build(deps): migrate Docker SDK to moby/moby and add dependency audit - #16
Merged
Merged
Conversation
github.com/docker/docker is affected by GO-2026-4887 and GO-2026-4883 in every version with no fix, and govulncheck reports both as reachable. The daemon now uses github.com/moby/moby/client v0.6.0 and github.com/moby/moby/api v1.56.0; docker/docker is no longer in the module graph, and a depguard rule keeps direct imports out. consumeEvents checks ctx.Err before classifying a stream error, so a closed-body error at shutdown no longer logs a spurious reconnect. go.opentelemetry.io/otel moves to v1.44.0 to clear GO-2026-5158. The v29 client refuses engines older than API 1.40, so Docker Engine 19.03+ is now documented as required.
…mit and CI make audit-deps runs the pinned govulncheck over every package and fails if github.com/docker/docker is reachable from the main module, printing the go mod why chain; depguard only sees direct imports, so this is the transitive guard. It runs as a pre-commit hook on go.mod and go.sum changes and as a dedicated CI job on every pull request, since the reviewdog pre-commit job only sees changed files.
CI jobs that read go-version-file from go.mod installed exactly go1.26.3, which govulncheck reports as reachable-vulnerable (GO-2026-6218 net/url, GO-2026-6090 crypto/tls, GO-2026-6089 net/http; fixed in 1.26.6). Release builds already used the latest 1.26 patch; this makes every toolchain path agree.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
govulncheckreports GO-2026-4887 and GO-2026-4883 againstgithub.com/docker/docker@v28.5.2+incompatibleas reachable, and that module has no fix in any version. This PR moves to the maintained SDK and adds a gate so the problem can't come back unnoticed.1.
build(deps): migrate Docker SDK to moby/moby client and apigithub.com/moby/moby/clientv0.6.0 andgithub.com/moby/moby/apiv1.56.0 (the latest).go mod why -m github.com/docker/dockernow reports "main module does not need module".dockerAPIandDockerInspectorinterfaces to the v29Options/Resultforms. The inspect response is flattened, and theState/Confignil guards stay because both fields are still pointers.consumeEventsnow checksctx.Err()before classifying a stream error. In v29 a cancelled stream can end with a closed-body error instead ofcontext.Canceled, which logged a spurious "docker events stream error, reconnecting" at shutdown. A new test fails without the fix.docker-sdkrule that deniesgithub.com/docker/docker/.go.opentelemetry.io/otel(indirect) to v1.44.0 to clear GO-2026-5158.2.
build(deps): add govulncheck and banned-module audit to make, pre-commit and CImake audit-depsrunsaudit-deps-go(pinned govulncheck v1.8.0 over./...) andaudit-deps-banned. The banned check fails if a module inBANNED_GO_MODULESis reachable, and prints thego mod whychain. It catches transitive reintroduction, which depguard cannot see.go.mod/go.sumchanges.audit-depsCI job runs it on every PR. The reviewdog pre-commit job only looks at changed files, so the hook alone would never run on most PRs.3.
build(go): require Go 1.26.8 to pick up stdlib security fixesaudit-depsCI job failed on its first run, and correctly so. CI jobs that readgo-version-filegot exactly go1.26.3, where govulncheck reports three reachable stdlib vulnerabilities: GO-2026-6218 (net/url), GO-2026-6090 (crypto/tls) and GO-2026-6089 (net/http), all fixed in 1.26.6.release.yamlusesgo-version: "1.26"and the Docker image builds ondhi.io/golang:1.godirective to 1.26.8 (the latest patch) makes every toolchain path agree.Testing
make go-vet,make go-test(race),make go-build,make check: pass.make audit-deps: "No vulnerabilities found.";github.com/docker/docker: not needed.make go-test-integrationagainst Docker 29.8.1: all 13 dry-run tests pass.docker/dockerreintroduced:audit-deps-bannedfails and prints the chain, and depguard fails on the import./dev/loop-controlis denied without the daemon, and can open it with the daemon andenable=true(real BPF rule,major=10 minor=237);ServiceInspectand gets access;systemctl daemon-reload(needs sudo; this PR doesn't touch that path beyondContainerList).Rollback: revert commit 2, then commit 1. No config, flag, wire or metric changes.
Pull request checklist
masterbranch (stacked; retargets tomasteronce the base PR merges)make checklocally before creating the commit and it has run successfullyWIPcommits in this PRType of changes