Wire cdxgen/govulncheck/scancode/toolchain-cache env vars into compose - #306
Merged
Merged
Conversation
This was referenced Sep 3, 2026
haksungjang
force-pushed
the
compose-env-wiring/cdxgen-toolchain-cache
branch
from
September 3, 2026 05:18
c6a6dd0 to
a1ef5ec
Compare
10 vars documented in .env.example (cdxgen image/spec selection,
govulncheck subprocess limits, scancode enable flag, shared
per-language toolchain cache size/idle/roots) were never referenced in
x-backend-env, so setting them in .env had no effect on the running
container. Adds them with defaults matching core/config.py exactly.
EXTRACTCODE_LIBARCHIVE_PATH / TYPECODE_LIBMAGIC_PATH were also flagged
by the audit but are deliberately excluded: Dockerfile.worker bakes
them as image ENV pointing scancode's ctypes loader at the arm64
system libarchive/libmagic, and an ${VAR:-} compose line would shadow
that with an empty string and crash scancode on import.
Part of the compose env-var wiring audit.
haksungjang
force-pushed
the
compose-env-wiring/cdxgen-toolchain-cache
branch
from
September 3, 2026 06:59
a1ef5ec to
5b561e4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.env.example(cdxgen image/spec selection, govulncheck subprocess limits, scancode enable flag, shared per-language toolchain cache size/idle/roots) were never referenced inx-backend-env, so setting them in.envhad no effect on the running container.core/config.pyexactly.Two vars deliberately excluded
The audit also flagged
EXTRACTCODE_LIBARCHIVE_PATH/TYPECODE_LIBMAGIC_PATH, but they are NOT wired here:Dockerfile.workerbakes them as imageENVpointing scancode's ctypes loader at the arm64 system libarchive/libmagic (integrations/_subprocess_env.py's comment: "MUST be forwarded or scancode crashes at import on arm64 withundefined symbol: archive_read_new"). Adding an${VAR:-}compose line would shadow that image default with an empty string and break scancode, which is worse than the gap it would "fix". Left unreferenced on purpose.Context
Part of the same compose env-var wiring audit as #300/#301/#303/#304.
Test plan