PipeCD - Slimming the Codegen Image

Fixed a reverted attempt to move PipeCD's codegen Docker image to debian:bookworm-slim, clearing Snyk-flagged curl CVEs from the base image and cutting it from ~800MB to ~500MB without breaking protoc or mockgen.

PipeCD's codegen image (used by contributors to generate protobuf code and mocks) was built on golang:1.25.2, which pulled in curl-related CVEs flagged by Snyk. An earlier PR (#6402) switched it to debian:bookworm-slim, but it had to be reverted (#6404) because it broke two things:

  1. protoc could no longer find the standard google/protobuf/*.proto files.
  2. mockgen needs the go command at runtime, which the slim image didn't have.

I fixed both in a single Dockerfile change:

  • installed libprotobuf-dev to bring back the standard .proto files,
  • used a multi-stage build that copies the Go toolchain from golang:1.25.2 into the slim image, so mockgen keeps working,
  • kept the x86_64 and aarch64 protoc-gen-js binaries and the existing protoc plugins.

The image went from about 800MB to about 500MB. This is a development-tooling change only, with no effect on PipeCD users.

Before submitting, I checked that the image builds, that every binary and proto file is present, that protoc compiles a real proto file, and that the full codegen.sh script runs. A maintainer reviewed it and it was merged.

Links: PR #6461 • Issue #6429