Skip to content

Go security: Bump moby/go-archive so the tar traversal fix lands - #100

Merged
sklinkert merged 1 commit into
mainfrom
bump-moby-go-archive
Aug 28, 2026
Merged

sklinkert merged 1 commit into
mainfrom
bump-moby-go-archive

Conversation

@sklinkert

Copy link
Copy Markdown
Owner

Why

The security job on main is red: make vulncheck (govulncheck) fails with exit 3.

github.com/moby/go-archive v0.2.0 is affected by GO-2026-6253 — a crafted tar archive can write files outside the extraction directory. The module arrives transitively via testcontainers-go, and govulncheck confirms we reach the vulnerable symbols (archive.TarWithOptions, compression.CompressStream, tarheader.*) through the Postgres test container helper in internal/testhelpers. So this is a reachable finding, not noise — it runs on every CI test run.

Failing run: https://github.com/sklinkert/go-ddd/actions/runs/32975578088/job/98199373320

What changed

  • github.com/moby/go-archive (indirect) v0.2.0 → v0.3.0, which contains the fix.
  • github.com/moby/sys/user (indirect) v0.4.0 → v0.4.1, required by the above.
  • go mod tidy + go mod vendor to keep the checked-in vendor/ tree in sync.

Dependency-only change. No application, domain, or test code touched.

How to test

make vulncheck            # No vulnerabilities found
go build ./... && go vet ./...
go test -race ./...       # needs Docker for testcontainers

Verified locally on Go 1.26.6: vulncheck clean, full suite green including the Postgres testcontainer packages.

govulncheck flags GO-2026-6253 in github.com/moby/go-archive v0.2.0, pulled
in transitively by testcontainers. A crafted tar can write outside the
extraction directory. v0.3.0 has the fix.

Also picks up moby/sys/user v0.4.1 as a required companion bump.
@sklinkert
sklinkert merged commit 64574f4 into main Aug 28, 2026
3 checks passed
@sklinkert
sklinkert deleted the bump-moby-go-archive branch August 28, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant