Skip to content

chore(deps): remove the docker/docker exceptions from the Dependency gate #799

Description

@alex-dembele

Problem

The Dependency gate (#487) passes on master only because two HIGH advisories in github.com/docker/docker v28.5.2+incompatible are excepted until 2026-12-23: CVE-2026-41567 and CVE-2026-42306. No fixed version exists. The module is not in the server binary or the image. It arrives only as a test dependency of golang-migrate, through github.com/dhui/dktest. When the exceptions expire, the gate turns master red on the daily run.

Acceptance criteria

  1. Given the Dependency gate on master, When it runs, Then neither CVE-2026-41567 nor CVE-2026-42306 is reported, because github.com/docker/docker is gone from backend/go.sum or upgraded to a fixed version.
  2. Both entries are removed from security/vulnerability-exceptions.yaml.
  3. If neither is possible by 2026-12-16, the exceptions are renewed with a new added date and a reason that still holds, and this issue records why.

Definition of Done

  • Dependency gate green on master with no docker/docker exception, or a renewal justified here
  • go test ./... green

Leads: a golang-migrate release that drops dktest from its module graph, or a docker/docker fix release.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:backendGo, /internal, /pkgpriority:P2-mediumNormal milestone workstatus:readyMeets the ready definitiontier:0-trustTrust: security, isolation, evidence integritytype:securitySecurity defect or hardening

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions