fix: 安全加固(VUL-001~009)+ 构建版本注入 + 死代码清理 #2

Merged
sun merged 12 commits from develop into main 2026-08-27 11:01:48 +08:00
4 changed files with 31 additions and 2 deletions
Showing only changes of commit c00c46e7a1 - Show all commits
+9 -1
View File
@@ -7,7 +7,15 @@ RUN go mod download
COPY . . COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -o tts-api . # VERSION 由 CI/CD 传入,通常为 `git describe --tags --always --dirty` 的输出
# COMMIT 为 `git rev-parse --short HEAD`
# 本地默认 dev
ARG VERSION=dev
ARG COMMIT=dev
RUN CGO_ENABLED=0 GOOS=linux go build \
-ldflags "-X github.com/volcano-tts/tts-api/version.Version=${VERSION} \
-X github.com/volcano-tts/tts-api/version.Commit=${COMMIT}" \
-o tts-api .
FROM alpine:3.21 FROM alpine:3.21
+3 -1
View File
@@ -18,6 +18,7 @@ import (
"github.com/volcano-tts/tts-api/middleware" "github.com/volcano-tts/tts-api/middleware"
"github.com/volcano-tts/tts-api/setting" "github.com/volcano-tts/tts-api/setting"
"github.com/volcano-tts/tts-api/telemetry" "github.com/volcano-tts/tts-api/telemetry"
"github.com/volcano-tts/tts-api/version"
) )
var ( var (
@@ -229,7 +230,8 @@ func HealthHandler(w http.ResponseWriter, r *http.Request) {
resp := dto.HealthResponse{ resp := dto.HealthResponse{
Status: status, Status: status,
Service: "ByteDance TTS to OpenAI API Adapter", Service: "ByteDance TTS to OpenAI API Adapter",
Version: "2.0.0 (v3 API)", Version: version.Version,
Commit: version.Commit,
Uptime: fmt.Sprintf("%.0f seconds", time.Since(startTime).Seconds()), Uptime: fmt.Sprintf("%.0f seconds", time.Since(startTime).Seconds()),
StartTime: startTime.Format(time.RFC3339), StartTime: startTime.Format(time.RFC3339),
Memory: collectMemorySnapshot(), Memory: collectMemorySnapshot(),
+1
View File
@@ -7,6 +7,7 @@ type HealthResponse struct {
Status string `json:"status"` Status string `json:"status"`
Service string `json:"service"` Service string `json:"service"`
Version string `json:"version"` Version string `json:"version"`
Commit string `json:"commit"`
Uptime string `json:"uptime"` Uptime string `json:"uptime"`
StartTime string `json:"start_time"` StartTime string `json:"start_time"`
Memory map[string]interface{} `json:"memory"` Memory map[string]interface{} `json:"memory"`
+18
View File
@@ -0,0 +1,18 @@
// Package version 提供构建时注入的版本信息。
//
// Version 和 Commit 在编译时通过 -ldflags 注入:
//
// go build -ldflags "-X github.com/volcano-tts/tts-api/version.Version=$VERSION \
// -X github.com/volcano-tts/tts-api/version.Commit=$COMMIT"
//
// 开发时默认 "dev",CI/CD 时通常由 git describe 自动算出:
// VERSION=$(git describe --tags --always --dirty)
// COMMIT=$(git rev-parse --short HEAD)
//
// /health 端点会暴露这两个值,方便运维确认"跑的到底是哪个 commit"。
package version
var (
Version = "dev"
Commit = "dev"
)