An open index of dependabot pull requests across open source projects.

github.com/containerd/containerd

Ecosystem:
go
Package URL:
pkg:golang/github.com/containerd/containerd
Total PRs:
805 Dependabot PRs
Latest PR:
10 days ago
Unique Repositories:
499 repositories
Unique Repos (30 days):
20 repositories
Security Advisories
containerd-shim API Exposed to Host Network Containers
GHSA-36xw-fx78-c5r4 CVE-2020-15257 MODERATE published about 5 years ago • updated about 2 hours ago
## Impact Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwise restrict...
OCI image importer memory exhaustion in github.com/containerd/containerd
GHSA-259w-8hf6-59c2 CVE-2023-25153 MODERATE published over 3 years ago • updated 5 days ago
### Impact When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large ...
containerd CRI server: Host memory exhaustion through Attach goroutine leak
GHSA-m6hq-p25p-ffr2 CVE-2025-64329 MODERATE published 7 months ago • updated 1 day ago
### Impact A bug was found in containerd's CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. Repetit...
Archive package allows chmod of file outside of unpack target directory
GHSA-c72p-9xmj-rx3w CVE-2021-32760 MODERATE published almost 5 years ago • updated 10 days ago
## Impact A bug was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission change...
containerd affected by a local privilege escalation via wide permissions on CRI directory
GHSA-pwhc-rpq9-4c8w CVE-2024-25621 HIGH published 7 months ago • updated 1 day ago
### Impact An overly broad default permission vulnerability was found in containerd. - `/var/lib/containerd` was created with the permission bits...
Recent PRs
Package Details
Name: github.com/containerd/containerd
Ecosystem: go
PURL Type: golang
Package URL: pkg:golang/github.com/containerd/containerd
JSON API: View JSON
Security Advisories

18

Active advisories
HIGH 4
MODERATE 12
LOW 2
View All golang Advisories
Package Information
Description:

Repository: https://github.com/containerd/containerd
Homepage: https://github.com/containerd/containerd
Latest Release: v1.7.27
about 1 year ago
Dependent Repos: 26,380
Dependent Packages: 9,153
Ranking: Top 0.0379% by dependent repos Top 0.0279% by dependent pkgs
PR Status
Open 420 (52.2%)
Merged 44 (5.5%)
Closed 288 (35.8%)
PR Types
Minor 109 (13.5%)
Patch 643 (79.9%)