I made PipeCD’s codegen image more secure. I moved it from golang:1.25.2 to the smaller debian:bookworm-slim base, while keeping the full toolchain that tool/codegen/codegen.sh needs.
The result was a safer and smaller image (about 800MB → 500MB), with protobuf generation and mockgen workflows still working.
Key implementation points:
- a multi-stage build that copies only the needed Go runtime pieces,
- installed the protobuf headers and standard
.protodependencies, - kept cross-architecture support and existing plugins working.
I submitted the patch with proof that it worked (build checks, checks that the binaries exist, and compile path checks), and it was reviewed and merged.
Links: PR #6461 • Issue #6429