chore: replace aws-sdk-go v1 with aws-sdk-go-v2 - #7
Merged
Merged
Conversation
aws-sdk-go v1 is flagged for CVE-2020-8911 and CVE-2020-8912, which live in the s3crypto package. No v1 release fixes them, so scanners flag every binary that embeds this module even though goofys never imports s3crypto. Port the S3 and GCS backends, the credential providers and the V2 signer to aws-sdk-go-v2 so the module drops out entirely. Request and response checksums are set to WhenRequired rather than the v2 default of WhenSupported, which would add CRC32 to every request and break S3-compatible stores. The GCS resumable upload path moves from mutating request objects to smithy middleware, since v2 has no request object to mutate.
Egr711
approved these changes
Sep 11, 2026
quannhoang
approved these changes
Sep 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Ports the S3 and GCS backends, the credential providers and the V2 signer from
aws-sdk-gov1 toaws-sdk-go-v2, removing the v1 module from the dependency graph.Why
close https://github.com/parallelworks/core/issues/19809
aws-sdk-gov1 is flagged for CVE-2020-8911 and CVE-2020-8912. Both live inservice/s3/s3crypto, which goofys never imports, and no v1 release fixes them. Scanners match at module level, so every binary embedding goofys is flagged, including all sixpwCLI binaries in the ACTIVATE ingress image. Dropping the module is the only way to clear it. Tracked as CORE-7555.Notable decisions
RequestChecksumCalculationandResponseChecksumValidationare set toWhenRequired. The v2 default ofWhenSupportedadds CRC32 to every request and breaks S3-compatible stores.The GCS resumable upload path moved from mutating request objects to smithy middleware, since v2 has no request object to mutate. The deserialize middleware still translates Google's 308 into a successful
PutObjectOutput.release.ymlnow uploads to an existing release instead of failing when the tag already has one.Testing
Unit tests added for the ported surfaces: error mapping, V2 signatures, multipart, delete MD5, bucket detection and region, SSE-over-TLS, and GCS resumable.
Verified live on two ACTIVATE clusters with the rebuilt CLI, confirmed by binary hash, against a real AWS bucket and a real GCS bucket mounted through the interop endpoint. Both passed: small and 50MB writes with md5 verified byte-identical, ranged reads, file and directory renames, 50MB rename with md5 rechecked, listing 1200 objects past the pagination boundary, single and bulk deletes, and missing-file mapping to ENOENT.
Not covered: credential rotation, non-AWS S3 endpoints, and
UploadPartCopyabove the 5GB copy limit.