Skip to content

Instantly share code, notes, and snippets.

@ihcsim
Created August 3, 2026 04:28
Show Gist options
  • Select an option

  • Save ihcsim/73ad83e50ec7193ee90af907aca89c91 to your computer and use it in GitHub Desktop.

Select an option

Save ihcsim/73ad83e50ec7193ee90af907aca89c91 to your computer and use it in GitHub Desktop.
gomod-vex image report for docker.io/rancher/rke2-runtime:v1.36.3-rc5-rke2r1,docker.io/rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723,docker.io/rancher/hardened-coredns:v1.14.6-build20260722,docker.io/rancher/hardened-cluster-autoscaler:v1.10.3-build20260717,docker.io/rancher/hardened-dns-node-cache:1.26.8-build20260722,docker.io/ranch…
gomod-vex report (image) for docker.io/rancher/rke2-runtime:v1.36.3-rc5-rke2r1
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 1 linked, 0 reachable, 0 undetermined
[LINKED] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /bin/containerd (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /bin/kubelet (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723
module: golang.org/x/crypto
summary: 5 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /usr/local/bin/kube-apiserver (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /usr/local/bin/kube-controller-manager (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /usr/local/bin/kube-proxy (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /usr/local/bin/kube-scheduler (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /usr/local/bin/kubelet (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-coredns:v1.14.6-build20260722
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /coredns (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-cluster-autoscaler:v1.10.3-build20260717
module: golang.org/x/crypto
No findings: the module was not linked into any Go binary in this image,
or no matching advisories were found.
gomod-vex report (image) for docker.io/rancher/hardened-dns-node-cache:1.26.8-build20260722
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.52.0
cve: GO-2026-5932
binary: /node-cache (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-etcd:v3.6.14-k3s1-build20260723
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.52.0
cve: GO-2026-5932
binary: /usr/local/bin/etcd (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-k8s-metrics-server:v0.9.0-build20260722
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.52.0
cve: GO-2026-5932
binary: /metrics-server (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-addon-resizer:1.8.23-build20260717
module: golang.org/x/crypto
No findings: the module was not linked into any Go binary in this image,
or no matching advisories were found.
gomod-vex report (image) for docker.io/rancher/klipper-helm:v0.13.3-build20260727
module: golang.org/x/crypto
summary: 42 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5005
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5006
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5013
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5014
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5015
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5016
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5017
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5018
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5019
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5020
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5021
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh/knownhosts (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5023
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5033
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5932
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5005
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5006
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5013
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5014
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5015
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5016
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5017
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5018
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5019
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5020
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5021
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh/knownhosts (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5023
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5033
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5932
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5005
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5006
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5013
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5014
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5015
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5016
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5017
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5018
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5019
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5020
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5021
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh/knownhosts (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5023
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5033
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5932
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/klipper-lb:v0.4.17
module: golang.org/x/crypto
No findings: the module was not linked into any Go binary in this image,
or no matching advisories were found.
gomod-vex report (image) for docker.io/rancher/mirrored-pause:3.10.2
module: golang.org/x/crypto
No findings: the module was not linked into any Go binary in this image,
or no matching advisories were found.
gomod-vex report (image) for docker.io/rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709
module: golang.org/x/crypto
summary: 14 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5005
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5006
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5013
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5014
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5015
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5016
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5017
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5018
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5019
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5020
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5021
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh/knownhosts (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5023
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5033
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.51.0
cve: GO-2026-5932
binary: /usr/local/bin/rke2-cloud-provider (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-snapshot-controller:v8.6.0-build20260722
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.52.0
cve: GO-2026-5932
binary: /snapshot-controller
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-traefik:v3.7.8-build20260717
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.52.0
cve: GO-2026-5932
binary: /traefik (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-calico:v3.32.1-build20260722
module: golang.org/x/crypto
summary: 5 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /calicoctl (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /opt/cni/bin/calico (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /opt/cni/bin/calico-ipam (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /usr/bin/calico-node (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /usr/bin/kube-controllers (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/hardened-flannel:v0.28.8-build20260722
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /opt/bin/flanneld (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment