Problem
The Dependency gate (#487) passes on master only because two HIGH advisories in github.com/docker/docker v28.5.2+incompatible are excepted until 2026-12-23: CVE-2026-41567 and CVE-2026-42306. No fixed version exists. The module is not in the server binary or the image. It arrives only as a test dependency of golang-migrate, through github.com/dhui/dktest. When the exceptions expire, the gate turns master red on the daily run.
Acceptance criteria
- Given the Dependency gate on master, When it runs, Then neither CVE-2026-41567 nor CVE-2026-42306 is reported, because
github.com/docker/docker is gone from backend/go.sum or upgraded to a fixed version.
- Both entries are removed from
security/vulnerability-exceptions.yaml.
- If neither is possible by 2026-12-16, the exceptions are renewed with a new
added date and a reason that still holds, and this issue records why.
Definition of Done
Leads: a golang-migrate release that drops dktest from its module graph, or a docker/docker fix release.
Problem
The Dependency gate (#487) passes on master only because two HIGH advisories in
github.com/docker/dockerv28.5.2+incompatible are excepted until 2026-12-23: CVE-2026-41567 and CVE-2026-42306. No fixed version exists. The module is not in the server binary or the image. It arrives only as a test dependency of golang-migrate, throughgithub.com/dhui/dktest. When the exceptions expire, the gate turns master red on the daily run.Acceptance criteria
github.com/docker/dockeris gone frombackend/go.sumor upgraded to a fixed version.security/vulnerability-exceptions.yaml.addeddate and a reason that still holds, and this issue records why.Definition of Done
go test ./...greenLeads: a golang-migrate release that drops dktest from its module graph, or a
docker/dockerfix release.