Skip to content

Update github/codeql-action action to v4.37.3#121

Open
csi-components-e2e wants to merge 1 commit into
mainfrom
renovate/all-non-major-dependencies
Open

Update github/codeql-action action to v4.37.3#121
csi-components-e2e wants to merge 1 commit into
mainfrom
renovate/all-non-major-dependencies

Conversation

@csi-components-e2e

@csi-components-e2e csi-components-e2e commented Jul 21, 2026

Copy link
Copy Markdown
Collaborator

This PR contains the following updates:

Package Type Update Change
github/codeql-action action patch v4.37.1v4.37.3

Release Notes

github/codeql-action (github/codeql-action)

v4.37.3

Compare Source

No user facing changes.

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@csi-components-e2e csi-components-e2e added the dependencies Pull requests that update a dependency file label Jul 21, 2026
@csi-components-e2e
csi-components-e2e enabled auto-merge (squash) July 21, 2026 15:02
torredil
torredil previously approved these changes Jul 21, 2026
@github-actions

Copy link
Copy Markdown

Trivy Output

702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-snapshotter:f5a6c8ecdd946352b886cca1238634b4129c5f1f-v8.6.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-snapshotter:f5a6c8ecdd946352b8- │  amazon  │        0        │    -    │
│ 86cca1238634b4129c5f1f-v8.6.0-eksbuild.3 (amazon 2023.12.20260720 (Amazon        │          │                 │         │
│ Linux))                                                                          │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-snapshotter                                                                  │ gobinary │        1        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-snapshotter (gobinary)
==========================
Total: 1 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌─────────────────────┬───────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│       Library       │ Vulnerability │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├─────────────────────┼───────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto │ GO-2026-5932  │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                     │               │          │          │                   │               │ unsafe by design, and has known security...              │
└─────────────────────┴───────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-attacher:f5a6c8ecdd946352b886cca1238634b4129c5f1f-v4.12.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-attacher:f5a6c8ecdd946352b886c- │  amazon  │        0        │    -    │
│ ca1238634b4129c5f1f-v4.12.0-eksbuild.3 (amazon 2023.12.20260720 (Amazon Linux))  │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-attacher                                                                     │ gobinary │        1        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-attacher (gobinary)
=======================
Total: 1 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌─────────────────────┬───────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│       Library       │ Vulnerability │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├─────────────────────┼───────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto │ GO-2026-5932  │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                     │               │          │          │                   │               │ unsafe by design, and has known security...              │
└─────────────────────┴───────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-provisioner:f5a6c8ecdd946352b886cca1238634b4129c5f1f-v6.3.0-eksbuild.2

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-provisioner:f5a6c8ecdd946352b8- │  amazon  │        0        │    -    │
│ 86cca1238634b4129c5f1f-v6.3.0-eksbuild.2 (amazon 2023.12.20260720 (Amazon        │          │                 │         │
│ Linux))                                                                          │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-provisioner                                                                  │ gobinary │        1        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-provisioner (gobinary)
==========================
Total: 1 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌─────────────────────┬───────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│       Library       │ Vulnerability │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├─────────────────────┼───────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto │ GO-2026-5932  │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                     │               │          │          │                   │               │ unsafe by design, and has known security...              │
└─────────────────────┴───────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-resizer:f5a6c8ecdd946352b886cca1238634b4129c5f1f-v2.2.1-eksbuild.1

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-resizer:f5a6c8ecdd946352b886cc- │  amazon  │        0        │    -    │
│ a1238634b4129c5f1f-v2.2.1-eksbuild.1 (amazon 2023.12.20260720 (Amazon Linux))    │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-resizer                                                                      │ gobinary │        1        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-resizer (gobinary)
======================
Total: 1 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌─────────────────────┬───────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│       Library       │ Vulnerability │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├─────────────────────┼───────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto │ GO-2026-5932  │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                     │               │          │          │                   │               │ unsafe by design, and has known security...              │
└─────────────────────┴───────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-node-driver-registrar:f5a6c8ecdd946352b886cca1238634b4129c5f1f-v2.17.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-node-driver-registrar:f5a6c8ec- │  amazon  │        0        │    -    │
│ dd946352b886cca1238634b4129c5f1f-v2.17.0-eksbuild.3 (amazon 2023.12.20260720     │          │                 │         │
│ (Amazon Linux))                                                                  │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-node-driver-registrar                                                        │ gobinary │        0        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)

702945799511.dkr.ecr.us-west-2.amazonaws.com/livenessprobe:f5a6c8ecdd946352b886cca1238634b4129c5f1f-v2.19.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/livenessprobe:f5a6c8ecdd946352b886- │  amazon  │        0        │    -    │
│ cca1238634b4129c5f1f-v2.19.0-eksbuild.3 (amazon 2023.12.20260720 (Amazon Linux)) │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ livenessprobe                                                                    │ gobinary │        0        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)

702945799511.dkr.ecr.us-west-2.amazonaws.com/snapshot-controller:f5a6c8ecdd946352b886cca1238634b4129c5f1f-v8.6.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/snapshot-controller:f5a6c8ecdd9463- │  amazon  │        0        │    -    │
│ 52b886cca1238634b4129c5f1f-v8.6.0-eksbuild.3 (amazon 2023.12.20260720 (Amazon    │          │                 │         │
│ Linux))                                                                          │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ snapshot-controller                                                              │ gobinary │        1        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


snapshot-controller (gobinary)
==============================
Total: 1 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌─────────────────────┬───────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│       Library       │ Vulnerability │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├─────────────────────┼───────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto │ GO-2026-5932  │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                     │               │          │          │                   │               │ unsafe by design, and has known security...              │
└─────────────────────┴───────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/volume-modifier-for-k8s:f5a6c8ecdd946352b886cca1238634b4129c5f1f-v0.9.5-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/volume-modifier-for-k8s:f5a6c8ecdd- │  amazon  │        0        │    -    │
│ 946352b886cca1238634b4129c5f1f-v0.9.5-eksbuild.3 (amazon 2023.12.20260720        │          │                 │         │
│ (Amazon Linux))                                                                  │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ volume-modifier-for-k8s                                                          │ gobinary │        0        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)

| datasource  | package              | from    | to      |
| ----------- | -------------------- | ------- | ------- |
| github-tags | github/codeql-action | v4.37.1 | v4.37.3 |
@csi-components-e2e
csi-components-e2e force-pushed the renovate/all-non-major-dependencies branch from f855cca to 373f24b Compare July 22, 2026 06:38
@csi-components-e2e csi-components-e2e changed the title Update github/codeql-action action to v4.37.2 Update github/codeql-action action to v4.37.3 Jul 22, 2026
@github-actions

Copy link
Copy Markdown

Trivy Output

702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-snapshotter:a8470bf78753c9aefeb48dac130745b9f970107a-v8.6.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-snapshotter:a8470bf78753c9aefe- │  amazon  │        0        │    -    │
│ b48dac130745b9f970107a-v8.6.0-eksbuild.3 (amazon 2023.12.20260720 (Amazon        │          │                 │         │
│ Linux))                                                                          │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-snapshotter                                                                  │ gobinary │        2        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-snapshotter (gobinary)
==========================
Total: 2 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌────────────────────────┬─────────────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│        Library         │    Vulnerability    │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto    │ GO-2026-5932        │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                        │                     │          │          │                   │               │ unsafe by design, and has known security...              │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ google.golang.org/grpc │ GHSA-hrxh-6v49-42gf │ HIGH     │ fixed    │ v1.81.1           │ 1.82.1        │ gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities             │
│                        │                     │          │          │                   │               │ https://github.com/advisories/GHSA-hrxh-6v49-42gf        │
└────────────────────────┴─────────────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-attacher:a8470bf78753c9aefeb48dac130745b9f970107a-v4.12.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-attacher:a8470bf78753c9aefeb48- │  amazon  │        0        │    -    │
│ dac130745b9f970107a-v4.12.0-eksbuild.3 (amazon 2023.12.20260720 (Amazon Linux))  │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-attacher                                                                     │ gobinary │        2        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-attacher (gobinary)
=======================
Total: 2 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌────────────────────────┬─────────────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│        Library         │    Vulnerability    │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto    │ GO-2026-5932        │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                        │                     │          │          │                   │               │ unsafe by design, and has known security...              │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ google.golang.org/grpc │ GHSA-hrxh-6v49-42gf │ HIGH     │ fixed    │ v1.81.1           │ 1.82.1        │ gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities             │
│                        │                     │          │          │                   │               │ https://github.com/advisories/GHSA-hrxh-6v49-42gf        │
└────────────────────────┴─────────────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-provisioner:a8470bf78753c9aefeb48dac130745b9f970107a-v6.3.0-eksbuild.2

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-provisioner:a8470bf78753c9aefe- │  amazon  │        0        │    -    │
│ b48dac130745b9f970107a-v6.3.0-eksbuild.2 (amazon 2023.12.20260720 (Amazon        │          │                 │         │
│ Linux))                                                                          │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-provisioner                                                                  │ gobinary │        2        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-provisioner (gobinary)
==========================
Total: 2 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌────────────────────────┬─────────────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│        Library         │    Vulnerability    │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto    │ GO-2026-5932        │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                        │                     │          │          │                   │               │ unsafe by design, and has known security...              │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ google.golang.org/grpc │ GHSA-hrxh-6v49-42gf │ HIGH     │ fixed    │ v1.81.1           │ 1.82.1        │ gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities             │
│                        │                     │          │          │                   │               │ https://github.com/advisories/GHSA-hrxh-6v49-42gf        │
└────────────────────────┴─────────────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-resizer:a8470bf78753c9aefeb48dac130745b9f970107a-v2.2.1-eksbuild.1

