Update module github.com/docker/cli to v29 [SECURITY] - autoclosed #1560

Closed
viceice-bot wants to merge 1 commit from renovate/go-github.com-docker-cli-vulnerability into main
Member

This PR contains the following updates:

Package Change Age Confidence
github.com/docker/cli v28.5.2+incompatiblev29.2.0+incompatible age confidence

Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows in github.com/docker/cli

BIT-docker-cli-2025-15558 / CVE-2025-15558 / GHSA-p436-gjf2-799p / GO-2026-4610

More information

Details

Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows in github.com/docker/cli

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Release Notes

docker/cli (github.com/docker/cli)

v29.2.0+incompatible

Compare Source

v29.1.5+incompatible

Compare Source

v29.1.4+incompatible

Compare Source

v29.1.3+incompatible

Compare Source

v29.1.2+incompatible

Compare Source

v29.1.1+incompatible

Compare Source

v29.1.0+incompatible

Compare Source

v29.0.4+incompatible

Compare Source

v29.0.3+incompatible

Compare Source

v29.0.2+incompatible

Compare Source

v29.0.1+incompatible

Compare Source

v29.0.0+incompatible

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [github.com/docker/cli](https://github.com/docker/cli) | `v28.5.2+incompatible` → `v29.2.0+incompatible` | ![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fdocker%2fcli/v29.2.0+incompatible?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fdocker%2fcli/v28.5.2+incompatible/v29.2.0+incompatible?slim=true) | --- ### Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows in github.com/docker/cli BIT-docker-cli-2025-15558 / [CVE-2025-15558](https://nvd.nist.gov/vuln/detail/CVE-2025-15558) / [GHSA-p436-gjf2-799p](https://github.com/advisories/GHSA-p436-gjf2-799p) / [GO-2026-4610](https://pkg.go.dev/vuln/GO-2026-4610) <details> <summary>More information</summary> #### Details Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows in github.com/docker/cli #### Severity Unknown #### References - [https://github.com/docker/cli/security/advisories/GHSA-p436-gjf2-799p](https://github.com/docker/cli/security/advisories/GHSA-p436-gjf2-799p) - [https://github.com/docker/cli/commit/13759330b1f7e7cb0d67047ea42c5482548ba7fa](https://github.com/docker/cli/commit/13759330b1f7e7cb0d67047ea42c5482548ba7fa) - [https://github.com/docker/cli/pull/6713](https://github.com/docker/cli/pull/6713) - [https://github.com/docker/compose/pull/12300](https://github.com/docker/compose/pull/12300) - [https://docs.docker.com/desktop/release-notes](https://docs.docker.com/desktop/release-notes) - [https://www.zerodayinitiative.com/advisories/ZDI-CAN-28304](https://www.zerodayinitiative.com/advisories/ZDI-CAN-28304) This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-4610) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)). </details> --- ### Release Notes <details> <summary>docker/cli (github.com/docker/cli)</summary> ### [`v29.2.0+incompatible`](https://github.com/docker/cli/compare/v29.1.5...v29.2.0) [Compare Source](https://github.com/docker/cli/compare/v29.1.5...v29.2.0) ### [`v29.1.5+incompatible`](https://github.com/docker/cli/compare/v29.1.4...v29.1.5) [Compare Source](https://github.com/docker/cli/compare/v29.1.4...v29.1.5) ### [`v29.1.4+incompatible`](https://github.com/docker/cli/compare/v29.1.3...v29.1.4) [Compare Source](https://github.com/docker/cli/compare/v29.1.3...v29.1.4) ### [`v29.1.3+incompatible`](https://github.com/docker/cli/compare/v29.1.2...v29.1.3) [Compare Source](https://github.com/docker/cli/compare/v29.1.2...v29.1.3) ### [`v29.1.2+incompatible`](https://github.com/docker/cli/compare/v29.1.1...v29.1.2) [Compare Source](https://github.com/docker/cli/compare/v29.1.1...v29.1.2) ### [`v29.1.1+incompatible`](https://github.com/docker/cli/compare/v29.1.0...v29.1.1) [Compare Source](https://github.com/docker/cli/compare/v29.1.0...v29.1.1) ### [`v29.1.0+incompatible`](https://github.com/docker/cli/compare/v29.0.4...v29.1.0) [Compare Source](https://github.com/docker/cli/compare/v29.0.4...v29.1.0) ### [`v29.0.4+incompatible`](https://github.com/docker/cli/compare/v29.0.3...v29.0.4) [Compare Source](https://github.com/docker/cli/compare/v29.0.3...v29.0.4) ### [`v29.0.3+incompatible`](https://github.com/docker/cli/compare/v29.0.2...v29.0.3) [Compare Source](https://github.com/docker/cli/compare/v29.0.2...v29.0.3) ### [`v29.0.2+incompatible`](https://github.com/docker/cli/compare/v29.0.1...v29.0.2) [Compare Source](https://github.com/docker/cli/compare/v29.0.1...v29.0.2) ### [`v29.0.1+incompatible`](https://github.com/docker/cli/compare/v29.0.0...v29.0.1) [Compare Source](https://github.com/docker/cli/compare/v29.0.0...v29.0.1) ### [`v29.0.0+incompatible`](https://github.com/docker/cli/compare/v28.5.2...v29.0.0) [Compare Source](https://github.com/docker/cli/compare/v28.5.2...v29.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTQuNSIsInVwZGF0ZWRJblZlciI6IjQzLjIxNC41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJLaW5kL0RlcGVuZGVuY3lVcGRhdGUiLCJydW4tZW5kLXRvLWVuZC10ZXN0cyJdfQ==-->
Update module github.com/docker/cli to v29 [SECURITY]
Some checks failed
test-multi-platform / Build Forgejo Runner (pull_request) Has been skipped
cascade / debug (pull_request_target) Has been skipped
test-multi-platform / validate mocks (pull_request) Has been skipped
issue-labels / release-notes (pull_request_target) Has been skipped
test-multi-platform / Build unsupported platforms (pull_request) Has been skipped
test-multi-platform / validate pre-commit-hooks file (pull_request) Has been skipped
checks / validate mocks (pull_request) Successful in 26s
checks / validate pre-commit-hooks file (pull_request) Successful in 31s
checks / Build Forgejo Runner (pull_request) Failing after 35s
test-multi-platform / runner exec tests (pull_request) Has been skipped
test-multi-platform / Run integration tests with Docker (docker-latest) (pull_request) Has been skipped
test-multi-platform / Run integration tests with Docker (docker-stable) (pull_request) Has been skipped
test-multi-platform / Run integration tests with Podman (pull_request) Has been skipped
Integration tests for the release process / release-simulation (pull_request) Failing after 4m22s
checks / Build unsupported platforms (pull_request) Has been skipped
checks / runner exec tests (pull_request) Has been skipped
checks / Run integration tests with Docker (docker-latest) (pull_request) Has been skipped
checks / Run integration tests with Docker (docker-stable) (pull_request) Has been skipped
checks / Run integration tests with Podman (pull_request) Has been skipped
test-multi-platform / arm64 (pull_request) Has been skipped
cascade / end-to-end (pull_request_target) Successful in 5s
cascade / forgejo (pull_request_target) Successful in 1m18s
c58dae5038
Author
Member

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 2 additional dependencies were updated

Details:

Package Change
github.com/docker/go-connections v0.6.0 -> v0.7.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.46.1 -> v0.60.0
### ℹ️ Artifact update notice ##### File name: go.mod In order to perform the update(s) described in the table above, Renovate ran the `go get` command, which resulted in the following additional change(s): - 2 additional dependencies were updated Details: | **Package** | **Change** | | :-------------------------------------------------------------- | :--------------------- | | `github.com/docker/go-connections` | `v0.6.0` -> `v0.7.0` | | `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` | `v0.46.1` -> `v0.60.0` |
Contributor

cascading-pr updated at actions/setup-forgejo#1009

cascading-pr updated at https://code.forgejo.org/actions/setup-forgejo/pulls/1009
viceice-bot changed title from Update module github.com/docker/cli to v29 [SECURITY] to Update module github.com/docker/cli to v29 [SECURITY] - autoclosed 2026-07-02 06:05:14 +00:00
viceice-bot closed this pull request 2026-07-02 06:05:14 +00:00
Some checks failed
test-multi-platform / Build Forgejo Runner (pull_request) Has been skipped
cascade / debug (pull_request_target) Has been skipped
Required
Details
test-multi-platform / validate mocks (pull_request) Has been skipped
issue-labels / release-notes (pull_request_target) Has been skipped
test-multi-platform / Build unsupported platforms (pull_request) Has been skipped
test-multi-platform / validate pre-commit-hooks file (pull_request) Has been skipped
checks / validate mocks (pull_request) Successful in 26s
checks / validate pre-commit-hooks file (pull_request) Successful in 31s
checks / Build Forgejo Runner (pull_request) Failing after 35s
Required
Details
test-multi-platform / runner exec tests (pull_request) Has been skipped
test-multi-platform / Run integration tests with Docker (docker-latest) (pull_request) Has been skipped
test-multi-platform / Run integration tests with Docker (docker-stable) (pull_request) Has been skipped
test-multi-platform / Run integration tests with Podman (pull_request) Has been skipped
Integration tests for the release process / release-simulation (pull_request) Failing after 4m22s
checks / Build unsupported platforms (pull_request) Has been skipped
checks / runner exec tests (pull_request) Has been skipped
Required
Details
checks / Run integration tests with Docker (docker-latest) (pull_request) Has been skipped
Required
Details
checks / Run integration tests with Docker (docker-stable) (pull_request) Has been skipped
Required
Details
checks / Run integration tests with Podman (pull_request) Has been skipped
Required
Details
test-multi-platform / arm64 (pull_request) Has been skipped
cascade / end-to-end (pull_request_target) Successful in 5s
Required
Details
cascade / forgejo (pull_request_target) Successful in 1m18s
Required
Details

Pull request closed

Sign in to join this conversation.
No reviewers
forgejo/Reviewers
No milestone
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
forgejo/runner!1560
No description provided.