Repository navigation
sec(deps): bump moby/go-archive to v0.3.0 for GO-2026-6253 - #1895
Conversation
govulncheck GO-2026-6253 (crafted tar archive can write outside the
extraction directory) is symbol-reachable in the root module through
testcontainers, so `govulncheck ./...` exits 3 and turns CI red on main
and on every branch cut from it.
Bump the indirect requirement from v0.2.0 to the published fixed version
v0.3.0. MVS pulls three transitive indirect bumps that go-archive v0.3.0
requires: klauspost/compress v1.18.5 -> v1.18.7, moby/sys/sequential
v0.6.0 -> v0.7.0, moby/sys/user v0.4.0 -> v0.4.1. No testcontainers
upgrade is needed. Only the root module requires go-archive; the other
five workspace modules (pkg, providers/{aws,azure,gcp}, tests/e2e) are
untouched.
Verified with govulncheck v1.1.4 (the version pinned in ci.yml) across
all six workspace modules, asserting on the summary line and the
-format json OSV finding count rather than a grep for a module name:
before: root module exits 3, "Your code is affected by 1 vulnerability
from 1 module", json findings [GO-2026-5841, GO-2026-5932,
GO-2026-6253] with GO-2026-6253 traced to called symbols
TarWithOptions, CompressStream, FileInfoHeaderNoLookups, ...
after: all six modules exit 0, root reports "No vulnerabilities
found." and GO-2026-6253 is absent from the json findings.
`go test ./...` in the root module passes (33 ok, 10 without tests),
including the testcontainers-backed internal/database/postgres/
testhelpers and internal/config packages. The other five modules still
build.
Closes #1894
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: 1 review is currently available. Your included PR review attempts over the past 7 days set your current allowance at 3 reviews per hour. 📝 WalkthroughWalkthroughThe change updates four indirect Go dependencies in ChangesDependency updates
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to This PR makes a localized dependency update to remove the affected archive vulnerability, with the relevant checks passing and no actionable merge-blocking risk remaining beyond normal review. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
Full details: Linked Issues checkExplanation The pull request updates github.com/moby/go-archive to v0.3.0, which satisfies the primary fix in issue Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
govulncheck GO-2026-6253 (crafted tar archive can write outside the
extraction directory) is symbol-reachable in the root module through
testcontainers, so `govulncheck ./...` exits 3 and turns CI red on main
and on every branch cut from it.
Bump the indirect requirement from v0.2.0 to the published fixed version
v0.3.0. MVS pulls three transitive indirect bumps that go-archive v0.3.0
requires: klauspost/compress v1.18.5 -> v1.18.7, moby/sys/sequential
v0.6.0 -> v0.7.0, moby/sys/user v0.4.0 -> v0.4.1. No testcontainers
upgrade is needed. Only the root module requires go-archive; the other
five workspace modules (pkg, providers/{aws,azure,gcp}, tests/e2e) are
untouched.
Verified with govulncheck v1.1.4 (the version pinned in ci.yml) across
all six workspace modules, asserting on the summary line and the
-format json OSV finding count rather than a grep for a module name:
before: root module exits 3, "Your code is affected by 1 vulnerability
from 1 module", json findings [GO-2026-5841, GO-2026-5932,
GO-2026-6253] with GO-2026-6253 traced to called symbols
TarWithOptions, CompressStream, FileInfoHeaderNoLookups, ...
after: all six modules exit 0, root reports "No vulnerabilities
found." and GO-2026-6253 is absent from the json findings.
`go test ./...` in the root module passes (33 ok, 10 without tests),
including the testcontainers-backed internal/database/postgres/
testhelpers and internal/config packages. The other five modules still
build.
Closes #1894
Problem
CI - Build & Testis red onmainat84a884e:govulncheck ./...in the root module exits 3 on GO-2026-6253 (crafted tar archive can write outside the extraction directory,github.com/moby/go-archive). The advisory was published 2026-08-25; no dependency change caused it. Every branch cut frommaininherits the failure, so the merge gate is blocked repo-wide.go-archivereaches the graph as an indirect requirement throughtestcontainers, and it is symbol-reachable (internal/database/postgres/testhelpers,internal/config/store_postgres.go), which is why source-mode govulncheck fails rather than reporting an unused require.Change
Bump
github.com/moby/go-archivev0.2.0->v0.3.0, the published fixed version, via a targetedgo get(notgo get -u).MVS pulls three transitive indirect bumps that
go-archive@v0.3.0requires in its owngo.mod:github.com/moby/go-archivegithub.com/klauspost/compressgithub.com/moby/sys/sequentialgithub.com/moby/sys/userNo
testcontainersupgrade is required. Diff is 4 lines ofgo.modplus the matchinggo.sumhashes.Module scope
This is a
go.workmonorepo with 6 modules. Only the root module requiresgo-archive:pkg,providers/aws,providers/azure,providers/gcpandtests/e2eare untouched;go.work.sumneeded no update either.go mod tidywas run in the root module (the only one touched).Verification
Scanned all six modules with govulncheck v1.1.4 (the version pinned in
ci.yml), mirroring the CI loopfor mod in . pkg providers/aws providers/azure providers/gcp tests/e2e; do (cd "$mod" && govulncheck ./...); done.The assertion is the text-mode summary line plus the process exit code, corroborated by the distinct-OSV count from
govulncheck -format json ./... | jq -r 'select(.finding != null) | .finding.osv' | sort -u. Deliberately notgrep -c 'Module: stdlib', which returns 0 whether or not findings exist (#1835, #1837).Before the bump (pre-bump tree = known-vulnerable input)
Root module:
exit code 3. json OSV findings:
GO-2026-5841, GO-2026-5932, GO-2026-6253(3). GO-2026-6253 traces to called symbolsTarWithOptions,CompressStream,FileInfoHeaderNoLookups,Close,Gname,Uname,Sys,init. The other five modules exit 0. Aggregate loop exit: 1 (failure).This is the teeth check: the exact same command and assertion reports the finding and fails on the pre-bump tree.
After the bump
.GO-2026-5932(require-only)pkgproviders/awsproviders/azureproviders/gcptests/e2eAggregate loop exit: 0. GO-2026-6253 is absent from every module's json findings.
Tests
go test ./...in the root module (the only module changed): exit 0, 33 packagesok, 10 without tests. That includes the testcontainers-backed paths this bump could plausibly break, both of which really spun containers:go vet ./...exits 0, and the other five modules stillgo build ./...cleanly under the workspace.Scope note
GO-2026-5932(golang.org/x/crypto, require-only, does not gate CI) is #1837's separate concern and is deliberately untouched here.GO-2026-5841(klauspost/compress, also require-only, also #1837) drops out as a side effect of thecompress v1.18.7requirement thatgo-archive@v0.3.0carries; that was not a goal of this PR and #1837's own conclusion still stands on its own terms.Closes #1894
Summary by CodeRabbit