Repository navigation
Go security: Bump moby/go-archive so the tar traversal fix lands - #100
Merged
Merged
Conversation
govulncheck flags GO-2026-6253 in github.com/moby/go-archive v0.2.0, pulled in transitively by testcontainers. A crafted tar can write outside the extraction directory. v0.3.0 has the fix. Also picks up moby/sys/user v0.4.1 as a required companion bump.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The
securityjob onmainis red:make vulncheck(govulncheck) fails with exit 3.github.com/moby/go-archive v0.2.0is affected by GO-2026-6253 — a crafted tar archive can write files outside the extraction directory. The module arrives transitively viatestcontainers-go, and govulncheck confirms we reach the vulnerable symbols (archive.TarWithOptions,compression.CompressStream,tarheader.*) through the Postgres test container helper ininternal/testhelpers. So this is a reachable finding, not noise — it runs on every CI test run.Failing run: https://github.com/sklinkert/go-ddd/actions/runs/32975578088/job/98199373320
What changed
github.com/moby/go-archive(indirect)v0.2.0→v0.3.0, which contains the fix.github.com/moby/sys/user(indirect)v0.4.0→v0.4.1, required by the above.go mod tidy+go mod vendorto keep the checked-invendor/tree in sync.Dependency-only change. No application, domain, or test code touched.
How to test
Verified locally on Go 1.26.6: vulncheck clean, full suite green including the Postgres testcontainer packages.