CI - Build & Test is failing on main as of 84a884e (run 32909072296, 2026-08-25T23:03:53Z). The previous commit ae1e632 was green, and nothing in #1881 touched dependencies: the advisory was published the same day.
Your code is affected by 1 vulnerability
GO-2026-6253
Fixed in: github.com/moby/go-archive@v0.3.0
Why p0
This is not a single red run. Every PR branches from main and runs the same govulncheck ./..., so every open and future PR inherits the same failure until this lands. It blocks the merge gate repo-wide, and it does it in the security job, which is exactly the check nobody should be tempted to wave through.
The fix is a version bump to an already-published fixed version, so the cost of clearing it is near zero and the cost of leaving it is every merge in the repo.
Detail
github.com/moby/go-archive reaches the module graph through testcontainers, via internal/database/postgres/testhelpers and internal/config/store_postgres.go:968. It is symbol-reachable, which is why source-mode govulncheck exits 3 rather than reporting it as an unused require.
Fix
Bump github.com/moby/go-archive to v0.3.0. This is a go.work monorepo with 6 modules (., pkg, providers/{aws,azure,gcp}, tests/e2e) and ./... covers only the current one, so check each module that pulls it in rather than assuming the root is the only one.
Verification
Assert on govulncheck's summary line or -format json OSV count, never grep -c 'Module: stdlib' - that pattern returns 0 whether or not findings exist (established on #1835, reconfirmed on #1837).
Prove the assertion has teeth: it must report non-zero against the pre-bump tree and zero after. An assertion never demonstrated to fail is not evidence.
Related
Found while investigating #1837, which is a separate pair of advisories and should not be conflated. #1837's own conclusion is that it needs no code change; evidence is posted there.
CI - Build & Testis failing onmainas of84a884e(run 32909072296, 2026-08-25T23:03:53Z). The previous commitae1e632was green, and nothing in #1881 touched dependencies: the advisory was published the same day.Why p0
This is not a single red run. Every PR branches from
mainand runs the samegovulncheck ./..., so every open and future PR inherits the same failure until this lands. It blocks the merge gate repo-wide, and it does it in the security job, which is exactly the check nobody should be tempted to wave through.The fix is a version bump to an already-published fixed version, so the cost of clearing it is near zero and the cost of leaving it is every merge in the repo.
Detail
github.com/moby/go-archivereaches the module graph throughtestcontainers, viainternal/database/postgres/testhelpersandinternal/config/store_postgres.go:968. It is symbol-reachable, which is why source-modegovulncheckexits 3 rather than reporting it as an unused require.Fix
Bump
github.com/moby/go-archivetov0.3.0. This is ago.workmonorepo with 6 modules (.,pkg,providers/{aws,azure,gcp},tests/e2e) and./...covers only the current one, so check each module that pulls it in rather than assuming the root is the only one.Verification
Assert on govulncheck's summary line or
-format jsonOSV count, nevergrep -c 'Module: stdlib'- that pattern returns 0 whether or not findings exist (established on #1835, reconfirmed on #1837).Prove the assertion has teeth: it must report non-zero against the pre-bump tree and zero after. An assertion never demonstrated to fail is not evidence.
Related
Found while investigating #1837, which is a separate pair of advisories and should not be conflated. #1837's own conclusion is that it needs no code change; evidence is posted there.