Skip to content

sec(deps): bump moby/go-archive to v0.3.0 for GO-2026-6253 - #1895

Merged
cristim merged 1 commit into
mainfrom
sec/1894-go-archive-v0.3.0
Aug 26, 2026
Merged

cristim merged 1 commit into
mainfrom
sec/1894-go-archive-v0.3.0

Conversation

@cristim

@cristim cristim commented Aug 25, 2026 •

Copy link
Copy Markdown
Member

Problem

CI - Build & Test is red on main at 84a884e: govulncheck ./... in the root module exits 3 on GO-2026-6253 (crafted tar archive can write outside the extraction directory, github.com/moby/go-archive). The advisory was published 2026-08-25; no dependency change caused it. Every branch cut from main inherits the failure, so the merge gate is blocked repo-wide.

go-archive reaches the graph as an indirect requirement through testcontainers, and it is symbol-reachable (internal/database/postgres/testhelpers, internal/config/store_postgres.go), which is why source-mode govulncheck fails rather than reporting an unused require.

Change

Bump github.com/moby/go-archive v0.2.0 -> v0.3.0, the published fixed version, via a targeted go get (not go get -u).

MVS pulls three transitive indirect bumps that go-archive@v0.3.0 requires in its own go.mod:

module from to
github.com/moby/go-archive v0.2.0 v0.3.0
github.com/klauspost/compress v1.18.5 v1.18.7
github.com/moby/sys/sequential v0.6.0 v0.7.0
github.com/moby/sys/user v0.4.0 v0.4.1

No testcontainers upgrade is required. Diff is 4 lines of go.mod plus the matching go.sum hashes.

Module scope

This is a go.work monorepo with 6 modules. Only the root module requires go-archive:

$ rg -n 'moby/go-archive' --glob 'go.mod' --glob 'go.sum' --glob 'go.work.sum' .
./go.mod:168:   github.com/moby/go-archive v0.2.0 // indirect
./go.sum:287:github.com/moby/go-archive v0.2.0 h1:...
./go.sum:288:github.com/moby/go-archive v0.2.0/go.mod h1:...

pkg, providers/aws, providers/azure, providers/gcp and tests/e2e are untouched; go.work.sum needed no update either. go mod tidy was run in the root module (the only one touched).

Verification

Scanned all six modules with govulncheck v1.1.4 (the version pinned in ci.yml), mirroring the CI loop for mod in . pkg providers/aws providers/azure providers/gcp tests/e2e; do (cd "$mod" && govulncheck ./...); done.

The assertion is the text-mode summary line plus the process exit code, corroborated by the distinct-OSV count from govulncheck -format json ./... | jq -r 'select(.finding != null) | .finding.osv' | sort -u. Deliberately not grep -c 'Module: stdlib', which returns 0 whether or not findings exist (#1835, #1837).

Before the bump (pre-bump tree = known-vulnerable input)

Root module:

Vulnerability #1: GO-2026-6253
    moby/go-archive: Crafted tar archive can write outside the extraction
    directory in github.com/moby/go-archive
  Module: github.com/moby/go-archive
    Found in: github.com/moby/go-archive@v0.2.0
    Fixed in: github.com/moby/go-archive@v0.3.0

Your code is affected by 1 vulnerability from 1 module.

exit code 3. json OSV findings: GO-2026-5841, GO-2026-5932, GO-2026-6253 (3). GO-2026-6253 traces to called symbols TarWithOptions, CompressStream, FileInfoHeaderNoLookups, Close, Gname, Uname, Sys, init. The other five modules exit 0. Aggregate loop exit: 1 (failure).

This is the teeth check: the exact same command and assertion reports the finding and fails on the pre-bump tree.

After the bump

module summary line exit json OSV findings
. No vulnerabilities found. / affected by 0 vulnerabilities 0 GO-2026-5932 (require-only)
pkg No vulnerabilities found. 0 none
providers/aws No vulnerabilities found. 0 none
providers/azure No vulnerabilities found. 0 none
providers/gcp No vulnerabilities found. 0 none
tests/e2e No vulnerabilities found. 0 none

Aggregate loop exit: 0. GO-2026-6253 is absent from every module's json findings.

Tests

go test ./... in the root module (the only module changed): exit 0, 33 packages ok, 10 without tests. That includes the testcontainers-backed paths this bump could plausibly break, both of which really spun containers:

ok  github.com/LeanerCloud/CUDly/internal/database/postgres/testhelpers   5.425s
ok  github.com/LeanerCloud/CUDly/internal/config                          9.578s
ok  github.com/LeanerCloud/CUDly/internal/database/postgres/migrations    6.615s

go vet ./... exits 0, and the other five modules still go build ./... cleanly under the workspace.

Scope note

GO-2026-5932 (golang.org/x/crypto, require-only, does not gate CI) is #1837's separate concern and is deliberately untouched here. GO-2026-5841 (klauspost/compress, also require-only, also #1837) drops out as a side effect of the compress v1.18.7 requirement that go-archive@v0.3.0 carries; that was not a goal of this PR and #1837's own conclusion still stands on its own terms.

Closes #1894

Summary by CodeRabbit

  • Chores
    • Updated internal dependency versions to incorporate maintenance updates and improvements.
    • No user-facing features or behavior changes were introduced.

govulncheck GO-2026-6253 (crafted tar archive can write outside the
extraction directory) is symbol-reachable in the root module through
testcontainers, so `govulncheck ./...` exits 3 and turns CI red on main
and on every branch cut from it.

Bump the indirect requirement from v0.2.0 to the published fixed version
v0.3.0. MVS pulls three transitive indirect bumps that go-archive v0.3.0
requires: klauspost/compress v1.18.5 -> v1.18.7, moby/sys/sequential
v0.6.0 -> v0.7.0, moby/sys/user v0.4.0 -> v0.4.1. No testcontainers
upgrade is needed. Only the root module requires go-archive; the other
five workspace modules (pkg, providers/{aws,azure,gcp}, tests/e2e) are
untouched.

Verified with govulncheck v1.1.4 (the version pinned in ci.yml) across
all six workspace modules, asserting on the summary line and the
-format json OSV finding count rather than a grep for a module name:

  before: root module exits 3, "Your code is affected by 1 vulnerability
          from 1 module", json findings [GO-2026-5841, GO-2026-5932,
          GO-2026-6253] with GO-2026-6253 traced to called symbols
          TarWithOptions, CompressStream, FileInfoHeaderNoLookups, ...
  after:  all six modules exit 0, root reports "No vulnerabilities
          found." and GO-2026-6253 is absent from the json findings.

`go test ./...` in the root module passes (33 ok, 10 without tests),
including the testcontainers-backed internal/database/postgres/
testhelpers and internal/config packages. The other five modules still
build.

Closes #1894
@cristim cristim added priority/p0 Drop everything; same-day fix severity/high Significant harm urgency/now Drop other things impact/internal Team-internal only effort/xs Trivial / one-liner type/bug Defect triaged Item has been triaged labels Aug 25, 2026
@coderabbitai

coderabbitai Bot commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 2092b53e-74d9-44fa-b5d3-8bfe36490cbc

📥 Commits

Reviewing files that changed from the base of the PR and between 84a884e and 3cbb5a4.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (1)
  • go.mod

Included review availability: 1 review is currently available. Your included PR review attempts over the past 7 days set your current allowance at 3 reviews per hour.


📝 Walkthrough

Walkthrough

The change updates four indirect Go dependencies in go.mod, including github.com/moby/go-archive to the version that fixes GO-2026-6253.

Changes

Dependency updates

Layer / File(s) Summary
Update indirect module versions
go.mod
Updates github.com/klauspost/compress, github.com/moby/go-archive, github.com/moby/sys/sequential, and github.com/moby/sys/user to newer versions.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to 3cbb5

This PR makes a localized dependency update to remove the affected archive vulnerability, with the relevant checks passing and no actionable merge-blocking risk remaining beyond normal review.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Linked Issues check ❓ Inconclusive The pull request updates github.com/moby/go-archive to v0.3.0, which satisfies the primary fix in issue #1894. Verification across all six workspace modules cannot be confirmed from the reviewable sum… Provide reviewable evidence that govulncheck covers all six workspace modules, fails before the dependency bump, and passes afterward. Include or otherwise verify the excluded go.sum dependency changes.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the security dependency update, the affected module, the target version, and the vulnerability identifier.
Out of Scope Changes check ✅ Passed The additional indirect dependency updates are consistent with the requested go-archive upgrade and its dependency graph. No unrelated code changes are shown.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Full details: Linked Issues check

Explanation

The pull request updates github.com/moby/go-archive to v0.3.0, which satisfies the primary fix in issue #1894. Verification across all six workspace modules cannot be confirmed from the reviewable summary. The relevant go.sum file was excluded by the !**/*.sum path filter, so the complete dependency state also cannot be verified.

Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sec/1894-go-archive-v0.3.0

Comment @coderabbitai help to get the list of available commands.

@cristim
cristim merged commit ae331a0 into main Aug 26, 2026
25 checks passed
cristim added a commit that referenced this pull request Sep 27, 2026
govulncheck GO-2026-6253 (crafted tar archive can write outside the
extraction directory) is symbol-reachable in the root module through
testcontainers, so `govulncheck ./...` exits 3 and turns CI red on main
and on every branch cut from it.

Bump the indirect requirement from v0.2.0 to the published fixed version
v0.3.0. MVS pulls three transitive indirect bumps that go-archive v0.3.0
requires: klauspost/compress v1.18.5 -> v1.18.7, moby/sys/sequential
v0.6.0 -> v0.7.0, moby/sys/user v0.4.0 -> v0.4.1. No testcontainers
upgrade is needed. Only the root module requires go-archive; the other
five workspace modules (pkg, providers/{aws,azure,gcp}, tests/e2e) are
untouched.

Verified with govulncheck v1.1.4 (the version pinned in ci.yml) across
all six workspace modules, asserting on the summary line and the
-format json OSV finding count rather than a grep for a module name:

  before: root module exits 3, "Your code is affected by 1 vulnerability
          from 1 module", json findings [GO-2026-5841, GO-2026-5932,
          GO-2026-6253] with GO-2026-6253 traced to called symbols
          TarWithOptions, CompressStream, FileInfoHeaderNoLookups, ...
  after:  all six modules exit 0, root reports "No vulnerabilities
          found." and GO-2026-6253 is absent from the json findings.

`go test ./...` in the root module passes (33 ok, 10 without tests),
including the testcontainers-backed internal/database/postgres/
testhelpers and internal/config packages. The other five modules still
build.

Closes #1894
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/xs Trivial / one-liner impact/internal Team-internal only priority/p0 Drop everything; same-day fix severity/high Significant harm triaged Item has been triaged type/bug Defect urgency/now Drop other things

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sec(deps): govulncheck GO-2026-6253 in moby/go-archive turns CI red on main (fixed in v0.3.0)

1 participant