a signature generated with `git commit -s` **
If this is a bug fix, make sure your description includes "fixes #xxxx", or
"closes #xxxx" or "resolves #xxxx"
Please provide the following information:
-->
#### Why I did it
Attempt to fix new docker-ptf security vulnerability as of 04/2026
This pull request updates the `dockers/docker-ptf/Dockerfile.j2` to incorporate several dependency upgrades and security improvements. The main focus is on updating Go and related dependencies to address vulnerabilities and ensure compatibility with the latest features and fixes.
Dependency and version updates:
* Upgraded the Go version used in the Docker image from `1.25.8` to `1.25.9` for improved stability and security.
* Updated the `go.opentelemetry.io/otel/sdk` dependency from version `v1.40.0` to `v1.43.0` for the `gnmic` build process.
* Added or updated the `github.com/go-jose/go-jose/v4` dependency to version `v4.1.4` in the build steps for `grpcurl`, `gnoic`, and `gnmic` to ensure consistent cryptography support. [[1]](diffhunk://#diff-bdead431cfeb50ac3debd09da54bbc77f0b1772edf769de0cd4e30538fd012e0R128-R135) [[2]](diffhunk://#diff-bdead431cfeb50ac3debd09da54bbc77f0b1772edf769de0cd4e30538fd012e0R411) [[3]](diffhunk://#diff-bdead431cfeb50ac3debd09da54bbc77f0b1772edf769de0cd4e30538fd012e0L423-R429)
* Added the latest versions of `github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream` and `github.com/aws/aws-sdk-go-v2/service/s3` as dependencies for the `gnmic` build.
Security improvements:
* Included a system package upgrade step to address vulnerabilities such as CVE-2026-33416 and CVE-2026-33636 (affecting `libpng16-16`), among others.
##### Work item tracking
- Microsoft ADO **(number only)**:
#### How I did it
#### How to verify it
<!--
If PR needs to be backported, then the PR must be tested against the base branch and the earliest backport release branch and provide tested image version on these two branches. For example, if the PR is requested for master, 202211 and 202012, then the requester needs to provide test results on master and 202012.
-->
#### Which release branch to backport (provide reason below if selected)
<!--
- Note we only backport fixes to a release branch, *not* features!
- Please also provide a reason for the backporting below.
- e.g.
- [x] 202006
-->
- [ ] 202305
- [ ] 202311
- [ ] 202405
- [ ] 202411
- [ ] 202505
- [ ] 202511
#### Tested branch (Please provide the tested image version)
<!--
- Please provide tested image version
- e.g.
- [x] 20201231.100
-->
- [ ] <!-- image version 1 -->
- [ ] <!-- image version 2 -->
#### Description for the changelog
<!--
Write a short (one line) summary that describes the changes in this
pull request for inclusion in the changelog:
-->
<!--
Ensure to add label/tag for the feature raised. example - PR#2174 under sonic-utilities repo. where, Generic Config and Update feature has been labelled as GCU.
-->
#### Link to config_db schema for YANG module changes
<!--
Provide a link to config_db schema for the table for which YANG model
is defined
Link should point to correct section on https://github.com/Azure/sonic-buildimage/blob/master/src/sonic-yang-models/doc/Configuration.md
-->
Signed-off-by: Sonic Build Admin <sonicbld@microsoft.com>
#### A picture of a cute animal (not mandatory but encouraged)
Collaborator
Author
|
Original PR: #26676 |
8 tasks
Collaborator
Author
|
/azp run Azure.sonic-buildimage |
|
Azure Pipelines successfully started running 1 pipeline(s). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why I did it
Attempt to fix new docker-ptf security vulnerability as of 04/2026
This pull request updates the
dockers/docker-ptf/Dockerfile.j2to incorporate several dependency upgrades and security improvements. The main focus is on updating Go and related dependencies to address vulnerabilities and ensure compatibility with the latest features and fixes.Dependency and version updates:
1.25.8to1.25.9for improved stability and security.go.opentelemetry.io/otel/sdkdependency from versionv1.40.0tov1.43.0for thegnmicbuild process.github.com/go-jose/go-jose/v4dependency to versionv4.1.4in the build steps forgrpcurl,gnoic, andgnmicto ensure consistent cryptography support. [1] [2] [3]github.com/aws/aws-sdk-go-v2/aws/protocol/eventstreamandgithub.com/aws/aws-sdk-go-v2/service/s3as dependencies for thegnmicbuild.Security improvements:
libpng16-16), among others.Work item tracking
How I did it
How to verify it
Which release branch to backport (provide reason below if selected)
Tested branch (Please provide the tested image version)
Description for the changelog
Link to config_db schema for YANG module changes
Signed-off-by: Sonic Build Admin sonicbld@microsoft.com
A picture of a cute animal (not mandatory but encouraged)