Package
podman-5.8
Component
github.com/moby/buildkit
Latest update
8.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The CVE is fixed in github.com/moby/buildkit 0.28.1, but 0.28.1 requires github.com/cyphar/filepath-securejoin v0.6.0, which removes the
deprecated root-package OpenInRoot/Reopen aliases that go.podman.io/storage
v1.62.0 still calls — the bump fails the build (verified:undefined: securejoin.OpenInRoot/Reopen).
Bumping buildkit requires podman's storage dependency drops the deprecated securejoin API, an upstream change absent
from v5.8.5.
Status