Skip to content

fix: rebuild CUDA image to patch CVEs, migrate to multi-stage build - #14

Merged
dvcdsys merged 1 commit into
mainfrom
fix/cuda-image-vulnerabilities
Mar 24, 2026
Merged

fix: rebuild CUDA image to patch CVEs, migrate to multi-stage build#14
dvcdsys merged 1 commit into
mainfrom
fix/cuda-image-vulnerabilities

Conversation

@dvcdsys

@dvcdsys dvcdsys commented Mar 24, 2026

Copy link
Copy Markdown
Owner
  • Migrate Dockerfile.cuda from single-stage Ubuntu 22.04 to multi-stage Ubuntu 24.04 (devel builder + runtime final), reducing image from 8.6GB to ~5GB and CVEs from 80 (6 HIGH) to 9 (0 HIGH)
  • Adopt industry-standard CUDA tag convention: :cu130, :version-cu130
  • Auto-detect VERSION from latest git tag in Makefile
  • Update README with new CUDA tags and driver requirements (>= 550)
  • Update docker-compose.cuda.yml and portainer-stack-cuda.yml

What

Why

How

Type of change

  • Bug fix
  • New feature
  • Refactor
  • Docs
  • CI / infra

Checklist

  • Tested against a running API server
  • go vet ./... passes (CLI changes)
  • pytest tests/ passes (API changes)
  • No secrets or API keys committed

- Migrate Dockerfile.cuda from single-stage Ubuntu 22.04 to multi-stage
  Ubuntu 24.04 (devel builder + runtime final), reducing image from
  8.6GB to ~5GB and CVEs from 80 (6 HIGH) to 9 (0 HIGH)
- Adopt industry-standard CUDA tag convention: :cu130, :version-cu130
- Auto-detect VERSION from latest git tag in Makefile
- Update README with new CUDA tags and driver requirements (>= 550)
- Update docker-compose.cuda.yml and portainer-stack-cuda.yml

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cursor

cursor Bot commented Mar 24, 2026

Copy link
Copy Markdown

You have used all of your free Bugbot PR reviews.

To receive reviews on all of your PRs, visit the Cursor dashboard to activate Pro and start your 14-day free trial.

@dvcdsys
dvcdsys merged commit ca88a8f into main Mar 24, 2026
4 checks passed
@dvcdsys
dvcdsys deleted the fix/cuda-image-vulnerabilities branch March 24, 2026 11:24
dvcdsys added a commit that referenced this pull request May 14, 2026
Two related migration-safety fixes:

1. migrateSplitWorkspaceRepos used to commit the DB tx first and
   then rename clone dirs — a kill -9 in that window left old
   {workspace_repos.id} dirs orphaned and forced a re-clone. Now
   the rename runs BEFORE the transaction and an error aborts the
   migration (leaves workspace_repos in place so the next run
   retries). Counters for renamed / skipped_missing_source /
   skipped_target_exists / failed are logged on completion.

2. Add schema_migrations(version, name, applied_at). Open() reads
   MAX(version) and skips already-applied migrations. Existing
   prod DBs bootstrap by detecting which legacy tables are present.

3. Migration test suite expanded with subtests covering partial
   rename, pre-existing target, missing source dir, duplicate
   project_path rows, and idempotent re-runs.

Resolves Fix #3, #7, #14.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
dvcdsys added a commit that referenced this pull request May 14, 2026
Two related migration-safety fixes:

1. migrateSplitWorkspaceRepos used to commit the DB tx first and
   then rename clone dirs — a kill -9 in that window left old
   {workspace_repos.id} dirs orphaned and forced a re-clone. Now
   the rename runs BEFORE the transaction and an error aborts the
   migration (leaves workspace_repos in place so the next run
   retries). Counters for renamed / skipped_missing_source /
   skipped_target_exists / failed are logged on completion.

2. Add schema_migrations(version, name, applied_at). Open() reads
   MAX(version) and skips already-applied migrations. Existing
   prod DBs bootstrap by detecting which legacy tables are present.

3. Migration test suite expanded with subtests covering partial
   rename, pre-existing target, missing source dir, duplicate
   project_path rows, and idempotent re-runs.

Resolves Fix #3, #7, #14.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant