An open index of dependabot pull requests across open source projects.

github.com/docker/docker

Ecosystem:
go
Package URL:
pkg:golang/github.com/docker/docker
Total PRs:
5,467 Dependabot PRs
Latest PR:
14 days ago
Unique Repositories:
1,823 repositories
Unique Repos (30 days):
4 repositories
Security Advisories
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
GHSA-vp62-88p7-qqf5 CVE-2026-41568 MODERATE published 15 days ago • updated 3 days ago
## Summary A race condition during `docker cp` mount setup allows a malicious container to create empty files or directories at arbitrary absolute...
/sys/devices/virtual/powercap accessible by default to containers
GHSA-jq35-85cj-fj4p MODERATE published over 2 years ago • updated 5 days ago
Intel's RAPL (Running Average Power Limit) feature, introduced by the Sandy Bridge microarchitecture, provides software insights into hardware ener...
Arbitrary File Write in Libcontainer
GHSA-g44j-7vp3-68cv CVE-2015-3629 HIGH published over 4 years ago • updated about 18 hours ago
Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary fil...
Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
GHSA-2mm7-x5h6-5pvq CVE-2022-24769 MODERATE published about 2 years ago • updated 1 day ago
### Impact A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities...
Arbitrary File Override in Docker Engine
GHSA-v4h8-794j-g8mm CVE-2015-3631 MODERATE published over 4 years ago • updated 14 days ago
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes ...
Recent PRs (filtered by: Open , Major PRs )
build(deps): bump the engine group across 1 directory with 74 updates

samalba/dagger #280

26.1.0+incompatible → 28.5.2+incompatible Major PR
Open 2 months ago 1 comment
samalba
Bump the go_modules group across 35 directories with 8 updates

RemyLoveLogicAI/anyquery #11

27.5.0+incompatible → 28.0.0+incompatible Major PR
Open 3 months ago 5 comments
RemyLoveLogicAI
Bump the go_modules group across 1 directory with 8 updates

Wbaker7702/jfrog-cli #1

27.3.1+incompatible → 28.0.0+incompatible Major PR
Open 4 months ago 1 comment
Wbaker7702
build(deps): bump the go_modules group across 1 directory with 3 updates

BrianCLong/summit #17760

27.1.1+incompatible → 28.0.0+incompatible Major PR
Open 4 months ago 1 comment
BrianCLong
Bump the go_modules group across 6 directories with 5 updates

AKJUS/consul #123

24.0.5+incompatible → 25.0.13+incompatible Major PR
Open 5 months ago 2 comments
AKJUS
Bump github.com/docker/docker from 0.7.3-0.20190327010347-be7ac8be2ae0 to 25.0.13+incompatible

kmodules/kubectl #2

0.7.3-0.20190327010347-be7ac8be2ae0 → 25.0.13+incompatible Major PR
Open 5 months ago 1 comment
kmodules
Bump the go_modules group across 2 directories with 9 updates

q1blue/SuperCoder #3

26.1.4+incompatible → 28.0.0+incompatible Major PR
Open 6 months ago 2 comments
q1blue
Bump the go_modules group across 1 directory with 13 updates

spring-financial-group/helmfile #34

20.10.12+incompatible → 25.0.13+incompatible Major PR
Open 7 months ago 1 comment
spring-financial-group
Bump the go_modules group across 3 directories with 5 updates

peaceiris/pipecd #13

26.1.5+incompatible → 28.0.0+incompatible Major PR
Open 7 months ago 3 comments
peaceiris
Package Details
Name: github.com/docker/docker
Ecosystem: go
PURL Type: golang
Package URL: pkg:golang/github.com/docker/docker
JSON API: View JSON
Security Advisories

33

Active advisories
CRITICAL 2
HIGH 10
MODERATE 18
LOW 3
View All golang Advisories
Package Information
Description:

Repository: https://github.com/docker/docker
Homepage: https://github.com/docker/docker
Latest Release: v28.2.2+incompatible
about 1 year ago
Dependent Repos: 40,103
Dependent Packages: 16,935
Ranking: Top 0.0289% by dependent repos Top 0.0137% by dependent pkgs
PR Status
Open 2,557 (46.8%)
Merged 824 (15.1%)
Closed 1,692 (30.9%)
PR Types
Major 2,063 (37.7%)
Minor 2,025 (37.0%)
Patch 983 (18.0%)