Package
kyverno-1.17
Component
github.com/chrismellard/docker-credential-acr-env
Latest update
Aliases
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
GO-2026-6225 affects the Go module github.com/chrismellard/docker-credential-acr-env, which is present in this package only as an indirect (transitive) dependency.
No fixed version of the affected module is available. The Go vulnerability database records all versions as affected with no fixed release; the module has had no release since March 2023, and the upstream report remains open. The dependency version present here (v0.0.0-20230304212654-82a0ddb27589) is already the latest published version of that module. The maintained successor is published under a different module path (github.com/osscontainertools/docker-credential-acr), so remediation requires the upstream dependency to migrate to that successor; this package will pick up the fix once that migration is released upstream. As of this writing, the latest cosign release still depends on the affected module.
References:
Status