Skip to content

cluster-api-helm-controller/0.3.2-r4: cve remediation - #63421

Merged
aborrero merged 4 commits into
mainfrom
cve-cluster-api-helm-controller-0.3.2-r4-45daddae2bbf227f1c3eb7d61f7e0076
Aug 18, 2025
Merged

cluster-api-helm-controller/0.3.2-r4: cve remediation#63421
aborrero merged 4 commits into
mainfrom
cve-cluster-api-helm-controller-0.3.2-r4-45daddae2bbf227f1c3eb7d61f7e0076

Conversation

@octo-sts

@octo-sts octo-sts Bot commented Aug 17, 2025

Copy link
Copy Markdown
Contributor

cluster-api-helm-controller/0.3.2-r4: fix GHSA-f9f8-9pmf-xv68

Advisory data: https://github.com/wolfi-dev/advisories/blob/main/cluster-api-helm-controller.advisories.yaml


"Breadcrumbs" for this automated service

@octo-sts octo-sts Bot added P1 This label indicates our scanning found High, Medium or Low CVEs for these packages. automated pr cluster-api-helm-controller GHSA-f9f8-9pmf-xv68 go/bump request-cve-remediation labels Aug 17, 2025
@debasishbsws debasishbsws self-assigned this Aug 18, 2025
…addae2bbf227f1c3eb7d61f7e0076

Signed-off-by: Debasish Biswas <debasishbsws.dev@gmail.com>
@octo-sts

octo-sts Bot commented Aug 18, 2025

Copy link
Copy Markdown
Contributor Author

📦 Build Failed: Missing Dependency

module k8s.io/apiserver@latest found (v0.33.4), but does not contain package k8s.io/apiserver/pkg/util/version

Build Details

Category Details
Build System melange/go
Failure Point go mod tidy command during go/bump pipeline step

Root Cause Analysis 🔍

The k8s.io/apiserver module version v0.33.4 does not contain the required package k8s.io/apiserver/pkg/util/version that is imported by the dependency chain. This indicates either the package was moved/removed in the latest version or there's a version compatibility issue between cluster-api dependencies and the apiserver module.


Was this comment helpful? Please use 👍 or 👎 reactions on this comment.

@octo-sts octo-sts Bot added the ai/skip-comment Stop AI from commenting on PR label Aug 18, 2025
…erver to something latest that is missing utils/version module

Signed-off-by: Debasish Biswas <debasishbsws.dev@gmail.com>
@octo-sts octo-sts Bot added bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. manual/review-needed labels Aug 18, 2025
@debasishbsws
debasishbsws requested a review from a team August 18, 2025 15:29

@aborrero aborrero left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@aborrero
aborrero merged commit 52b3fd8 into main Aug 18, 2025
18 checks passed
@aborrero
aborrero deleted the cve-cluster-api-helm-controller-0.3.2-r4-45daddae2bbf227f1c3eb7d61f7e0076 branch August 18, 2025 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai/skip-comment Stop AI from commenting on PR automated pr bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. cluster-api-helm-controller GHSA-f9f8-9pmf-xv68 go/bump manual/review-needed P1 This label indicates our scanning found High, Medium or Low CVEs for these packages. request-cve-remediation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants