ci: fix sonarcloud supply-chain vulnerabilities - #4631
Merged
Conversation
- Add --only-binary :all: to pip install in kurtosis smoke test to prevent execution of setup.py scripts from source distributions. - Use go install tool for govulncheck so versions resolve from the go.mod/go.sum lockfile instead of fetching unpinned transitive deps.
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #4631 +/- ##
==========================================
+ Coverage 58.16% 58.19% +0.02%
==========================================
Files 247 247
Lines 34043 34043
==========================================
+ Hits 19802 19811 +9
+ Misses 11768 11760 -8
+ Partials 2473 2472 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
OisinKyne
approved these changes
Aug 7, 2026
KaloyanTanev
added a commit
that referenced
this pull request
Aug 8, 2026
- Add --only-binary :all: to pip install in kurtosis smoke test to prevent execution of setup.py scripts from source distributions. - Use go install tool for govulncheck so versions resolve from the go.mod/go.sum lockfile instead of fetching unpinned transitive deps.
KaloyanTanev
added a commit
that referenced
this pull request
Aug 8, 2026
* docs: refresh stale architecture and structure docs (#4580) * docs: refresh stale architecture and structure docs Update docs/architecture.md and docs/structure.md to match the current implementation: fix component interfaces to match core/interfaces.go, remove the nonexistent Signer/remote-signer component, correct the BFT fault tolerance formula, document the consensus controller and priority protocol, replace outdated DutyDB/ParSigDB data models, refresh the validator API endpoint list, and add a duty lifecycle table and supporting components section. Update the project structure doc with current packages and CLI commands. category: docs ticket: none Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: align CLAUDE.md architecture summary with refreshed docs Mention the pluggable consensus controller, correct the Priority and peer discovery descriptions, and add the InclusionChecker. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Small rephrases * Add per-duty workflow * Simplify Charon cluster diagram; migrate core workflow to mermaid --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: kalo <24719519+KaloyanTanev@users.noreply.github.com> * Fix exchanger deadlock during partial signature exchange (#4590) * *: opt in for incomplete validator_keys (#4591) * Opt in for incomplete validator_keys * Strict unique validator keys * Other small improvements * build(deps): Bump the go-dependencies group with 3 updates (#4593) Bumps the go-dependencies group with 3 updates: [golang.org/x/sync](https://github.com/golang/sync), [golang.org/x/term](https://github.com/golang/term) and [golang.org/x/text](https://github.com/golang/text). Updates `golang.org/x/sync` from 0.21.0 to 0.22.0 - [Commits](golang/sync@v0.21.0...v0.22.0) Updates `golang.org/x/term` from 0.44.0 to 0.45.0 - [Commits](golang/term@v0.44.0...v0.45.0) Updates `golang.org/x/text` from 0.39.0 to 0.40.0 - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.39.0...v0.40.0) --- updated-dependencies: - dependency-name: golang.org/x/sync dependency-version: 0.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/term dependency-version: 0.45.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/text dependency-version: 0.40.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): Bump the docker-dependencies group across 2 directories with 1 update (#4594) Bumps the docker-dependencies group with 1 update in the / directory: golang. Bumps the docker-dependencies group with 1 update in the /testutil/promrated directory: golang. Updates `golang` from 1.26.4-trixie to 1.26.5-trixie Updates `golang` from 1.26.4-trixie to 1.26.5-trixie Updates `golang` from 1.26.4-alpine to 1.26.5-alpine Updates `golang` from 1.26.4-alpine to 1.26.5-alpine --- updated-dependencies: - dependency-name: golang dependency-version: 1.26.5-trixie dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-dependencies - dependency-name: golang dependency-version: 1.26.5-trixie dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-dependencies - dependency-name: golang dependency-version: 1.26.5-alpine dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-dependencies - dependency-name: golang dependency-version: 1.26.5-alpine dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): Bump the go-dependencies group with 3 updates (#4595) Bumps the go-dependencies group with 3 updates: [golang.org/x/crypto](https://github.com/golang/crypto), [golang.org/x/net](https://github.com/golang/net) and [golang.org/x/tools](https://github.com/golang/tools). Updates `golang.org/x/crypto` from 0.53.0 to 0.54.0 - [Commits](golang/crypto@v0.53.0...v0.54.0) Updates `golang.org/x/net` from 0.56.0 to 0.57.0 - [Commits](golang/net@v0.56.0...v0.57.0) Updates `golang.org/x/tools` from 0.47.0 to 0.48.0 - [Release notes](https://github.com/golang/tools/releases) - [Commits](golang/tools@v0.47.0...v0.48.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.54.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/net dependency-version: 0.57.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/tools dependency-version: 0.48.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Fix potential code injection (#4598) * *: fetch latest versions release notes (#4597) * Fetch latest versions on minor releases for compatibility matrix * Fix auth style * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: kalo <24719519+KaloyanTanev@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: kalo <24719519+KaloyanTanev@users.noreply.github.com> --------- Signed-off-by: kalo <24719519+KaloyanTanev@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * p2p: fix flaky TestWithReceiveTimeout on QUIC (#4606) The zero receive timeout makes the server close the stream almost immediately, racing the client's request write. On TCP the close is a graceful FIN, so the write always lands and the failure surfaces as an EOF on the response read. QUIC instead resets the stream, which can abort the write already in flight, failing with "write request: stream reset (remote)" before the read is ever reached. Accept either error on the QUIC iteration. The TCP iteration stays strict. category: test ticket: none * Increase sync message deadline to a slot duration (#4610) * build(deps): Bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#4608) Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.81.1 to 1.82.1. - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.81.1...v1.82.1) --- updated-dependencies: - dependency-name: google.golang.org/grpc dependency-version: 1.82.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): Bump github.com/google/cel-go from 0.28.1 to 0.29.0 (#4609) Bumps [github.com/google/cel-go](https://github.com/google/cel-go) from 0.28.1 to 0.29.0. - [Release notes](https://github.com/google/cel-go/releases) - [Commits](cel-expr/cel-go@v0.28.1...v0.29.0) --- updated-dependencies: - dependency-name: github.com/google/cel-go dependency-version: 0.29.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): Bump the go-dependencies group across 1 directory with 5 updates (#4607) Bumps the go-dependencies group with 4 updates in the / directory: [github.com/attestantio/go-builder-client](https://github.com/attestantio/go-builder-client), [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum), [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang) and [github.com/bufbuild/buf](https://github.com/bufbuild/buf). Updates `github.com/attestantio/go-builder-client` from 0.7.2 to 0.8.0 - [Changelog](https://github.com/attestantio/go-builder-client/blob/master/CHANGELOG.md) - [Commits](attestantio/go-builder-client@v0.7.2...v0.8.0) Updates `github.com/ethereum/go-ethereum` from 1.17.4 to 1.17.5 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.17.4...v1.17.5) Updates `github.com/golang/snappy` from 1.0.0 to 1.0.1-0.20260716114414-9ae09f520e93 - [Release notes](https://github.com/golang/snappy/releases) - [Commits](https://github.com/golang/snappy/commits) Updates `github.com/prometheus/client_golang` from 1.23.2 to 1.24.1 - [Release notes](https://github.com/prometheus/client_golang/releases) - [Changelog](https://github.com/prometheus/client_golang/blob/v1.24.1/CHANGELOG.md) - [Commits](prometheus/client_golang@v1.23.2...v1.24.1) Updates `github.com/bufbuild/buf` from 1.71.0 to 1.72.0 - [Release notes](https://github.com/bufbuild/buf/releases) - [Changelog](https://github.com/bufbuild/buf/blob/main/CHANGELOG.md) - [Commits](bufbuild/buf@v1.71.0...v1.72.0) --- updated-dependencies: - dependency-name: github.com/attestantio/go-builder-client dependency-version: 0.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/bufbuild/buf dependency-version: 1.72.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.17.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/golang/snappy dependency-version: 1.0.1-0.20260716114414-9ae09f520e93 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/prometheus/client_golang dependency-version: 1.24.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * *: harden partial signature exchange (#4599) Bind partial signatures received during the DKG lock-hash exchange to their authenticated sender: a peer may only contribute partial signatures under its own assigned share index. parsigex.handle now passes the authenticated sender to the verify function; the core workflow verifier ignores it, since those partial signatures are already verified cryptographically against the pubshare for the claimed share index. The DKG exchanger keys the binding on each peer's assigned share index via a peer map, so it stays correct when share indices are not contiguous with peer positions, such as after operators are removed. newExchanger validates its peer index and peer map up front and returns an error on a misconfigured map instead of silently timing out. category: bug ticket: none * core/priority: add leading slash to protocol ID (#4605) Normalise the priority protocol ID to /charon/priority/2.0.0, matching every other charon libp2p protocol. The wire format is unchanged, so the version stays at 2.0.0 and the old spelling is kept as a legacy alias so that patched and unpatched nodes interoperate. Nodes now offer both IDs when dialling, preferring the slash-prefixed one, and serve both via separate exact-match handler registrations. The two IDs share no common prefix, so registering them in a single RegisterHandler call would collapse protocolPrefix to the bare wildcard "*" and advertise that to peers via libp2p identify instead of the real protocol IDs. category: refactor ticket: none * core/priority: use stable sort for scored priorities (#4611) Replace slices.SortFunc with slices.SortStableFunc when ordering scored priorities so that equal-score priorities keep first-seen order, with messages processed in ascending peer ID order. Go's sort is unstable for slices longer than ~12 elements, so the equal-score order depended on the sort implementation and could diverge across versions and other implementations. Add a regression test with 24 priorities where tied pairs arrive out of score order. category: bug ticket: none * *: sync contributions per subcommittee (#4602) * Sync contributions per subcommittee * Gate behind info sync * Check for 0 value division * Add more tests * Optimise sync contribution fetching (#4615) * dkg: fail fast on peer restart or death during ceremonies (#4616) * harden dkg * dkg/sync: harden step tracking against invalid peers Only track sync steps of peers that passed request validation, so an invalid peer cannot influence step state or overwrite the recorded fatal error. Reword the restart error since not every step inconsistency is strictly a peer restart. * build(deps): Bump github.com/pion/stun/v3 from 3.1.2 to 3.1.5 (#4614) Bumps [github.com/pion/stun/v3](https://github.com/pion/stun) from 3.1.2 to 3.1.5. - [Release notes](https://github.com/pion/stun/releases) - [Commits](pion/stun@v3.1.2...v3.1.5) --- updated-dependencies: - dependency-name: github.com/pion/stun/v3 dependency-version: 3.1.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): Bump github.com/quic-go/webtransport-go (#4612) Bumps [github.com/quic-go/webtransport-go](https://github.com/quic-go/webtransport-go) from 0.10.0 to 0.11.1. - [Release notes](https://github.com/quic-go/webtransport-go/releases) - [Commits](quic-go/webtransport-go@v0.10.0...v0.11.1) --- updated-dependencies: - dependency-name: github.com/quic-go/webtransport-go dependency-version: 0.11.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Close streams on all SendReceive and Send paths (#4626) * Add 1MB limit to the peer info messages (#4625) * Fix proposer short second round (#4623) * core/qbft: prevent double PREPARE on equivocating leader (#4624) * Prevent double-PREPARE on equivocating leader PRE-PREPARE * Improve tests * Remove legacy unversioned attestations (#4621) * Reject lock with validator count mismatch with definition (#4620) * core/qbft: reject zero-value PRE-PREPARE from leader (#4619) * Reject zero-value PRE-PREPARE from leader * Avoid closing channel while QBFT goroutine is running * Fix flaky peer death DKG test (#4627) * core/consensus: fix qbft optimistic first qcommit (#4622) * Fix optimistic QBFT using qcommit[0] rather than verifying it includes the actual correct value * Use qCommitValue, rather than