Skip to content

build(deps): Bump github.com/kubescape/storage from 0.0.185 to 0.2.0#2968

Open
gaganhr94 wants to merge 1 commit intoguacsec:mainfrom
gaganhr94:fix/kubespace-0.2.0
Open

build(deps): Bump github.com/kubescape/storage from 0.0.185 to 0.2.0#2968
gaganhr94 wants to merge 1 commit intoguacsec:mainfrom
gaganhr94:fix/kubespace-0.2.0

Conversation

@gaganhr94
Copy link
Copy Markdown
Contributor

Description of the PR

Related to #2719

PR Checklist

  • All commits have a Developer Certificate of Origin (DCO) -- they are generated using -s flag to git commit.
  • All new changes are covered by tests
  • If GraphQL schema is changed, make generate has been run
  • If GraphQL schema is changed, GraphQL client updates/additions have been made
  • If OpenAPI spec is changed, make generate has been run
  • If ent schema is changed, make generate has been run
  • If collectsub protobuf has been changed, make proto has been run
  • All CI checks are passing (tests and formatting)
  • All dependent PRs have already been merged

@kusari-inspector
Copy link
Copy Markdown

kusari-inspector Bot commented Apr 9, 2026

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both dependency and code security analyses independently recommend proceeding with this PR. From a dependency perspective, this PR is a net security improvement: it removes three OpenTelemetry OTLP HTTP exporter packages carrying CVE-2026-39882 (HIGH - unbounded HTTP response body memory exhaustion) and upgrades github.com/opencontainers/selinux from v1.12.0 to v1.13.1, resolving the previously flagged CVE-2025-52881 (container escape). All newly introduced packages carry no active CVEs. Minor risk flags on ginkgo/v2 and go-sqlite3 are policy-related (absent mandatory upstream code review), not exploitable vulnerabilities, and both are indirect transitive dependencies only. From a code security perspective, govulncheck confirms zero vulnerabilities with zero affected execution paths across all scanned files, zero secrets exposed, and zero workflow issues. The selinux update is validated as effective by govulncheck's reachability analysis. Licenses are permissive or weak copyleft on transitive-only deps, which is acceptable. There are no conflicting findings between the two analyses.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: cd2f05a, performed at: 2026-04-09T04:47:38Z

Found this helpful? Give it a 👍 or 👎 reaction!

@gaganhr94 gaganhr94 force-pushed the fix/kubespace-0.2.0 branch from 8f750b1 to cd2f05a Compare April 9, 2026 04:43
@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - cd2f05a performed at: 2026-04-09T04:48:14Z - link to updated analysis

@mihaimaruseac
Copy link
Copy Markdown
Member

Needs a rebase and another review

@gaganhr94 gaganhr94 force-pushed the fix/kubespace-0.2.0 branch from 1b1db32 to c7e57a4 Compare April 11, 2026 15:34
@gaganhr94
Copy link
Copy Markdown
Contributor Author

Rebased. Unit and Integration test failing due to update in the OSV data, so the test data needs to be updated. PR #2973 will have to be merged to unblock this

@gaganhr94 gaganhr94 force-pushed the fix/kubespace-0.2.0 branch from c7e57a4 to 8d48361 Compare April 12, 2026 14:54
@gaganhr94
Copy link
Copy Markdown
Contributor Author

Unit test workflow needs a rerun. Looks like an intermittent failure.

@gaganhr94
Copy link
Copy Markdown
Contributor Author

@mlieberman85 please do review this PR when you get a chance. Thanks !

@gaganhr94 gaganhr94 force-pushed the fix/kubespace-0.2.0 branch 2 times, most recently from 47ff740 to 78bc8ba Compare April 18, 2026 16:20
@gaganhr94 gaganhr94 force-pushed the fix/kubespace-0.2.0 branch from 78bc8ba to 532b5e2 Compare April 22, 2026 10:00
@gaganhr94 gaganhr94 force-pushed the fix/kubespace-0.2.0 branch from 532b5e2 to 9058227 Compare May 2, 2026 07:16
Signed-off-by: Gagan H R <hrgagan4@gmail.com>
@gaganhr94 gaganhr94 force-pushed the fix/kubespace-0.2.0 branch from 9058227 to a9891b9 Compare May 2, 2026 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants