Skip to content

build(deps): migrate Docker SDK to moby/moby and add dependency audit - #16

Merged
leinardi merged 3 commits into
masterfrom
fix/moby-sdk-migration
Sep 25, 2026
Merged

leinardi merged 3 commits into
masterfrom
fix/moby-sdk-migration

Conversation

@leinardi

@leinardi leinardi commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Summary

Stacked on #15. This PR targets docs/port-runhold-skills because commit 1 updates the adversarial-review skill added there. Once that PR merges, GitHub retargets this one to master. Only the last three commits belong to this PR.

govulncheck reports GO-2026-4887 and GO-2026-4883 against github.com/docker/docker@v28.5.2+incompatible as reachable, and that module has no fix in any version. This PR moves to the maintained SDK and adds a gate so the problem can't come back unnoticed.

1. build(deps): migrate Docker SDK to moby/moby client and api

  • Moves to github.com/moby/moby/client v0.6.0 and github.com/moby/moby/api v1.56.0 (the latest). go mod why -m github.com/docker/docker now reports "main module does not need module".
  • Changes the dockerAPI and DockerInspector interfaces to the v29 Options/Result forms. The inspect response is flattened, and the State/Config nil guards stay because both fields are still pointers.
  • Fixes the shutdown log: consumeEvents now checks ctx.Err() before classifying a stream error. In v29 a cancelled stream can end with a closed-body error instead of context.Canceled, which logged a spurious "docker events stream error, reconnecting" at shutdown. A new test fails without the fix.
  • Adds a depguard docker-sdk rule that denies github.com/docker/docker/.
  • Bumps go.opentelemetry.io/otel (indirect) to v1.44.0 to clear GO-2026-5158.
  • Docs: requires Docker Engine 19.03+ (API 1.40), because the v29 client refuses older engines. No engine minimum was documented before.

2. build(deps): add govulncheck and banned-module audit to make, pre-commit and CI

  • make audit-deps runs audit-deps-go (pinned govulncheck v1.8.0 over ./...) and audit-deps-banned. The banned check fails if a module in BANNED_GO_MODULES is reachable, and prints the go mod why chain. It catches transitive reintroduction, which depguard cannot see.
  • A pre-commit hook runs it on go.mod/go.sum changes.
  • A dedicated audit-deps CI job runs it on every PR. The reviewdog pre-commit job only looks at changed files, so the hook alone would never run on most PRs.

3. build(go): require Go 1.26.8 to pick up stdlib security fixes

  • The new audit-deps CI job failed on its first run, and correctly so. CI jobs that read go-version-file got exactly go1.26.3, where govulncheck reports three reachable stdlib vulnerabilities: GO-2026-6218 (net/url), GO-2026-6090 (crypto/tls) and GO-2026-6089 (net/http), all fixed in 1.26.6.
  • Release artifacts were not affected: release.yaml uses go-version: "1.26" and the Docker image builds on dhi.io/golang:1.
  • Raising the go directive to 1.26.8 (the latest patch) makes every toolchain path agree.

Testing

  • make go-vet, make go-test (race), make go-build, make check: pass.
  • make audit-deps: "No vulnerabilities found."; github.com/docker/docker: not needed.
  • make go-test-integration against Docker 29.8.1: all 13 dry-run tests pass.
  • Negative checks in a scratch worktree with docker/docker reintroduced: audit-deps-banned fails and prints the chain, and depguard fails on the import.
  • Real (non-dry-run) run of the built image on a single-node Swarm manager with cgroup v2:
    • a container bind-mounting /dev/loop-control is denied without the daemon, and can open it with the daemon and enable=true (real BPF rule, major=10 minor=237);
    • a Swarm service with only a service-level label is opted in via ServiceInspect and gets access;
    • 11 start/stop cycles log no stream error at shutdown.
  • Not tested: re-applying rules after systemctl daemon-reload (needs sudo; this PR doesn't touch that path beyond ContainerList).

Rollback: revert commit 2, then commit 1. No config, flag, wire or metric changes.

Pull request checklist

  • I am targeting the master branch (stacked; retargets to master once the base PR merges)
  • I have rebased this branch on top of the destination branch
  • I have executed make check locally before creating the commit and it has run successfully
  • I have performed a self-review of my own code
  • There are no WIP commits in this PR

Type of changes

  • 🐛 Bug fix
  • ✨ New feature
  • 🔧 Refactoring
  • 📜 Docs
  • 🧰 CI / tooling / infra
  • Other (describe in Summary)

github.com/docker/docker is affected by GO-2026-4887 and GO-2026-4883 in every version with no fix, and govulncheck reports both as reachable. The daemon now uses github.com/moby/moby/client v0.6.0 and github.com/moby/moby/api v1.56.0; docker/docker is no longer in the module graph, and a depguard rule keeps direct imports out.

consumeEvents checks ctx.Err before classifying a stream error, so a closed-body error at shutdown no longer logs a spurious reconnect. go.opentelemetry.io/otel moves to v1.44.0 to clear GO-2026-5158. The v29 client refuses engines older than API 1.40, so Docker Engine 19.03+ is now documented as required.
…mit and CI

make audit-deps runs the pinned govulncheck over every package and fails if github.com/docker/docker is reachable from the main module, printing the go mod why chain; depguard only sees direct imports, so this is the transitive guard.

It runs as a pre-commit hook on go.mod and go.sum changes and as a dedicated CI job on every pull request, since the reviewdog pre-commit job only sees changed files.
CI jobs that read go-version-file from go.mod installed exactly go1.26.3, which govulncheck reports as reachable-vulnerable (GO-2026-6218 net/url, GO-2026-6090 crypto/tls, GO-2026-6089 net/http; fixed in 1.26.6). Release builds already used the latest 1.26 patch; this makes every toolchain path agree.
Base automatically changed from docs/port-runhold-skills to master September 25, 2026 14:14
@leinardi
leinardi merged commit 8aa833b into master Sep 25, 2026
7 checks passed
@leinardi
leinardi deleted the fix/moby-sdk-migration branch September 25, 2026 14:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant