Skip to content

PCP-6775 Updating go build version & fixing vulns#21

Merged
vishu2498 merged 1 commit into
spectro-release-4.8from
PCP-6775
Jun 1, 2026
Merged

PCP-6775 Updating go build version & fixing vulns#21
vishu2498 merged 1 commit into
spectro-release-4.8from
PCP-6775

Conversation

@vishu2498

Copy link
Copy Markdown

No description provided.

@bulwark-spectrocloud bulwark-spectrocloud Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ GoVulnCheck scan found vulnerabilities:

  1. GO-2026-4394
    • Module: go.opentelemetry.io/otel/sdk
    • Found in: v1.39.0
    • Fixed in: v1.40.0
    • Example Traces:
      1. pkg/cloud/cks_cluster.go:143:71: cloud.RemoveVMFromCksCluster calls cloudstack.RemoveVirtualMachinesFromKubernetesCluster, which eventually calls otelhttp.Read
      2. main.go:36:2: cluster-api-provider-cloudstack.init calls flags.init, which eventually calls resource.init
      3. main.go:36:2: cluster-api-provider-cloudstack.init calls flags.init, which eventually calls trace.Tracer$1
      4. main.go:36:2: cluster-api-provider-cloudstack.init calls flags.init, which eventually calls trace.init
      5. main.go:36:2: cluster-api-provider-cloudstack.init calls flags.init, which eventually calls observ.NewTracer

Please review these findings and fix the issues before merging.

@vishu2498 vishu2498 force-pushed the PCP-6775 branch 2 times, most recently from c4205c0 to 484ec89 Compare June 1, 2026 16:03
@bulwark-spectrocloud bulwark-spectrocloud Bot dismissed their stale review June 1, 2026 16:04

Changes have been made to address the security findings.

@vishu2498 vishu2498 merged commit cc1b21a into spectro-release-4.8 Jun 1, 2026
4 of 5 checks passed
@vishu2498 vishu2498 deleted the PCP-6775 branch June 1, 2026 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant