You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The last 5 open Dependabot alerts are on github.com/docker/docker and github.com/docker/cli, three high and two medium. No version bump closes them: the Docker Go module moved to github.com/moby/moby/client and github.com/moby/moby/api after 28.x, and docker/cli 29 only builds against those. Part of #4051.
Exposure today: none.go list -deps ./cmd/livepeer links only docker/client, docker/api/types/*, errdefs, pkg/jsonmessage and cli/opts. No daemon package and no CLI plugin loader is compiled in, and the copy and archive client APIs the alerts describe are never called anywhere in the repo. All five bugs live in code we do not ship.
Scope.ai/worker/docker.go and its test. The worker uses Docker through a local DockerClient interface with eight methods: ContainerCreate, ContainerInspect, ContainerList, ContainerRemove, ContainerStart, ContainerStop, ImageInspectWithRaw, ImagePull. Around thirty type uses across eleven imports.
Add the moby client and api modules at the versions docker/cli 29 vendors, bump docker/cli to 29, drop docker/docker and go-connections if nothing else needs them.
Rewrite imports and renamed types, check the eight calls against the moby signatures, update the mock.
Remove the docker/cli ignore from .github/dependabot.yaml.
Verify on a GPU orchestrator end to end: pull, create with GPU devices and mounts, start, health check, stop, remove.
Risk of doing it. Contained to AI runner container management; failures are loud, not subtle. Same Docker API over the same socket, so no operator Docker upgrade. Ship with a canary orchestrator, not as a hotfix.
Risk of not doing it.
The daemon bugs are real on an orchestrator's host, but they are fixed by the operator's Docker installation, not by our go.mod. Bumping the module would protect nobody.
If code is later added that calls the copy or archive APIs, or the CLI plugin loader, the exposure becomes real and nothing re-flags it, because the alerts are already known-open.
Five permanently open alerts, three of them high, erode attention on the security page.
@j0sh Meaning it might not even be worth it if we deprecate the software for a more minimal modular stack soon.
The last 5 open Dependabot alerts are on
github.com/docker/dockerandgithub.com/docker/cli, three high and two medium. No version bump closes them: the Docker Go module moved togithub.com/moby/moby/clientandgithub.com/moby/moby/apiafter 28.x, and docker/cli 29 only builds against those. Part of #4051.Exposure today: none.
go list -deps ./cmd/livepeerlinks onlydocker/client,docker/api/types/*,errdefs,pkg/jsonmessageandcli/opts. No daemon package and no CLI plugin loader is compiled in, and the copy and archive client APIs the alerts describe are never called anywhere in the repo. All five bugs live in code we do not ship.Scope.
ai/worker/docker.goand its test. The worker uses Docker through a localDockerClientinterface with eight methods: ContainerCreate, ContainerInspect, ContainerList, ContainerRemove, ContainerStart, ContainerStop, ImageInspectWithRaw, ImagePull. Around thirty type uses across eleven imports.Work
.github/dependabot.yaml.Risk of doing it. Contained to AI runner container management; failures are loud, not subtle. Same Docker API over the same socket, so no operator Docker upgrade. Ship with a canary orchestrator, not as a hotfix.
Risk of not doing it.
go.mod. Bumping the module would protect nobody.@j0sh Meaning it might not even be worth it if we deprecate the software for a more minimal modular stack soon.