Skip to content

chore(deps): security update#16221

Open
kumahq[bot] wants to merge 1 commit intorelease-2.7from
chore/security-updates-release-2.7
Open

chore(deps): security update#16221
kumahq[bot] wants to merge 1 commit intorelease-2.7from
chore/security-updates-release-2.7

Conversation

@kumahq
Copy link
Copy Markdown
Contributor

@kumahq kumahq bot commented Apr 11, 2026

Scan output:

Before update:

OSV URL CVSS ECOSYSTEM PACKAGE VERSION SOURCE
https://osv.dev/GO-2026-4883 6.8 Go github.com/docker/docker 28.0.0 incompatible
https://osv.dev/GHSA-pxq6-2prw-chj9
https://osv.dev/GO-2026-4887 8.8 Go github.com/docker/docker 28.0.0 incompatible
https://osv.dev/GHSA-x744-4wpc-v9h2
https://osv.dev/GHSA-hr2v-4r36-88hr 4.8 Go helm.sh/helm/v3 3.18.5 go.mod
------------------------------------- ------ ----------- --------------------------- --------------------- --------
Uncalled vulnerabilities
------------------------------------- ------ ----------- --------------------------- --------------------- --------
https://osv.dev/GO-2022-0635 Go github.com/aws/aws-sdk-go 1.49.6 go.mod
https://osv.dev/GO-2022-0646 Go github.com/aws/aws-sdk-go 1.49.6 go.mod

After update:

OSV URL CVSS ECOSYSTEM PACKAGE VERSION SOURCE
https://osv.dev/GO-2026-4883 6.8 Go github.com/docker/docker 28.0.0 incompatible
https://osv.dev/GHSA-pxq6-2prw-chj9
https://osv.dev/GO-2026-4887 8.8 Go github.com/docker/docker 28.0.0 incompatible
https://osv.dev/GHSA-x744-4wpc-v9h2
------------------------------------- ------ ----------- --------------------------- --------------------- --------
Uncalled vulnerabilities
------------------------------------- ------ ----------- --------------------------- --------------------- --------
https://osv.dev/GO-2022-0635 Go github.com/aws/aws-sdk-go 1.49.6 go.mod
https://osv.dev/GO-2022-0646 Go github.com/aws/aws-sdk-go 1.49.6 go.mod

If a package is showing up in the scan but the script is not trying to update it then it might be because there is no fixed version yet.

@kumahq kumahq bot added dependencies Pull requests that update a dependency file release-2.7 labels Apr 11, 2026
@kumahq kumahq bot requested a review from a team as a code owner April 11, 2026 04:04
@kumahq kumahq bot requested review from lukidzi and slonka April 11, 2026 04:04
@kumahq kumahq bot force-pushed the chore/security-updates-release-2.7 branch 4 times, most recently from 404801e to cb9063b Compare April 17, 2026 04:16
Signed-off-by: kumahq[bot] <110050114+kumahq[bot]@users.noreply.github.com>
@kumahq kumahq bot force-pushed the chore/security-updates-release-2.7 branch from cb9063b to 0b06d8d Compare April 21, 2026 04:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file release-2.7

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants