Skip to content

sec(deps): govulncheck GO-2026-6253 in moby/go-archive turns CI red on main (fixed in v0.3.0) #1894

Description

@cristim

CI - Build & Test is failing on main as of 84a884e (run 32909072296, 2026-08-25T23:03:53Z). The previous commit ae1e632 was green, and nothing in #1881 touched dependencies: the advisory was published the same day.

Your code is affected by 1 vulnerability
GO-2026-6253
Fixed in: github.com/moby/go-archive@v0.3.0

Why p0

This is not a single red run. Every PR branches from main and runs the same govulncheck ./..., so every open and future PR inherits the same failure until this lands. It blocks the merge gate repo-wide, and it does it in the security job, which is exactly the check nobody should be tempted to wave through.

The fix is a version bump to an already-published fixed version, so the cost of clearing it is near zero and the cost of leaving it is every merge in the repo.

Detail

github.com/moby/go-archive reaches the module graph through testcontainers, via internal/database/postgres/testhelpers and internal/config/store_postgres.go:968. It is symbol-reachable, which is why source-mode govulncheck exits 3 rather than reporting it as an unused require.

Fix

Bump github.com/moby/go-archive to v0.3.0. This is a go.work monorepo with 6 modules (., pkg, providers/{aws,azure,gcp}, tests/e2e) and ./... covers only the current one, so check each module that pulls it in rather than assuming the root is the only one.

Verification

Assert on govulncheck's summary line or -format json OSV count, never grep -c 'Module: stdlib' - that pattern returns 0 whether or not findings exist (established on #1835, reconfirmed on #1837).

Prove the assertion has teeth: it must report non-zero against the pre-bump tree and zero after. An assertion never demonstrated to fail is not evidence.

Related

Found while investigating #1837, which is a separate pair of advisories and should not be conflated. #1837's own conclusion is that it needs no code change; evidence is posted there.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions