Skip to content

fix(security): update docker version; update dependencies#132

Merged
alinashklyar merged 1 commit into
masterfrom
CR-39175-security
Jun 5, 2026
Merged

fix(security): update docker version; update dependencies#132
alinashklyar merged 1 commit into
masterfrom
CR-39175-security

Conversation

@alinashklyar
Copy link
Copy Markdown
Contributor

@alinashklyar alinashklyar commented Jun 4, 2026

What

Why

Notes

Labels

Assign the following labels to the PR:

security - to trigger image scanning in CI build

PR Comments

Add the following comments to the PR:

/e2e - to trigger E2E build

Security Report

Important

Current summary is in beta mode.
Please analyze the full scan report for comprehensive details.

Fixed CVEs: 24

🔴 High: 10

  • CVE-2026-42499 in net/mail@1.25.8 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2026-42499 in net/mail@1.26.2 at /usr/local/bin/containerd
  • CVE-2026-39820 in net/mail@1.26.2 at /usr/local/bin/containerd
  • CVE-2026-39820 in net/mail@1.25.8 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2026-3805 in curl@8.17.0-r1 at unknown path
  • CVE-2026-33811 in net@1.25.8 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2026-32283 in crypto/tls@1.25.8 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2026-32281 in crypto/x509@1.25.8 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2026-32280 in crypto/x509@1.25.8 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2026-35469 in github.com/moby/spdystream@v0.5.0 at /usr/local/libexec/docker/cli-plugins/docker-buildx

🟠 Medium: 13

🟡 Low: 1

🔗 View all related Jira tickets

@alinashklyar
Copy link
Copy Markdown
Contributor Author

/e2e

@alinashklyar alinashklyar merged commit 67b378d into master Jun 5, 2026
4 checks passed
@alinashklyar alinashklyar deleted the CR-39175-security branch June 5, 2026 07:04
alinashklyar added a commit that referenced this pull request Jun 5, 2026
* update docker version; update dependencies (#132)

(cherry picked from commit 67b378d)

* get rig of removal of /usr/local/bin/vpnkit
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants