Skip to content

PCP-6787 Fix CVEs#19

Merged
vishu2498 merged 1 commit into
spectro-mainfrom
PCP-6787
May 29, 2026
Merged

PCP-6787 Fix CVEs#19
vishu2498 merged 1 commit into
spectro-mainfrom
PCP-6787

Conversation

@vishu2498

Copy link
Copy Markdown

No description provided.

@bulwark-spectrocloud bulwark-spectrocloud Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ GoVulnCheck scan found vulnerabilities:

  1. GO-2026-4394
    • Module: go.opentelemetry.io/otel/sdk
    • Found in: v1.29.0
    • Fixed in: v1.40.0
    • Example Traces:
      1. controllers/cloudstackfailuredomain_controller.go:150:28: controllers.GetAllMachinesInFailureDomain calls client.List, which eventually calls noop.Start
      2. main.go:36:2: cluster-api-provider-cloudstack.init calls flags.init, which eventually calls otelhttp.newTracer
      3. pkg/cloud/instance.go:493:27: cloud.DeployVM calls cloud.compress, which eventually calls otelhttp.serveHTTP$4
      4. pkg/cloud/cks_cluster.go:143:71: cloud.RemoveVMFromCksCluster calls cloudstack.RemoveVirtualMachinesFromKubernetesCluster, which eventually calls otelhttp.Close
      5. controllers/cloudstackfailuredomain_controller.go:150:28: controllers.GetAllMachinesInFailureDomain calls client.List, which eventually calls otelhttp.RoundTrip

Please review these findings and fix the issues before merging.

@bulwark-spectrocloud bulwark-spectrocloud Bot dismissed their stale review May 29, 2026 09:33

Changes have been made to address the security findings.

@vishu2498 vishu2498 merged commit 52eee57 into spectro-main May 29, 2026
4 of 5 checks passed
@vishu2498 vishu2498 deleted the PCP-6787 branch May 29, 2026 09:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant