Skip to content

refactor: update dependency github.com/ory/dockertest to v4#370

Merged
anderseknert merged 2 commits intoopen-policy-agent:mainfrom
szuecs:refactor/update-dockertest-to-v4
Apr 10, 2026
Merged

refactor: update dependency github.com/ory/dockertest to v4#370
anderseknert merged 2 commits intoopen-policy-agent:mainfrom
szuecs:refactor/update-dockertest-to-v4

Conversation

@szuecs
Copy link
Copy Markdown
Contributor

@szuecs szuecs commented Apr 5, 2026

refactor: update dependency github.com/ory/dockertest to v4 to get rid of old docker dependency

This is needed to fix osv-scanner finding caused by github.com/ory/dockertest/v3 having a dependency to an outdated docker/docker, version.

% go mod why -m github.com/docker/docker
# github.com/docker/docker
github.com/zalando/skipper/filters/openpolicyagent
github.com/open-policy-agent/eopa/pkg/plugins/decision_logs
github.com/open-policy-agent/eopa/internal/benthos/elasticsearch
github.com/open-policy-agent/eopa/internal/benthos/impl/elasticsearch
github.com/open-policy-agent/eopa/internal/benthos/impl/elasticsearch.test
github.com/ory/dockertest/v3
github.com/ory/dockertest/v3/docker/opts
github.com/docker/cli/cli/compose/loader
github.com/docker/docker/api/types/mount

ref:
https://osv.dev/vulnerability/GHSA-x744-4wpc-v9h2
https://osv.dev/vulnerability/GHSA-pxq6-2prw-chj9
testcontainers/testcontainers-go#3591

…d of old docker dependency

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
@szuecs
Copy link
Copy Markdown
Contributor Author

szuecs commented Apr 7, 2026

@anderseknert would be great to get the test run and a review after successful test runs.

Copy link
Copy Markdown
Member

@anderseknert anderseknert left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks fine to me!

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
@szuecs
Copy link
Copy Markdown
Contributor Author

szuecs commented Apr 8, 2026

I need another approval for test run, go version was too old to run the tools.

@szuecs
Copy link
Copy Markdown
Contributor Author

szuecs commented Apr 8, 2026

@anderseknert I need a click to approve the test run

@anderseknert
Copy link
Copy Markdown
Member

Sorry about the delay! I don't check my email too often 😅

@szuecs
Copy link
Copy Markdown
Contributor Author

szuecs commented Apr 9, 2026

@anderseknert the e2e likely only needs a retry , because it failed to download x/test dependency.
For the "check / test (pull request)" failure I have no idea, yet. Maybe you have an idea?
Or maybe retry this, too and we check if the same failures (TestBenthosPulsar/plain and TestLocalFileData/two_polls_-_yaml ) happen again.

@anderseknert anderseknert merged commit 769c001 into open-policy-agent:main Apr 10, 2026
81 of 83 checks passed
@anderseknert
Copy link
Copy Markdown
Member

Thanks!

@szuecs szuecs deleted the refactor/update-dockertest-to-v4 branch April 10, 2026 16:34
ponimas pushed a commit to zalando/skipper that referenced this pull request Apr 13, 2026
- testcontainers-go depends on docker/docker
- eopa depends on docker/docker

Both depend only in tests/examples on docker/docker , so CVE is not a
vulnerability in skipper binary.

testcontainers-go was fixed
testcontainers/testcontainers-go#3591
eopa we are working on a fix
open-policy-agent/eopa#370

---------

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants