gitlab-runner-17.11
Chainguard
Status
Justification
Impact
github.com/docker/docker v25.0.6+incompatible was incorrectly flagged due to a vulnerability-component mismatch; this version matches the v25.0.6 upstream release: https://github.com/moby/moby/releases/tag/v25.0.6 which includes the fix for GHSA-gh5c-3h97-2f3q: https://github.com/moby/moby/commit/8e3bcf19748838b30e34d612832d1dc9d90363b8 The +incompatible suffix is a Go module artifact and does not affect vulnerability status.
Status
Impact
Unable to use govulncheck to triage this advisory because the vulnerability was not found in the Go vuln DB. Treating as a true positive since we can't confirm this is a false positive.
Status
Status
Impact
Upgrading the github.com/docker/docker dependency to >= v26 resulting build failure: "undefined: types.ContainerStartOptions".