PipeCD - Codegen Image Security Hardening

Made PipeCD's codegen Docker image more secure: fixed CVEs (known security flaws), cut the image size from 800MB to 500MB, and switched to a debian:bookworm-slim base while keeping everything working.

I made PipeCD’s codegen image more secure. I moved it from golang:1.25.2 to the smaller debian:bookworm-slim base, while keeping the full toolchain that tool/codegen/codegen.sh needs.

The result was a safer and smaller image (about 800MB → 500MB), with protobuf generation and mockgen workflows still working.

Key implementation points:

  • a multi-stage build that copies only the needed Go runtime pieces,
  • installed the protobuf headers and standard .proto dependencies,
  • kept cross-architecture support and existing plugins working.

I submitted the patch with proof that it worked (build checks, checks that the binaries exist, and compile path checks), and it was reviewed and merged.

Links: PR #6461 • Issue #6429