Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@ require (
github.com/charmbracelet/bubbletea v1.3.6
github.com/charmbracelet/lipgloss v1.1.0
github.com/charmbracelet/x/term v0.2.1
github.com/docker/docker v28.5.2+incompatible
github.com/docker/docker v28.5.3-0.20260325120914-0afb41ce194c+incompatible

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Insufficient docker dependency pin

Medium Severity

go.mod now pins github.com/docker/docker to a pseudo-version instead of upgrading go-containerregistry. That keeps the old docker client on the graph, so a pin in this range may not include the docker cp fix for GHSA-rg2x-37c3-w2rh.

Fix in Cursor Fix in Web

Triggered by learned rule: Prefer upgrading go-containerregistry over docker/docker replace pins

Reviewed by Cursor Bugbot for commit 22e9c31. Configure here.

github.com/google/go-containerregistry v0.20.7
github.com/gorilla/websocket v1.5.3
github.com/itchyny/json2yaml v0.1.4
github.com/kernel/hypeman-go v0.28.0
github.com/kernel/hypeman-go v0.28.1-0.20261001160305-134587a222ac
github.com/knadh/koanf/parsers/yaml v1.1.0
github.com/knadh/koanf/providers/env v1.1.0
github.com/knadh/koanf/providers/file v1.2.1
Expand Down
Loading
Loading