fix(node-go): install golangci-lint directly, bypass install.sh checksum bug
The official install.sh (master branch) fails checksum verification because it matches the .tar.gz line against the .sbom.json checksum (the tarball filename is a prefix of the sbom filename). The downloaded tarball is NOT corrupt - its real sha256 matches the checksums file - install.sh just picks the wrong line. Replace install.sh with a direct tarball download + extract, reusing the existing go_arch variable. Consistent with how Go itself is installed in this Dockerfile (no checksum verification either). Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
+6
-4
@@ -24,10 +24,12 @@ RUN set -eux; \
|
||||
rm -rf /usr/local/go; \
|
||||
tar -C /usr/local -xzf /tmp/go.tgz; \
|
||||
rm -f /tmp/go.tgz; \
|
||||
curl -fsSL -o /tmp/golangci-lint-install.sh \
|
||||
"https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh"; \
|
||||
sh /tmp/golangci-lint-install.sh -b /usr/local/bin "${GOLANGCI_LINT_VERSION}"; \
|
||||
rm -f /tmp/golangci-lint-install.sh; \
|
||||
gcl_ver="${GOLANGCI_LINT_VERSION#v}"; \
|
||||
curl -fsSL -o /tmp/gcl.tgz \
|
||||
"https://github.com/golangci/golangci-lint/releases/download/${GOLANGCI_LINT_VERSION}/golangci-lint-${gcl_ver}-${go_arch}.tar.gz"; \
|
||||
tar -C /tmp -xzf /tmp/gcl.tgz; \
|
||||
install -m 0755 "/tmp/golangci-lint-${gcl_ver}-${go_arch}/golangci-lint" /usr/local/bin/golangci-lint; \
|
||||
rm -rf /tmp/gcl.tgz "/tmp/golangci-lint-${gcl_ver}-${go_arch}"; \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
Reference in New Issue
Block a user