Skip to content

[VAULT-43618] Resolve GHSA-x744-4wpc-v9h2 and GHSA-pxq6-2prw-chj9 in plugincontainer#179

Merged
ryancragun merged 1 commit into
mainfrom
ryan-vault-43618
Apr 1, 2026
Merged

[VAULT-43618] Resolve GHSA-x744-4wpc-v9h2 and GHSA-pxq6-2prw-chj9 in plugincontainer#179
ryancragun merged 1 commit into
mainfrom
ryan-vault-43618

Conversation

@ryancragun

@ryancragun ryancragun commented Mar 30, 2026

Copy link
Copy Markdown
Collaborator

Resolve GHSA-x744-4wpc-v9h2 and GHSA-pxq6-2prw-chj9 in plugincontainer by replacing github.com/docker/docker with github.com/moby/moby/client @ v0.3.0 and github.com/moby/moby/api @ v1.54.0. This is necessary as docker/docker is no longer maintained and the fixes are not available in it.

We also upgrade our dependencies to their respective latest compatible versions.

PCI review checklist

  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.

  • If applicable, I've worked with GRC to document the impact of any changes to security controls.

    Examples of changes to controls include access controls, encryption, logging, etc.

  • If applicable, I've worked with GRC to ensure compliance due to a significant change to the in-scope PCI environment.

    Examples include changes to operating systems, ports, protocols, services, cryptography-related components, PII processing code, etc.

@ryancragun ryancragun requested a review from a team as a code owner March 30, 2026 21:24
…plugincontainer

Resolve GHSA-x744-4wpc-v9h2 and GHSA-pxq6-2prw-chj9 in `plugincontainer`
replacing `github.com/docker/docker` with `github.com/moby/moby/client` @
`v0.3.0` and `github.com/moby/moby/api` @ `v1.54.0.`. This is necessary as
`docker/docker` is no longer maintained as the fixes are not available
in it.

We also upgrade our dependencies to their respective latest compatible
versions.

Signed-off-by: Ryan Cragun <me@ryan.ec>
Comment thread plugincontainer/container_runner_linux.go
Comment thread plugincontainer/container_runner_external_test.go
@ryancragun ryancragun requested a review from sgmiller April 1, 2026 16:12
@ryancragun ryancragun merged commit 2f652a3 into main Apr 1, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants