Skip to content

security: fix CVE-2026-26960 and harden Docker Scout gate#46

Merged
neverinfamous merged 4 commits intomasterfrom
fix/cve-2026-26960
Feb 18, 2026
Merged

security: fix CVE-2026-26960 and harden Docker Scout gate#46
neverinfamous merged 4 commits intomasterfrom
fix/cve-2026-26960

Conversation

@neverinfamous
Copy link
Copy Markdown
Owner

Changes

Security

  • CVE-2026-26960 (tar < 7.5.8) — Added explicit tar@latest upgrade in Dockerfile to fix path traversal vulnerability in npm's bundled tar
  • Docker Scout gate hardened — Scan now blocks deployments on any fixable CVE using --only-fixed --exit-code. Unfixable zero-days pass through.

Documentation

  • Optimized README/DOCKER_README code blocks for direct copy-paste
  • Trimmed DOCKER_README for Docker Hub character limit
  • Added changelog entries

@neverinfamous neverinfamous merged commit 8a193d1 into master Feb 18, 2026
8 checks passed
@neverinfamous neverinfamous deleted the fix/cve-2026-26960 branch February 18, 2026 18:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant