PipeCD's codegen image (used by contributors to generate protobuf code and mocks) was built on golang:1.25.2, which pulled in curl-related CVEs flagged by Snyk. An earlier PR (#6402) switched it to debian:bookworm-slim, but it had to be reverted (#6404) because it broke two things:
protoccould no longer find the standardgoogle/protobuf/*.protofiles.mockgenneeds thegocommand at runtime, which the slim image didn't have.
I fixed both in a single Dockerfile change:
- installed
libprotobuf-devto bring back the standard.protofiles, - used a multi-stage build that copies the Go toolchain from
golang:1.25.2into the slim image, so mockgen keeps working, - kept the x86_64 and aarch64
protoc-gen-jsbinaries and the existing protoc plugins.
The image went from about 800MB to about 500MB. This is a development-tooling change only, with no effect on PipeCD users.
Before submitting, I checked that the image builds, that every binary and proto file is present, that protoc compiles a real proto file, and that the full codegen.sh script runs. A maintainer reviewed it and it was merged.
Links: PR #6461 • Issue #6429