qcommit[0] in commit/decide * Thread decided round through Decide callback * Fix potential test flakiness * Improve qbft unit testing * Rotate PAT (#4596) * *: fix libp2p logger routing (#4629) * Fix libp2p logger routing * Avoid per-record lock in libp2p slog handler * core/qbft: preserve local value on comparison failure (#4628) * Preserve the already fetched value for comparing between the rounds * Fix clock in tests * ci: fix sonarcloud supply-chain vulnerabilities (#4631) - Add --only-binary :all: to pip install in kurtosis smoke test to prevent execution of setup.py scripts from source distributions. - Use go install tool for govulncheck so versions resolve from the go.mod/go.sum lockfile instead of fetching unpinned transitive deps. * build(deps): Bump the go-dependencies group across 1 directory with 7 updates (#4633) Bumps the go-dependencies group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/showwin/speedtest-go](https://github.com/showwin/speedtest-go) | `1.7.10` | `1.7.11` | | [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | | [go.opentelemetry.io/otel/exporters/otlp/otlptrace](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | | [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | | [go.opentelemetry.io/otel/exporters/stdout/stdouttrace](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | Updates `github.com/showwin/speedtest-go` from 1.7.10 to 1.7.11 - [Release notes](https://github.com/showwin/speedtest-go/releases) - [Changelog](https://github.com/showwin/speedtest-go/blob/master/docs/release.md) - [Commits](showwin/speedtest-go@v1.7.10...v1.7.11) Updates `go.opentelemetry.io/otel` from 1.44.0 to 1.45.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.44.0...v1.45.0) Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace` from 1.44.0 to 1.45.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.44.0...v1.45.0) Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc` from 1.44.0 to 1.45.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.44.0...v1.45.0) Updates `go.opentelemetry.io/otel/exporters/stdout/stdouttrace` from 1.44.0 to 1.45.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.44.0...v1.45.0) Updates `go.opentelemetry.io/otel/sdk` from 1.44.0 to 1.45.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.44.0...v1.45.0) Updates `go.opentelemetry.io/otel/trace` from 1.44.0 to 1.45.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.44.0...v1.45.0) --- updated-dependencies: - dependency-name: github.com/showwin/speedtest-go dependency-version: 1.7.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: go.opentelemetry.io/otel dependency-version: 1.45.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace dependency-version: 1.45.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc dependency-version: 1.45.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: go.opentelemetry.io/otel/exporters/stdout/stdouttrace dependency-version: 1.45.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: go.opentelemetry.io/otel/sdk dependency-version: 1.45.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: go.opentelemetry.io/otel/trace dependency-version: 1.45.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * app/peerinfo: add dv_type field to peerinfo protocol (#4632) * app/peerinfo: add dv_type field to peerinfo protocol Add a dv_type field to the PeerInfo protobuf message so DV client implementations can identify themselves. Charon sets this to "charon". Non-charon peers (e.g. Pluto) skip the SemVer compatibility check since the supported version list only applies to Charon releases. Empty dv_type (from older Charon nodes) defaults to "charon" for backwards compatibility. Also adds an app_peerinfo_dv_type Prometheus metric with {peer, dv_type} labels for dashboard visibility. category: feature ticket: none * docs: regenerate metrics reference for dv_type gauge * app/peerinfo: rename dv_type to dv_client --------- Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: kalo <24719519+KaloyanTanev@users.noreply.github.com> Co-authored-by: Andrei Smirnov <andrei@obol.tech> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Add
--only-binary :all:topip installin the kurtosis smoke test workflow to prevent execution ofsetup.pyscripts from source distributions (sonar rules S8541, S8544).Use
go install toolfor govulncheck so transitive dependency versions resolve from thego.mod/go.sumlockfile instead of being fetched unpinned (sonar rule S8545).category: fixbuild
ticket: none