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-resizer:a8470bf78753c9aefeb48d- │  amazon  │        0        │    -    │
│ ac130745b9f970107a-v2.2.1-eksbuild.1 (amazon 2023.12.20260720 (Amazon Linux))    │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-resizer                                                                      │ gobinary │        2        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-resizer (gobinary)
======================
Total: 2 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌────────────────────────┬─────────────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│        Library         │    Vulnerability    │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto    │ GO-2026-5932        │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                        │                     │          │          │                   │               │ unsafe by design, and has known security...              │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ google.golang.org/grpc │ GHSA-hrxh-6v49-42gf │ HIGH     │ fixed    │ v1.81.1           │ 1.82.1        │ gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities             │
│                        │                     │          │          │                   │               │ https://github.com/advisories/GHSA-hrxh-6v49-42gf        │
└────────────────────────┴─────────────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-node-driver-registrar:a8470bf78753c9aefeb48dac130745b9f970107a-v2.17.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-node-driver-registrar:a8470bf7- │  amazon  │        0        │    -    │
│ 8753c9aefeb48dac130745b9f970107a-v2.17.0-eksbuild.3 (amazon 2023.12.20260720     │          │                 │         │
│ (Amazon Linux))                                                                  │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-node-driver-registrar                                                        │ gobinary │        1        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-node-driver-registrar (gobinary)
====================================
Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌────────────────────────┬─────────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────┐
│        Library         │    Vulnerability    │ Severity │ Status │ Installed Version │ Fixed Version │                       Title                       │
├────────────────────────┼─────────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────┤
│ google.golang.org/grpc │ GHSA-hrxh-6v49-42gf │ HIGH     │ fixed  │ v1.81.1           │ 1.82.1        │ gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities      │
│                        │                     │          │        │                   │               │ https://github.com/advisories/GHSA-hrxh-6v49-42gf │
└────────────────────────┴─────────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/livenessprobe:a8470bf78753c9aefeb48dac130745b9f970107a-v2.19.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/livenessprobe:a8470bf78753c9aefeb4- │  amazon  │        0        │    -    │
│ 8dac130745b9f970107a-v2.19.0-eksbuild.3 (amazon 2023.12.20260720 (Amazon Linux)) │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ livenessprobe                                                                    │ gobinary │        1        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


livenessprobe (gobinary)
========================
Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌────────────────────────┬─────────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────┐
│        Library         │    Vulnerability    │ Severity │ Status │ Installed Version │ Fixed Version │                       Title                       │
├────────────────────────┼─────────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────┤
│ google.golang.org/grpc │ GHSA-hrxh-6v49-42gf │ HIGH     │ fixed  │ v1.81.1           │ 1.82.1        │ gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities      │
│                        │                     │          │        │                   │               │ https://github.com/advisories/GHSA-hrxh-6v49-42gf │
└────────────────────────┴─────────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/snapshot-controller:a8470bf78753c9aefeb48dac130745b9f970107a-v8.6.0-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/snapshot-controller:a8470bf78753c9- │  amazon  │        0        │    -    │
│ aefeb48dac130745b9f970107a-v8.6.0-eksbuild.3 (amazon 2023.12.20260720 (Amazon    │          │                 │         │
│ Linux))                                                                          │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ snapshot-controller                                                              │ gobinary │        2        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


snapshot-controller (gobinary)
==============================
Total: 2 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌────────────────────────┬─────────────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────┐
│        Library         │    Vulnerability    │ Severity │  Status  │ Installed Version │ Fixed Version │                          Title                           │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ golang.org/x/crypto    │ GO-2026-5932        │ UNKNOWN  │ affected │ v0.54.0           │               │ The golang.org/x/crypto/openpgp package is unmaintained, │
│                        │                     │          │          │                   │               │ unsafe by design, and has known security...              │
├────────────────────────┼─────────────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────┤
│ google.golang.org/grpc │ GHSA-hrxh-6v49-42gf │ HIGH     │ fixed    │ v1.81.1           │ 1.82.1        │ gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities             │
│                        │                     │          │          │                   │               │ https://github.com/advisories/GHSA-hrxh-6v49-42gf        │
└────────────────────────┴─────────────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/volume-modifier-for-k8s:a8470bf78753c9aefeb48dac130745b9f970107a-v0.9.5-eksbuild.3

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/volume-modifier-for-k8s:a8470bf787- │  amazon  │        0        │    -    │
│ 53c9aefeb48dac130745b9f970107a-v0.9.5-eksbuild.3 (amazon 2023.12.20260720        │          │                 │         │
│ (Amazon Linux))                                                                  │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ volume-modifier-for-k8s                                                          │ gobinary │        1        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


volume-modifier-for-k8s (gobinary)
==================================
Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌────────────────────────┬─────────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────┐
│        Library         │    Vulnerability    │ Severity │ Status │ Installed Version │ Fixed Version │                       Title                       │
├────────────────────────┼─────────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────┤
│ google.golang.org/grpc │ GHSA-hrxh-6v49-42gf │ HIGH     │ fixed  │ v1.81.1           │ 1.82.1        │ gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities      │
│                        │                     │          │        │                   │               │ https://github.com/advisories/GHSA-hrxh-6v49-42gf │
└────────────────────────┴─────────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────┘

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants