Skip to content

chore: merge v0.14.1 - #41

Draft
janishorsts wants to merge 6 commits into
chore-merge-v0.14.1-unresolvedfrom
chore-merge-v0.14.1
Draft

janishorsts wants to merge 6 commits into
chore-merge-v0.14.1-unresolvedfrom
chore-merge-v0.14.1

Conversation

@janishorsts

@janishorsts janishorsts commented Oct 2, 2026 •

Copy link
Copy Markdown

@janishorsts
janishorsts added this pull request to stack #42 October 2, 2026 20:27
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🎉 Are we earthbuild yet?

Great progress! You've reduced "earthly" occurrences by 10 (4.61%)

📈 Overall Progress

Branch Total Count
main 217
This PR 207
Difference -10 (4.61%)

📁 Changes by file type:

File Type Change
Go files (.go) ✅ -9
Documentation (.md) ➖ No change
Earthfiles ➖ No change

Keep up the great work migrating from Earthly to Earthbuild! 🚀

💡 Tips for finding more occurrences

Run locally to see detailed breakdown:

./.github/scripts/count-earthly.sh

Note that the goal is not to reach 0.
There is anticipated to be at least some occurences of earthly in the source code due to backwards compatibility with config files and language constructs.

@socket-security

socket-security Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedgolang/​github.com/​docker/​docker@​v26.1.4+incompatible7225100100100
Addedgolang/​golang.org/​x/​crypto@​v0.21.07325100100100
Addedgolang/​google.golang.org/​grpc@​v1.59.07525100100100
Addedgolang/​github.com/​google/​shlex@​v0.0.0-20191202100458-e7afc7fbc51010010010050100
Addedgolang/​github.com/​hashicorp/​go-cleanhttp@​v0.5.21001001007570
Addedgolang/​github.com/​hashicorp/​go-immutable-radix@​v1.3.11001001007570
Addedgolang/​github.com/​hashicorp/​go-multierror@​v1.1.11001001007570
Addedgolang/​github.com/​hashicorp/​golang-lru@​v0.5.410010010010070
Addedgolang/​github.com/​opencontainers/​go-digest@​v1.0.01001001007570
Addedgolang/​github.com/​spdx/​tools-golang@​v0.5.39510010010070
Addedgolang/​kernel.org/​pub/​linux/​libs/​security/​libcap/​cap@​v1.2.6710010010010070
Addedgolang/​github.com/​containerd/​stargz-snapshotter@​v0.15.17110010010080
Addedgolang/​github.com/​aws/​aws-sdk-go-v2@​v1.24.171100100100100
Addedgolang/​github.com/​containernetworking/​plugins@​v1.4.072100100100100
Addedgolang/​github.com/​docker/​distribution@​v2.8.2+incompatible73100100100100
Addedgolang/​github.com/​containerd/​containerd@​v1.7.187573100100100
Addedgolang/​github.com/​containerd/​nydus-snapshotter@​v0.13.773100100100100
Addedgolang/​go.opentelemetry.io/​otel@​v1.21.074100100100100
Addedgolang/​github.com/​docker/​cli@​v26.1.4+incompatible7485100100100
Addedgolang/​github.com/​Microsoft/​hcsshim@​v0.11.574100100100100
Addedgolang/​golang.org/​x/​net@​v0.23.07580100100100
Addedgolang/​google.golang.org/​protobuf@​v1.33.075100100100100
Addedgolang/​github.com/​agext/​levenshtein@​v1.2.31001001007580
Addedgolang/​github.com/​armon/​circbuf@​v0.0.0-20190214190532-5111143e8da210010010075100
Addedgolang/​github.com/​gogo/​googleapis@​v1.4.19810010075100
Addedgolang/​github.com/​gogo/​protobuf@​v1.3.27610010075100
Addedgolang/​github.com/​mitchellh/​hashstructure/​v2@​v2.0.210010010075100
Addedgolang/​github.com/​moby/​locker@​v1.0.110010010075100
Addedgolang/​github.com/​pkg/​errors@​v0.9.110010010075100
Addedgolang/​github.com/​serialx/​hashring@​v0.0.0-20200727003509-22c0c7ab6b1b10010010075100
Addedgolang/​github.com/​tonistiigi/​units@​v0.0.0-20180711220420-6950e57a87ea10010010075100
Addedgolang/​github.com/​vishvananda/​netlink@​v1.2.1-beta.276100100100100
See 67 more rows in the dashboard

View full report

@socket-security

socket-security Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Critical priority
Critical CVE: Authz zero length regression in golang github.com/docker/docker

CVE: GHSA-v23v-6jw2-98fq Authz zero length regression (CRITICAL)

Affected versions: >= 19.03.0 < 23.0.15; >= 26.0.0 < 26.1.5; >= 27.0.0 < 27.1.1; >= 24.0.0 < 25.0.6

Patched version: 26.1.5

From: go.mod → golang/github.com/docker/docker@v26.1.4+incompatible

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/github.com/docker/docker@v26.1.4+incompatible. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Critical priority
Critical CVE: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang golang.org/x/crypto

CVE: GHSA-v778-237x-gjrc Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CRITICAL)

Affected versions: < 0.31.0

Patched version: 0.31.0

From: go.mod → golang/golang.org/x/crypto@v0.21.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/golang.org/x/crypto@v0.21.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Critical priority
Critical CVE: golang golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

CVE: GHSA-89gr-r52h-f8rx golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed (CRITICAL)

Affected versions: < 0.52.0

Patched version: 0.52.0

From: go.mod → golang/golang.org/x/crypto@v0.21.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/golang.org/x/crypto@v0.21.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Critical priority
Critical CVE: golang golang.org/x/crypto vulnerable to auth bypass via unenforced @Revoked status

CVE: GHSA-5cgq-3rg8-m6cv golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status (CRITICAL)

Affected versions: < 0.52.0

Patched version: 0.52.0

From: go.mod → golang/golang.org/x/crypto@v0.21.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/golang.org/x/crypto@v0.21.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Critical priority
Critical CVE: golang golang.org/x/crypto vulnerable to infinite loop on large channel writes

CVE: GHSA-rm3j-f69w-wqmq golang.org/x/crypto vulnerable to infinite loop on large channel writes (CRITICAL)

Affected versions: < 0.52.0

Patched version: 0.52.0

From: go.mod → golang/golang.org/x/crypto@v0.21.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/golang.org/x/crypto@v0.21.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Critical priority
Critical CVE: golang golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

CVE: GHSA-x527-x647-q7gg golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement (CRITICAL)

Affected versions: < 0.52.0

Patched version: 0.52.0

From: go.mod → golang/golang.org/x/crypto@v0.21.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/golang.org/x/crypto@v0.21.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Critical priority
Critical CVE: golang golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CVE: GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses (CRITICAL)

Affected versions: < 0.52.0

Patched version: 0.52.0

From: go.mod → golang/golang.org/x/crypto@v0.21.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/golang.org/x/crypto@v0.21.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Critical priority
Critical CVE: golang golang.org/x/crypto doesn't enforce invoking key constraints

CVE: GHSA-jppx-rxg9-jmrx golang.org/x/crypto doesn't enforce invoking key constraints (CRITICAL)

Affected versions: < 0.52.0

Patched version: 0.52.0

From: go.mod → golang/golang.org/x/crypto@v0.21.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/golang.org/x/crypto@v0.21.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Critical priority
Critical CVE: golang golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

CVE: GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys (CRITICAL)

Affected versions: < 0.52.0

Patched version: 0.52.0

From: go.mod → golang/golang.org/x/crypto@v0.21.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/golang.org/x/crypto@v0.21.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Critical priority
Critical CVE: gRPC-Go has an authorization bypass via missing leading slash in :path in golang google.golang.org/grpc

CVE: GHSA-p77j-4mvh-x3m3 gRPC-Go has an authorization bypass via missing leading slash in :path (CRITICAL)

Affected versions: < 1.79.3

Patched version: 1.79.3

From: go.mod → golang/google.golang.org/grpc@v1.59.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/google.golang.org/grpc@v1.59.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant