Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): bump github.com/docker/docker from 26.0.0+incompatible to 26.1.5+incompatible #223

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Aug 9, 2024

Bumps github.com/docker/docker from 26.0.0+incompatible to 26.1.5+incompatible.

Release notes

Sourced from github.com/docker/docker's releases.

v26.1.5

26.1.5

Security

This release contains a fix for CVE-2024-41110 / GHSA-v23v-6jw2-98fq that impacted setups using authorization plugins (AuthZ) for access control. No other changes are included in this release, and this release is otherwise identical for users not using AuthZ plugins.

Full Changelog: moby/moby@v26.1.4...v26.1.5

v26.1.4

26.1.4

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

This release updates the Go runtime to 1.21.11 which contains security fixes for:

Bug fixes and enhancements

  • Fixed an issue where promoting a node immediately after another node was demoted could cause the promotion to fail. moby/moby#47870
  • Prevent the daemon log from being spammed with superfluous response.WriteHeader call ... messages.. moby/moby#47843
  • Don't show empty hints when plugins return an empty hook message. docker/cli#5083
  • Added ContextType: "moby" to the context list/inspect output to address a compatibility issue with Visual Studio Container Tools. docker/cli#5095
  • Fix a compatibility issue with Visual Studio Container Tools. docker/cli#5095

Packaging updates

v26.1.3

26.1.3

... (truncated)

Commits
  • 411e817 Merge commit from fork
  • 9cc85ea If url includes scheme, urlPath will drop hostname, which would not match the...
  • 820cab9 Authz plugin security fixes for 0-length content and path validation
  • 6bc4906 Merge pull request #48123 from vvoland/v26.1-48120
  • 6fbdce4 update to go1.21.12
  • f533464 Merge pull request #47986 from vvoland/v26.1-47985
  • c1d4587 builder/mobyexporter: Add missing nil check
  • d642804 Merge pull request #47940 from thaJeztah/26.1_backport_api_remove_container_c...
  • daba246 docs: api: image inspect: remove Container and ContainerConfig
  • de5c9cf Merge pull request #47912 from thaJeztah/26.1_backport_vendor_containerd_1.7.18
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [github.com/docker/docker](https://github.com/docker/docker) from 26.0.0+incompatible to 26.1.5+incompatible.
- [Release notes](https://github.com/docker/docker/releases)
- [Commits](moby/moby@v26.0.0...v26.1.5)

---
updated-dependencies:
- dependency-name: github.com/docker/docker
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 9, 2024
Copy link

dryrunsecurity bot commented Aug 9, 2024

DryRun Security Summary

The pull request includes various updates to the project's dependencies, configuration files, and documentation, which do not introduce any obvious security concerns, but should still be reviewed to ensure there are no unintended consequences or potential security vulnerabilities.

Expand for full summary

Summary:

The code changes in this pull request cover a variety of updates to the project's dependencies and supporting files, such as README, LICENSE, and configuration files. Overall, these changes do not introduce any obvious security concerns, as they are primarily focused on maintaining the project's dependencies, improving the development workflow, and updating documentation.

The key changes include:

  1. Updates to the README and LICENSE files for various dependencies, which are routine maintenance tasks and do not impact the application's security.
  2. Version updates to the github.com/docker/docker dependency, which should be reviewed to ensure there are no known security vulnerabilities or breaking changes in the new version.
  3. Changes to the .gitignore file, which are intended to improve the project's Git repository management and do not have direct security implications.
  4. Updates to the build and test configuration files, such as the Makefile and Travis CI configuration, which help maintain code quality and consistency but do not introduce security risks.
  5. A migration guide for the ORAS Go library from version 1 to version 2, which highlights improvements in the areas of dependency reduction, test coverage, and authentication, all of which can positively impact the overall security of the application.

While these changes do not raise immediate security concerns, it is always important to review any updates to dependencies, configuration files, and supporting documentation to ensure that there are no unintended consequences or potential security vulnerabilities introduced. Regular monitoring and review of the project's security posture is recommended to maintain a secure application.

Files Changed:

  1. vendor/github.com/digitorus/timestamp/README.md: Routine update to the README file, with no security implications.
  2. vendor/github.com/cyberphone/json-canonicalization/LICENSE: Update to the copyright year in the LICENSE file, with no security implications.
  3. go.mod: Update to the version of the github.com/docker/docker dependency, which should be reviewed for potential security impacts.
  4. vendor/github.com/hashicorp/hcl/.gitignore: Updates to the .gitignore file to improve repository management, with no direct security implications.
  5. go.sum: Update to the version of the github.com/docker/docker dependency, which should be reviewed for potential security impacts.
  6. vendor/github.com/hashicorp/hcl/Makefile: Updates to the build and test configuration, with no security concerns.
  7. vendor/github.com/dimchansky/utfbom/.travis.yml: Updates to the Travis CI configuration, with no security concerns.
  8. vendor/github.com/docker/docker/AUTHORS: Addition of a new contributor, with no security implications.
  9. vendor/modules.txt: Update to the version of the github.com/docker/docker dependency, which should be reviewed for potential security impacts.
  10. vendor/oras.land/oras-go/v2/MIGRATION_GUIDE.md: Migration guide for the ORAS Go library, highlighting security-relevant improvements such as reduced dependencies and improved authentication.

Code Analysis

We ran 9 analyzers against 10 files and 0 analyzers had findings. 9 analyzers had no findings.

Riskiness

🟢 Risk threshold not exceeded.

View PR in the DryRun Dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file go Pull requests that update Go code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants