Fix CVEs in release-0.23 - #4153
Conversation
Full package: golang.org/x/mod Fixes: GO-2026-6179, GO-2026-6180 Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
The GO-2026-5932 (golang.org/x/crypto) ignore entry lacked the fix-state: not-fixed field, making it a permanent unconditional suppress instead of an auto-expiring one. Without fix-state, grype keeps the entry active even after a fix is published, silently hiding the CVE rather than re-reporting it for remediation. Add fix-state: not-fixed so the entry auto-expires when the OSV advisory records an available fix. Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
|
🤖 Created branch: z_pr4153/dfarrell07/fix-0.23-cves-2026-08-21 |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (3)
Included review availability: Your plan provides up to 8 included reviews per hour; 5 remain after this review. WalkthroughThe change updates ChangesDependency and security updates
Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to This dependency and vulnerability metadata update is merge-ready after normal checks and review; no actionable merge-blocking risk remains. Suggested reviewers: Caution Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional.
❌ Failed checks (1 error)
✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
See commit messages for details.
Summary by CodeRabbit
Security
Maintenance