Skip to content

[webhook-tls-manager] Fixing cve - #58

Merged
huizhifan merged 1 commit into
mainfrom
users/ruinanliu/golang-cve-fix
Jul 15, 2026
Merged

[webhook-tls-manager] Fixing cve#58
huizhifan merged 1 commit into
mainfrom
users/ruinanliu/golang-cve-fix

Conversation

@ruinan-liu

@ruinan-liu Ruinan Liu (ruinan-liu) commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

ruinanliu@TDC1011030635:~/go/src/go.goms.io/aks/webhook-tls-manager$ trivy image --scanners vuln --detection-priority comprehensive webhook-tls-manager:v1.1.10
2026-07-15T19:34:07Z INFO [vuln] Vulnerability scanning is enabled
2026-07-15T19:34:07Z INFO Number of language-specific files num=1
2026-07-15T19:34:07Z INFO [gobinary] Detecting vulnerabilities...
2026-07-15T19:34:07Z WARN Using severities from other vendors for some vulnerabilities. Read https://trivy.dev/docs/v0.72/guide/scanner/vulnerability#severity-selection for details.

Report Summary

┌─────────────────────┬──────────┬─────────────────┐
│ Target │ Type │ Vulnerabilities │
├─────────────────────┼──────────┼─────────────────┤
│ webhook-tls-manager │ gobinary │ 1 │
└─────────────────────┴──────────┴─────────────────┘
Legend:

  • '-': Not scanned
  • '0': Clean (no security findings detected)

webhook-tls-manager (gobinary)

Total: 1 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌─────────────────────┬───────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
├─────────────────────┼───────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto │ GO-2026-5932 │ UNKNOWN │ affected │ v0.54.0 │ │ The golang.org/x/crypto/openpgp package is unmaintained, │
│ │ │ │ │ │ │ unsafe by design, and has known security... │
└─────────────────────┴───────────────┴──────────┴──────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────

one cve that we can't fix and we are not using that binary.

@huizhifan
huizhifan merged commit fbc27fd into main Jul 15, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants