Package
skaffold-fips
Component
github.com/docker/docker
Latest update
8.8
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
CVE-2026-34040 (GHSA-x744-4wpc-v9h2) lives in Docker/Moby daemon packages (plugin/, pkg/authorization/, daemon/, and container/archive*). skaffold uses github.com/docker/docker only as a client for image build, registry, and log handling; go list -deps on cmd/skaffold confirms only api/types/* helpers plus registry, pkg/homedir, pkg/ioutils, pkg/jsonmessage, and pkg/stdcopy are linked into the binary, and the daemon packages where this vulnerability lives are not imported and therefore not present in the binary.
Status