Skip to content

cherry-picked makefile commits from 4.8#18

Merged
vishu2498 merged 2 commits into
spectro-mainfrom
makefile-4.8
May 19, 2026
Merged

cherry-picked makefile commits from 4.8#18
vishu2498 merged 2 commits into
spectro-mainfrom
makefile-4.8

Conversation

@kpiyush17

Copy link
Copy Markdown

No description provided.

@bulwark-spectrocloud bulwark-spectrocloud Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ GoVulnCheck scan found vulnerabilities:

  1. GO-2026-4918
    • Module: golang.org/x/net
    • Found in: v0.38.0
    • Fixed in: v0.53.0
    • Example Traces:
      1. controllers/cloudstackfailuredomain_controller.go:150:28: controllers.GetAllMachinesInFailureDomain calls client.List, which eventually calls http.roundTrip
      2. controllers/cloudstackfailuredomain_controller.go:150:28: controllers.GetAllMachinesInFailureDomain calls client.List, which eventually calls http2.run
      3. controllers/cloudstackfailuredomain_controller.go:150:28: controllers.GetAllMachinesInFailureDomain calls client.List, which eventually calls http.roundTrip
      4. controllers/cloudstackfailuredomain_controller.go:150:28: controllers.GetAllMachinesInFailureDomain calls client.List, which eventually calls http.roundTrip
  2. GO-2026-4394
    • Module: go.opentelemetry.io/otel/sdk
    • Found in: v1.29.0
    • Fixed in: v1.40.0
    • Example Traces:
      1. pkg/cloud/instance.go:493:27: cloud.DeployVM calls cloud.compress, which eventually calls otelhttp.serveHTTP$4
      2. pkg/cloud/cks_cluster.go:143:71: cloud.RemoveVMFromCksCluster calls cloudstack.RemoveVirtualMachinesFromKubernetesCluster, which eventually calls otelhttp.Read
      3. controllers/cloudstackfailuredomain_controller.go:150:28: controllers.GetAllMachinesInFailureDomain calls client.List, which eventually calls otelhttp.RoundTrip
      4. pkg/cloud/cks_cluster.go:143:71: cloud.RemoveVMFromCksCluster calls cloudstack.RemoveVirtualMachinesFromKubernetesCluster, which eventually calls otelhttp.Read
      5. controllers/cloudstackfailuredomain_controller.go:150:28: controllers.GetAllMachinesInFailureDomain calls client.List, which eventually calls noop.Start

Please review these findings and fix the issues before merging.

@vishu2498 vishu2498 merged commit fd3b375 into spectro-main May 19, 2026
3 of 5 checks passed
@vishu2498 vishu2498 deleted the makefile-4.8 branch May 19, 2026 09:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants