Paweł Gronowski
400b45f682
vendor: github.com/moby/go-archive v0.3.3
...
full diff: https://github.com/moby/go-archive/compare/v0.3.2...v0.3.3
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-08-05 19:11:05 +02:00
Sebastiaan van Stijn
a6014a702b
vendor: github.com/moby/go-archive v0.3.2
...
full diff: https://github.com/moby/go-archive/compare/v0.3.1...v0.3.2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-31 18:53:47 +02:00
Sebastiaan van Stijn
0b50545471
vendor: github.com/moby/go-archive v0.3.1
...
full diff: https://github.com/moby/go-archive/compare/v0.3.0...v0.3.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-31 18:10:04 +02:00
Sebastiaan van Stijn
f6d6bede46
vendor: github.com/moby/go-archive v0.3.0
...
full diff: https://github.com/moby/go-archive/compare/v0.2.1...v0.3.0
v0.3.0
This release fixes CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h, where a crafted
tar archive could use links to cause extraction operations to create or
overwrite files outside the intended destination directory.
The issue affected Unpack, UnpackLayer, Untar, UntarUncompressed, and the
ApplyLayer helpers. Users should upgrade and avoid extracting untrusted
archives with earlier versions.
What's Changed
* archive: harden tar extraction against path traversal
* archive: do not follow reparse points in chtimes
* archive: fix creation time updates on Windows
* archive: minor cleanups and godoc touch-up
* archive: RebaseArchiveEntries: fix archive path rebasing
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-30 19:17:27 +02:00
Paweł Gronowski and GitHub
775dd50364
Merge pull request #7111 from thaJeztah/bump_go_archive
...
vendor: github.com/moby/go-archive main / v0.3.0-dev
2026-07-27 22:13:35 +02:00
Sebastiaan van Stijn
487686142c
vendor: golang.org/x/net v0.57.0
...
Relevant changes (in vendor):
- bpf: add security considerations to package docs
- http2: initialize Transport on NewClientConn
fixes: x/net/http2: zero Transport not ready for use
- idna: reject all-ASCII xn-- labels on all Go versions
fixes x/net/idna: ToUnicode accepts Punycode labels encoding pure ASCII labels
full diff: https://github.com/golang/net/compare/v0.56.0...v0.57.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-27 21:28:05 +02:00
Sebastiaan van Stijn
e03b83ef06
vendor: golang.org/x/text v0.40.0
...
- unicode/norm: avoid infinite loop on invalid input
full diff: https://github.com/golang/text/compare/v0.38.0...v0.40.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-27 21:28:05 +02:00
Sebastiaan van Stijn
8dfca49e6b
vendor: golang.org/x/mod v0.38.0
...
full diff: https://github.com/golang/mod/compare/v0.37.0...v0.38.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-27 21:28:05 +02:00
Sebastiaan van Stijn
808405b67d
vendor: golang.org/x/term v0.45.0
...
full diff: https://github.com/golang/term/compare/v0.44.0...v0.45.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-27 21:28:05 +02:00
Sebastiaan van Stijn
3f5a7b50ab
vendor: golang.org/x/sys v0.47.0
...
- cpu: handle vendor suffixes in parseRelease
- unix: update glibc to 2.43
- unix: use epoll_pwait rather than epoll_wait
- windows: avoid length overflow in NewNTString
- windows: document safe usage of TrusteeValue
full diff: https://github.com/golang/sys/compare/v0.46.0...v0.47.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-27 21:28:05 +02:00
Sebastiaan van Stijn
40c63db4c8
vendor: golang.org/x/sync v0.22.0
...
semaphore: panic on negative weights
full diff: https://github.com/golang/sync/compare/v0.21.0...v0.22.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-27 21:28:03 +02:00
Sebastiaan van Stijn and GitHub
977f88900e
Merge pull request #7121 from thaJeztah/bump_go_connections
...
vendor: github.com/docker/go-connections v0.8.0
2026-07-27 21:26:50 +02:00
Sebastiaan van Stijn
f6dfb40875
vendor: github.com/moby/go-archive main / v0.3.0-dev
...
full diff: https://github.com/moby/go-archive/compare/v0.2.0...2ff9bfb8b2ee
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-27 21:24:52 +02:00
Paweł Gronowski
aa610f321d
vendor: github.com/moby/moby/client v0.5.1
...
full diff: https://github.com/moby/moby/compare/client/v0.5.0...client/v0.5.1
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-07-27 21:15:05 +02:00
Paweł Gronowski and GitHub
be7865c09e
Merge pull request #7123 from thaJeztah/bump_grpc
...
vendor: google.golang.org/grpc v1.82.1
2026-07-27 17:00:54 +02:00
Sebastiaan van Stijn
9f4301e8f5
vendor: go.yaml.in/yaml/v3 v3.0.5
...
removes transitive dependencies on gopkg.in/check.v1
full diff: https://github.com/yaml/go-yaml/compare/v3.0.4...v3.0.5
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-27 14:43:56 +02:00
Sebastiaan van Stijn
4e6e8fe5c8
vendor: github.com/docker/go-connections v0.8.0
...
- sockets: set socket permissions without overriding umask
- sockets: improve abstract Unix socket handling
- sockets: InmemSocket: add DialContext
- sockets: remove double error decoration
- sockets: test-enhancements and improve coverage
full diff: https://github.com/docker/go-connections/compare/v0.7.0...v0.8.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-25 19:47:59 +02:00
Sebastiaan van Stijn
532dcc37f5
vendor: google.golang.org/grpc v1.82.1
...
Fixes xDS RBAC and HTTP/2 Vulnerabilities: GHSA-hrxh-6v49-42gf
full diff: https://github.com/grpc/grpc-go/compare/v1.81.1...v1.82.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-25 03:59:22 +02:00
Sebastiaan van Stijn
349fad1635
vendor: github.com/moby/go-archive v0.2.1
...
full diff: https://github.com/moby/go-archive/compare/v0.2.0...v0.2.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-07-23 23:05:30 +02:00
Sebastiaan van Stijn
8fda97b545
vendor: github.com/moby/sys/user v0.4.1
...
- user: prevent possible DoS via unbounded parsing of user and group
database files in GHSA-mjcv-p78q-w5fw. This fixes a similar issue
as CVE-2026-47262 in containerd.
- user: prevent falling back to looking up numeric usernames
Improve handling of numeric user/group to prevent looking up numeric
values as usernames. This fixes a similar issue as [CVE-2026-46680] in
containerd.
- user: update minimum go version to go1.18
- assorted testing and linting fixes.
[CVE-2026-46680]: https://github.com/advisories/GHSA-fqw6-gf59-qr4w
full diff: https://github.com/moby/sys/compare/user/v0.4.0...user/v0.4.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-25 21:31:42 +02:00
Paweł Gronowski
ee2f737013
vendor: github.com/moby/moby/client v0.5.0
...
full diff: https://github.com/moby/moby/compare/client/v0.5.0-rc.1...client/v0.5.0
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-06-18 21:41:38 +02:00
Paweł Gronowski
1f80e23560
vendor: github.com/moby/moby/api v1.55.0
...
full diff: https://github.com/moby/moby/compare/api/v1.55.0-rc.1...api/v1.55.0
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2026-06-18 21:39:19 +02:00
Sebastiaan van Stijn
233cd4a643
vendor: github.com/moby/moby/api v1.55.0-rc.1, moby/client v0.5.0-rc.1
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-12 18:54:32 +02:00
Paweł Gronowski and GitHub
5b600d015d
Merge pull request #7047 from thaJeztah/bump_go_events
...
vendor: github.com/docker/go-events v0.0.0-20260608200158-dbf6103125a4
2026-06-12 18:44:35 +02:00
Paweł Gronowski and GitHub
e6decf4d85
Merge pull request #7048 from thaJeztah/bump_compress
...
vendor: github.com/klauspost/compress v1.18.6
2026-06-12 18:44:24 +02:00
Sebastiaan van Stijn
fef3ef83fe
vendor: golang.org/x/net v0.56.0
...
full diff: https://github.com/golang/net/compare/v0.55.0...v0.56.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-12 17:13:23 +02:00
Sebastiaan van Stijn
9eff92c55a
vendor: github.com/klauspost/compress v1.18.6
...
full diff: https://github.com/klauspost/compress/compare/v1.18.5...v1.18.6
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-12 17:11:24 +02:00
Sebastiaan van Stijn
43f745b242
vendor: github.com/docker/go-events v0.0.0-20260608200158-dbf6103125a4
...
full diff: https://github.com/docker/go-events/compare/605354379745...dbf6103125a4
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-12 17:07:53 +02:00
Sebastiaan van Stijn and GitHub
f4a4c1e2cf
Merge pull request #7038 from thaJeztah/bump_runewidth
...
vendor: github.com/mattn/go-runewidth v0.0.24
2026-06-10 15:48:14 +02:00
Sebastiaan van Stijn and GitHub
b680c49f57
Merge pull request #7041 from thaJeztah/no_tools
...
man: remove tools.go in favor of tools directive
2026-06-10 15:40:42 +02:00
Paweł Gronowski and GitHub
9c7701eb48
Merge pull request #7037 from thaJeztah/bump_otels
...
vendor: go.opentelemetry.io/otel v1.44.0, go.opentelemetry.io/contrib v0.69.0
2026-06-10 12:26:23 +02:00
Paweł Gronowski and GitHub
ddc801807d
Merge pull request #7036 from thaJeztah/bump_x_deps
...
vendor: update golang.org/x/* dependencies
2026-06-10 12:26:08 +02:00
Paweł Gronowski and GitHub
83963b759c
Merge pull request #7035 from thaJeztah/bump_sequential
...
vendor: github.com/moby/sys/sequential v0.7.0
2026-06-10 12:25:21 +02:00
Sebastiaan van Stijn
55016421fd
man: remove tools.go in favor of tools directive
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-10 11:37:02 +02:00
Sebastiaan van Stijn
a9c82c0a9f
vendor: github.com/mattn/go-runewidth v0.0.24
...
- Optimize EastAsian RuneWidth with precomputed width table
full diff: https://github.com/mattn/go-runewidth/compare/v0.0.23...v0.0.24
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-09 16:58:46 +02:00
Sebastiaan van Stijn
22d7ca46a3
vendor: go.opentelemetry.io/otel v1.44.0, go.opentelemetry.io/contrib v0.69.0
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-09 16:35:02 +02:00
Sebastiaan van Stijn
a721bd651b
vendor: google.golang.org/genproto 3dc84a4a5aaa
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-09 16:32:02 +02:00
Sebastiaan van Stijn
51583aec0b
vendor: golang.org/x/text v0.38.0
...
full diff: https://github.com/golang/text/compare/v0.37.0...v0.38.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-09 16:26:28 +02:00
Sebastiaan van Stijn
399c9456a7
vendor: golang.org/x/sync v0.21.0
...
full diff: https://github.com/golang/sync/compare/v0.20.0...v0.21.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-09 16:25:46 +02:00
Sebastiaan van Stijn
de24d1cbc0
vendor: golang.org/x/mod v0.37.0
...
full diff: https://github.com/golang/mod/compare/v0.36.0...v0.37.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-09 16:25:11 +02:00
Sebastiaan van Stijn
49dc46afed
vendor: golang.org/x/term v0.44.0
...
full diff: https://github.com/golang/term/compare/v0.43.0...v0.44.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-09 16:24:33 +02:00
Sebastiaan van Stijn
c72acd0a08
vendor: golang.org/x/sys v0.46.0
...
full diff: https://github.com/golang/sys/compare/v0.45.0...v0.46.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-09 16:23:59 +02:00
Sebastiaan van Stijn
b601b2577a
vendor: github.com/moby/sys/sequential v0.7.0
...
- update minimum go version to 1.24
- use os.OpenFile with O_FILE_FLAG_SEQUENTIAL_SCAN on Go 1.26+
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-09 16:22:14 +02:00
Sebastiaan van Stijn
1aae5d7822
vendor: github.com/docker/docker-credential-helpers v0.9.8
...
full diff: https://github.com/docker/docker-credential-helpers/compare/v0.9.7...v0.9.8
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-06-08 20:58:17 +02:00
Sebastiaan van Stijn
20f5e7c08c
vendor: golang.org/x/net v0.55.0
...
security changes (not used in our code)
- html: escape greater-than symbol in doctype identifiers (CVE-2026-25681)
- html: improve Noah's Ark clause performance (CVE-2026-25680)
- html: properly render fostered elements in foreign content (CVE-2026-42502)
- html: properly check namespace in "in body" any other end tag (CVE-2026-42506)
- html: ignore duplicate attributes during tokenization (CVE-2026-27136)
other changes:
- quic: fix appendMaxDataFrame erroneously accumulating sentLimit
- quic: establish a "happened-before" relationship between stream write and read
- quic: fix buffer slicing when handling overlapping stream data
- http2: avoid API changes when built with go1.27
security announce: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
full diff: https://github.com/golang/net/compare/v0.54.0...v0.55.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-05-22 11:27:01 +02:00
Sebastiaan van Stijn
20debc9c01
vendor: golang.org/x/sys v0.45.0
...
notable changes:
- unix: update to Linux kernel 7.0
- unix: add Readv, Writev, Preadv, Pwritev for OpenBSD
- windows: add NtSetEaFile, NtQueryEaFile and NtQueryInformationFile
- cpu: add LLACQ_SCREL, SCQ, DBAR_HINTS detection for loong64
- cpu: detect zbc extension on riscv64
full diff: https://github.com/golang/sys/compare/v0.44.0...v0.45.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-05-22 11:25:58 +02:00
Sebastiaan van Stijn
970afd5cc4
vendor: golang.org/x/net v0.54.0
...
full diff: https://github.com/golang/net/compare/v0.53.0...v0.54.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-05-11 12:22:37 +02:00
Sebastiaan van Stijn
7e07bf127c
vendor: golang.org/x/mod v0.36.0
...
full diff: https://github.com/golang/mod/compare/v0.34.0...v0.36.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-05-11 12:21:34 +02:00
Sebastiaan van Stijn
5aeb52681b
vendor: golang.org/x/text v0.37.0
...
full diff: https://github.com/golang/time/compare/v0.36.0...v0.37.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-05-11 12:20:20 +02:00
Sebastiaan van Stijn
644d046721
vendor: golang.org/x/term v0.43.0
...
full diff: https://github.com/golang/term/compare/v0.42.0...v0.43.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2026-05-11 12:18:58 +02:00