Repository navigation
lightwalletd: pull master for three dependency CVE fixes - #78
Conversation
aa9acac2f9 Merge pull request #599 from zcash/fix/crane-mirror-creds d79cd11005 Merge pull request #601 from zcash/dependabot/go_modules/google.golang.org/grpc-1.83.1 1cb42c5166 build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 51aba684c2 Merge pull request #600 from zecrocks/be/cve-dep-bumps 0e398d79cf docker: build in a stage, ship on debian:13-slim 5044f4b924 deps: bump golang.org/x/crypto for CVE-2026-56854 96fe9a145e deps: bump golang.org/x/net for CVE-2026-46600 a3cb34c5e6 deps: bump golang.org/x/text for CVE-2026-56852 77df3be44e CI: fix the zodlinc mirror step, which has never succeeded git-subtree-dir: lightwalletd git-subtree-split: aa9acac2f95e596f0edf9a3750ec7751d943e614
…update/lightwalletd-2026-09-15
Upstream cut v0.5.4 before shipping fixes for CVE-2026-56854 (x/crypto), CVE-2026-46600 (x/net) and CVE-2026-56852 (x/text), and has not cut another tag. Take master at aa9acac2f9 and note the un-pin so the next watch run does not read it as drift. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
🟡 Changes recommended
The Docker runtime still runs as root; configure it to use the restricted lightwalletd user.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Updates vendored lightwalletd with post-v0.5.4 CVE fixes, dependency upgrades, and packaging/CI changes.
Changes:
- Upgrades vulnerable Go dependencies and gRPC.
- Adds a staged Debian runtime image.
- Updates subtree metadata, changelog, and image mirroring.
File summaries
| File | Summary |
|---|---|
SUBTREES.md |
Documents the temporary unpinned revision. |
lightwalletd/go.sum |
Refreshes dependency checksums. |
lightwalletd/go.mod |
Updates Go dependencies. |
lightwalletd/Dockerfile |
Adds a staged Debian runtime image. |
lightwalletd/.github/workflows/CI.yaml |
Updates authenticated image mirroring. |
CHANGELOG.md |
Records security and packaging updates. |
Review details
- Files reviewed: 5/6 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "$LWD_USER" | ||
| "$LWD_USER" \ | ||
| && mkdir -p /var/lib/lightwalletd/db \ | ||
| && chown "$LWD_UID:$LWD_UID" /var/lib/lightwalletd/db |
There was a problem hiding this comment.
Correct about the vendored file, but it is not something this PR introduced and not something Zero ships.
Pre-existing upstream. The v0.5.4 Dockerfile we were already pinned to has no USER either. Upstream's 0e398d79cf changed the base image and moved the chown; root-by-default is unchanged across the pull.
Zero does not build this Dockerfile. images.yml builds docker/lightwalletd/Dockerfile, which we own precisely because upstream's cannot satisfy target: runtime (single stage, lightwalletd_base) and ships the whole Go toolchain in the final layer. Ours ends with:
WORKDIR /srv/lightwalletd
USER lightwalletdSo the hardening you are asking for is already in the image that actually runs, on the same uid 2002 and datadir.
Not fixing it here on purpose. Patching a vendored file we never build would add permanent [zero] divergence for no runtime benefit, which is the thing MAINTENANCE.md exists to prevent. The gap is real upstream though (creating uid 2002, chowning the datadir to it, then never switching is setup that only makes sense with a USER line), so it belongs in a PR to zcash/lightwalletd, not in this CVE pull.
Resolves the expected CHANGELOG conflict: #78 (lightwalletd CVEs) and this branch each opened an `## Unreleased` section. Both sets of entries are kept, folded into one section under Security / Changed / Removed. No content dropped from either side. SUBTREES.md auto-merged; the lightwalletd un-pin note and the zaino 0.10.0 pin note are both present. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Pulls
lightwalletd/fromv0.5.4(09593edbee) toup-lightwalletd/masterataa9acac2f9, nine commits.Motivated by the 2026-09-15 upstream watch, where this was the clearest action on the board for the second week running.
Why now
Upstream cut
v0.5.4and then shipped three dependency CVE fixes after the tag, and has not cut another. Staying pinned means sitting on known CVEs in a network-facing Go service.5044f4b924golang.org/x/cryptofor CVE-2026-5685496fe9a145egolang.org/x/netfor CVE-2026-46600a3cb34c5e6golang.org/x/textfor CVE-2026-56852Also included:
1cb42c5166grpc 1.82.1 to 1.83.1,0e398d79cfstaged Docker build shipping ondebian:13-slim, and a CI mirror-step fix.Conflicts
None. Our only diverged file in this subtree (
README.md) is not in the incoming set. Four files changed:go.mod,go.sum,Dockerfile, and a workflow.The tag pin
This deliberately un-pins from
v0.5.4until upstream cutsv0.5.5. That is recorded inSUBTREES.mdwith the reason, so the next watch run reads it as a decision rather than drift. The alternative, carrying the three dependency commits as[upstream-pending]to keep the tag pin exact, buys nothing here: there is no divergence to protect and the whole range is dependency and packaging work.Testing
go test -count=1 ./...green across all seven packages with test files.Note
This branch and #(zaino) both add an
## UnreleasedCHANGELOG section, so whichever merges second will conflict there trivially.🤖 Generated with Claude Code