An open index of dependabot pull requests across open source projects.

github.com/docker/docker

Ecosystem:
go
Package URL:
pkg:golang/github.com/docker/docker
Total PRs:
5,300 Dependabot PRs
Latest PR:
1 day ago
Unique Repositories:
1,751 repositories
Unique Repos (30 days):
28 repositories
Security Advisories
Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
GHSA-2mm7-x5h6-5pvq CVE-2022-24769 MODERATE published over 1 year ago • updated 8 days ago
### Impact A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities...
Arbitrary Code Execution
GHSA-997c-fj8j-rq5h CVE-2014-9357 HIGH published almost 4 years ago • updated about 1 month ago
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA...
Moby Docker cp broken with debian containers
GHSA-v2cv-wwxq-qq97 CVE-2019-14271 CRITICAL published over 3 years ago • updated about 1 month ago
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically load...
Privilege Escalation in Docker
GHSA-wxj3-qwv4-cvfm CVE-2014-3499 HIGH published almost 4 years ago • updated about 1 month ago
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecifi...
Docker Swarm encrypted overlay network traffic may be unencrypted
GHSA-33pg-m6jh-5237 CVE-2023-28841 MODERATE published over 2 years ago • updated about 1 month ago
[Moby](https://mobyproject.org/) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container R...
Recent PRs
chore(deps): bump the engine group across 2 directories with 5 updates

sipsma/dagger #1113

28.3.2+incompatible → 28.4.0+incompatible Minor PR
Open 4 months ago 1 comment
sipsma
Bump the docker group with 4 updates

robaiken/dpabot-cli-2 #1

28.2.2+incompatible → 28.4.0+incompatible Minor PR
Closed 4 months ago 1 comment
robaiken
build(deps): bump the dependabot group with 12 updates

ohsu-comp-bio/funnel #1245

28.3.3+incompatible → 28.4.0+incompatible Minor PR
Open 4 months ago
ohsu-comp-bio
chore(deps): bump the docker group across 1 directory with 2 updates

zarf-dev/zarf #4184

28.3.3+incompatible → 28.4.0+incompatible Minor PR
Open 4 months ago 6 comments
zarf-dev
chore(deps): bump the common group across 1 directory with 32 updates

aiflash/trivy #355

28.3.3+incompatible → 28.4.0+incompatible Minor PR
Open 4 months ago 2 comments
aiflash
chore(deps): bump the common group across 1 directory with 54 updates

maggieZzy785/trivy #36

27.5.1+incompatible → 28.4.0+incompatible Major PR
Open 4 months ago 1 comment
maggieZzy785
chore(deps): bump the engine group across 1 directory with 31 updates

sipsma/dagger #1111

28.3.2+incompatible → 28.4.0+incompatible Minor PR
Closed 4 months ago 2 comments
sipsma
chore(deps): bump the engine group across 2 directories with 32 updates

dagger/dagger #11046

28.3.2+incompatible → 28.4.0+incompatible Minor PR
Closed 4 months ago 3 comments
dagger
chore(deps): bump the engine group across 1 directory with 52 updates

shykes/dagger #430

27.3.1+incompatible → 28.4.0+incompatible Major PR
Open 4 months ago 1 comment
shykes
Bump the go-modules group across 1 directory with 13 updates

picatz/dynabuf #43

28.3.0+incompatible → 28.4.0+incompatible Minor PR
Open 4 months ago 1 comment
picatz
chore(deps): bump the docker group with 3 updates

aiflash/trivy #352

28.3.3+incompatible → 28.4.0+incompatible Minor PR
Closed 4 months ago 2 comments
aiflash
chore(deps): bump the common group across 1 directory with 31 updates

aiflash/trivy #350

28.3.3+incompatible → 28.4.0+incompatible Minor PR
Open 4 months ago 2 comments
aiflash
chore(deps): bump the common group across 1 directory with 54 updates

riddopic/trivy #163

27.5.0+incompatible → 28.4.0+incompatible Major PR
Closed 4 months ago 1 comment
riddopic
chore(deps): bump the common group across 1 directory with 41 updates

xycloops123/trivy #363

28.3.3+incompatible → 28.4.0+incompatible Minor PR
Closed 4 months ago 2 comments
xycloops123
Bump the all group across 1 directory with 17 updates

dependabot/cli #512

28.3.3+incompatible → 28.4.0+incompatible Minor PR
Merged 4 months ago
dependabot
Package Details
Name: github.com/docker/docker
Ecosystem: go
PURL Type: golang
Package URL: pkg:golang/github.com/docker/docker
JSON API: View JSON
Security Advisories

29

Active advisories
CRITICAL 2
HIGH 8
MODERATE 16
LOW 3
View All golang Advisories
Package Information
Description:

Repository: https://github.com/docker/docker
Homepage: https://github.com/docker/docker
Latest Release: v28.2.2+incompatible
7 months ago
Dependent Repos: 40,103
Dependent Packages: 16,935
Ranking: Top 0.0289% by dependent repos Top 0.0137% by dependent pkgs
PR Status
Open 2,496 (47.1%)
Merged 824 (15.6%)
Closed 1,585 (29.9%)
PR Types
Minor 2,002 (37.8%)
Major 1,966 (37.1%)
Patch 935 (17.6%)