build(deps): Bump github.com/kubescape/storage from 0.0.185 to 0.2.0#2968
build(deps): Bump github.com/kubescape/storage from 0.0.185 to 0.2.0#2968gaganhr94 wants to merge 1 commit intoguacsec:mainfrom
Conversation
Kusari Analysis Results:
Both dependency and code security analyses independently recommend proceeding with this PR. From a dependency perspective, this PR is a net security improvement: it removes three OpenTelemetry OTLP HTTP exporter packages carrying CVE-2026-39882 (HIGH - unbounded HTTP response body memory exhaustion) and upgrades github.com/opencontainers/selinux from v1.12.0 to v1.13.1, resolving the previously flagged CVE-2025-52881 (container escape). All newly introduced packages carry no active CVEs. Minor risk flags on ginkgo/v2 and go-sqlite3 are policy-related (absent mandatory upstream code review), not exploitable vulnerabilities, and both are indirect transitive dependencies only. From a code security perspective, govulncheck confirms zero vulnerabilities with zero affected execution paths across all scanned files, zero secrets exposed, and zero workflow issues. The selinux update is validated as effective by govulncheck's reachability analysis. Licenses are permissive or weak copyleft on transitive-only deps, which is acceptable. There are no conflicting findings between the two analyses. Note View full detailed analysis result for more information on the output and the checks that were run.
Found this helpful? Give it a 👍 or 👎 reaction! |
8f750b1 to
cd2f05a
Compare
|
Kusari PR Analysis rerun based on - cd2f05a performed at: 2026-04-09T04:48:14Z - link to updated analysis |
cd2f05a to
d334f02
Compare
|
Needs a rebase and another review |
1b1db32 to
c7e57a4
Compare
|
Rebased. Unit and Integration test failing due to update in the OSV data, so the test data needs to be updated. PR #2973 will have to be merged to unblock this |
c7e57a4 to
8d48361
Compare
|
Unit test workflow needs a rerun. Looks like an intermittent failure. |
|
@mlieberman85 please do review this PR when you get a chance. Thanks ! |
47ff740 to
78bc8ba
Compare
78bc8ba to
532b5e2
Compare
532b5e2 to
9058227
Compare
Signed-off-by: Gagan H R <hrgagan4@gmail.com>
9058227 to
a9891b9
Compare
Description of the PR
Related to #2719
PR Checklist
-sflag togit commit.make generatehas been runmake generatehas been runmake generatehas been runcollectsubprotobuf has been changed,make protohas been run