Skip to content

Instantly share code, notes, and snippets.

@ihcsim
Created August 3, 2026 05:24
Show Gist options
  • Select an option

  • Save ihcsim/806199a03e63f404f413b94b71aaadd6 to your computer and use it in GitHub Desktop.

Select an option

Save ihcsim/806199a03e63f404f413b94b71aaadd6 to your computer and use it in GitHub Desktop.
gomod-vex image report for docker.io/rancher/klipper-helm:v0.11.1-build20260615,docker.io/rancher/klipper-lb:v0.4.17,docker.io/rancher/local-path-provisioner:v0.0.36,docker.io/rancher/mirrored-coredns-coredns:1.14.4,docker.io/rancher/mirrored-library-busybox:1.37.0,docker.io/rancher/mirrored-library-traefik:3.7.4,docker.io/rancher/mirrored-metri…
gomod-vex report (image) for docker.io/rancher/klipper-helm:v0.11.1-build20260615
module: golang.org/x/crypto
summary: 42 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5005
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5006
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5013
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5014
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5015
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5016
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5017
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5018
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5019
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5020
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5021
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh/knownhosts (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5023
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5033
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5932
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5005
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5006
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5013
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5014
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5015
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5016
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5017
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5018
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5019
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5020
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5021
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh/knownhosts (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5023
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5033
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5932
binary: /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5005
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5006
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5013
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5014
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5015
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5016
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5017
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5018
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5019
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5020
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5021
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh/knownhosts (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5023
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5033
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5932
binary: /usr/bin/helm (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/klipper-lb:v0.4.17
module: golang.org/x/crypto
No findings: the module was not linked into any Go binary in this image,
or no matching advisories were found.
gomod-vex report (image) for docker.io/rancher/local-path-provisioner:v0.0.36
module: golang.org/x/crypto
No findings: the module was not linked into any Go binary in this image,
or no matching advisories were found.
gomod-vex report (image) for docker.io/rancher/mirrored-coredns-coredns:1.14.4
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.52.0
cve: GO-2026-5932
binary: /coredns (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/mirrored-library-busybox:1.37.0
module: golang.org/x/crypto
No findings: the module was not linked into any Go binary in this image,
or no matching advisories were found.
gomod-vex report (image) for docker.io/rancher/mirrored-library-traefik:3.7.4
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.52.0
cve: GO-2026-5932
binary: /usr/local/bin/traefik (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/mirrored-metrics-server:v0.8.1
module: golang.org/x/crypto
summary: 17 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2025-4116
binary: /metrics-server
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2025-4134
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2025-4135
binary: /metrics-server
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5005
binary: /metrics-server
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5006
binary: /metrics-server
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5013
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5014
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5015
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5016
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5017
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5018
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5019
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5020
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5021
binary: /metrics-server
packages: golang.org/x/crypto/ssh/knownhosts (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5023
binary: /metrics-server
packages: golang.org/x/crypto/ssh (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5033
binary: /metrics-server
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
[NOT PRESENT] golang.org/x/crypto@v0.38.0
cve: GO-2026-5932
binary: /metrics-server
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
vex: vulnerable_code_not_present [pclntab]
gomod-vex report (image) for docker.io/rancher/mirrored-pause:3.6
module: golang.org/x/crypto
No findings: the module was not linked into any Go binary in this image,
or no matching advisories were found.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment