Repository navigation
Fix 4 CVEs (CVE-2026-56864, CVE-2026-56865, CVE-2026-84304, ...) - #194
rhwa-cve-pr-creator[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
mshitrit
left a comment
There was a problem hiding this comment.
2 Nits:
an unreleased grpc version is used where there are multiple existing stable grpc versions which also fixes this vulnerability (i.e v1.83.2 and v1.84.0. ect... )
a higher go version is required for the vulnerability fix (e.g 1.26.6+) even though it's not relevant downstream (main priority) as the version is overridden it still means that upstream fix isn't complete.
/hold
holding until test setup is done for NMO so we can verify E2E tests.
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: mshitrit, rhwa-cve-pr-creator[bot] The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
CVE Fixes
Automated scan remediated 4 of 4 fixable Go dependency CVE(s) in
medik8s/node-maintenance-operatoron branchmain.How this was fixed
go getfor all vulnerable dependencies, using the highest reported fixed version per packagego mod tidyto clean upgo mod vendorto update vendored dependencies (if applicable)Generated by cve-scan pipeline