chore(deps): upgrade testcontainers-go to v0.41.0#142
Merged
Conversation
- Upgrade testcontainers-go from v0.40.0 to v0.41.0 - Bump docker/docker from v28.5.1 to v28.5.2 (latest available) - Update transitive dependencies: otel v1.41.0, moby/go-archive v0.2.0, moby/term v0.5.2 Note: CVE-2026-34040 (docker/docker AuthZ plugin bypass) requires v29.3.1, which is only available as github.com/moby/moby/v2. Full remediation is blocked until testcontainers-go migrates to the new module path (PR 3591). Actual risk is negligible: test-only indirect dependency, AuthZ vulnerability is not reachable through the client SDK.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
CVE-2026-34040 Note
The Trivy scan flags docker/docker < v29.3.1 for CVE-2026-34040 (AuthZ plugin bypass, HIGH). However, v29.3.1 is not available under the github.com/docker/docker Go module path - Docker v29+ was published as github.com/moby/moby/v2. Full remediation is blocked until testcontainers-go migrates to the new module path (testcontainers PR #3591).
Actual risk is negligible:
Test plan
Generated with Claude Code