Created
August 7, 2026 17:57
-
-
Save ihcsim/8101250842c2e94487ce10baf468e902 to your computer and use it in GitHub Desktop.
vexscan image report for docker.io/rancher/rke2-runtime:v1.36.3-rc5-rke2r1, docker.io/rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723, docker.io/rancher/hardened-coredns:v1.14.6-build20260722, docker.io/rancher/hardened-cluster-autoscaler:v1.10.3-build20260717, docker.io/rancher/hardened-dns-node-cache:1.26.8-build20260722, docker.io/ra…
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| [ | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: linked)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "bin/containerd" | |
| } | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "linked", | |
| "version": "v0.53.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "bin/kubelet" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:55:42.457679742Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/rke2-runtime:v1.36.3-rc5-rke2r1" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/kube-apiserver" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/kube-controller-manager" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/kube-proxy" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/kube-scheduler" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/kubelet" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:55:57.572186724Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "coredns" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:56:02.731786811Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-coredns:v1.14.6-build20260722" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": null | |
| } | |
| }, | |
| "results": null, | |
| "properties": { | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-cluster-autoscaler:v1.10.3-build20260717" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.52.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "node-cache" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.52.0", | |
| "status": "not_present", | |
| "version": "v0.52.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:56:10.176464482Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-dns-node-cache:1.26.8-build20260722" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.52.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/etcd" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.52.0", | |
| "status": "not_present", | |
| "version": "v0.52.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:56:14.358152808Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-etcd:v3.6.14-k3s1-build20260723" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.52.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "metrics-server" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.52.0", | |
| "status": "not_present", | |
| "version": "v0.52.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:56:17.781660408Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-k8s-metrics-server:v0.9.0-build20260722" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": null | |
| } | |
| }, | |
| "results": null, | |
| "properties": { | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-addon-resizer:1.8.23-build20260717" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5005", | |
| "name": "GO-2026-5005", | |
| "shortDescription": { | |
| "text": "GO-2026-5005 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5005", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5006", | |
| "name": "GO-2026-5006", | |
| "shortDescription": { | |
| "text": "GO-2026-5006 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5006", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5013", | |
| "name": "GO-2026-5013", | |
| "shortDescription": { | |
| "text": "GO-2026-5013 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5013", | |
| "properties": { | |
| "security-severity": "7.5", | |
| "severity": "HIGH", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5014", | |
| "name": "GO-2026-5014", | |
| "shortDescription": { | |
| "text": "GO-2026-5014 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5014", | |
| "properties": { | |
| "security-severity": "6.3", | |
| "severity": "MEDIUM", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5015", | |
| "name": "GO-2026-5015", | |
| "shortDescription": { | |
| "text": "GO-2026-5015 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5015", | |
| "properties": { | |
| "security-severity": "5.3", | |
| "severity": "MEDIUM", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5016", | |
| "name": "GO-2026-5016", | |
| "shortDescription": { | |
| "text": "GO-2026-5016 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5016", | |
| "properties": { | |
| "security-severity": "6.5", | |
| "severity": "MEDIUM", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5017", | |
| "name": "GO-2026-5017", | |
| "shortDescription": { | |
| "text": "GO-2026-5017 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5017", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5018", | |
| "name": "GO-2026-5018", | |
| "shortDescription": { | |
| "text": "GO-2026-5018 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5018", | |
| "properties": { | |
| "security-severity": "7.5", | |
| "severity": "HIGH", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5019", | |
| "name": "GO-2026-5019", | |
| "shortDescription": { | |
| "text": "GO-2026-5019 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5019", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5020", | |
| "name": "GO-2026-5020", | |
| "shortDescription": { | |
| "text": "GO-2026-5020 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5020", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5021", | |
| "name": "GO-2026-5021", | |
| "shortDescription": { | |
| "text": "GO-2026-5021 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5021", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5023", | |
| "name": "GO-2026-5023", | |
| "shortDescription": { | |
| "text": "GO-2026-5023 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5023", | |
| "properties": { | |
| "security-severity": "10.0", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5033", | |
| "name": "GO-2026-5033", | |
| "shortDescription": { | |
| "text": "GO-2026-5033 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5033", | |
| "properties": { | |
| "security-severity": "5.3", | |
| "severity": "MEDIUM", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5005", | |
| "ruleIndex": 0, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5005 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5006", | |
| "ruleIndex": 1, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5006 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5013", | |
| "ruleIndex": 2, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5013 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5014", | |
| "ruleIndex": 3, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5014 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5015", | |
| "ruleIndex": 4, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5015 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5016", | |
| "ruleIndex": 5, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5016 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5017", | |
| "ruleIndex": 6, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5017 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5018", | |
| "ruleIndex": 7, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5018 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5019", | |
| "ruleIndex": 8, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5019 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5020", | |
| "ruleIndex": 9, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5020 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5021", | |
| "ruleIndex": 10, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5021 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5023", | |
| "ruleIndex": 11, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5023 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5033", | |
| "ruleIndex": 12, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5033 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 13, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5005", | |
| "ruleIndex": 0, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5005 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5006", | |
| "ruleIndex": 1, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5006 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5013", | |
| "ruleIndex": 2, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5013 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5014", | |
| "ruleIndex": 3, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5014 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5015", | |
| "ruleIndex": 4, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5015 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5016", | |
| "ruleIndex": 5, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5016 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5017", | |
| "ruleIndex": 6, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5017 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5018", | |
| "ruleIndex": 7, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5018 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5019", | |
| "ruleIndex": 8, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5019 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5020", | |
| "ruleIndex": 9, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5020 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5021", | |
| "ruleIndex": 10, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5021 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5023", | |
| "ruleIndex": 11, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5023 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5033", | |
| "ruleIndex": 12, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5033 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 13, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5005", | |
| "ruleIndex": 0, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5005 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5006", | |
| "ruleIndex": 1, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5006 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5013", | |
| "ruleIndex": 2, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5013 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5014", | |
| "ruleIndex": 3, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5014 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5015", | |
| "ruleIndex": 4, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5015 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5016", | |
| "ruleIndex": 5, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5016 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5017", | |
| "ruleIndex": 6, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5017 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5018", | |
| "ruleIndex": 7, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5018 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5019", | |
| "ruleIndex": 8, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5019 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5020", | |
| "ruleIndex": 9, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5020 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5021", | |
| "ruleIndex": 10, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5021 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5023", | |
| "ruleIndex": 11, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5023 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5033", | |
| "ruleIndex": 12, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5033 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 13, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/helm" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:56:29.992576448Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/klipper-helm:v0.13.3-build20260727" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": null | |
| } | |
| }, | |
| "results": null, | |
| "properties": { | |
| "mode": "image", | |
| "target": "docker.io/rancher/klipper-lb:v0.4.17" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": null | |
| } | |
| }, | |
| "results": null, | |
| "properties": { | |
| "mode": "image", | |
| "target": "docker.io/rancher/mirrored-pause:3.10.2" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5005", | |
| "name": "GO-2026-5005", | |
| "shortDescription": { | |
| "text": "GO-2026-5005 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5005", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5006", | |
| "name": "GO-2026-5006", | |
| "shortDescription": { | |
| "text": "GO-2026-5006 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5006", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5013", | |
| "name": "GO-2026-5013", | |
| "shortDescription": { | |
| "text": "GO-2026-5013 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5013", | |
| "properties": { | |
| "security-severity": "7.5", | |
| "severity": "HIGH", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5014", | |
| "name": "GO-2026-5014", | |
| "shortDescription": { | |
| "text": "GO-2026-5014 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5014", | |
| "properties": { | |
| "security-severity": "6.3", | |
| "severity": "MEDIUM", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5015", | |
| "name": "GO-2026-5015", | |
| "shortDescription": { | |
| "text": "GO-2026-5015 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5015", | |
| "properties": { | |
| "security-severity": "5.3", | |
| "severity": "MEDIUM", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5016", | |
| "name": "GO-2026-5016", | |
| "shortDescription": { | |
| "text": "GO-2026-5016 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5016", | |
| "properties": { | |
| "security-severity": "6.5", | |
| "severity": "MEDIUM", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5017", | |
| "name": "GO-2026-5017", | |
| "shortDescription": { | |
| "text": "GO-2026-5017 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5017", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5018", | |
| "name": "GO-2026-5018", | |
| "shortDescription": { | |
| "text": "GO-2026-5018 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5018", | |
| "properties": { | |
| "security-severity": "7.5", | |
| "severity": "HIGH", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5019", | |
| "name": "GO-2026-5019", | |
| "shortDescription": { | |
| "text": "GO-2026-5019 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5019", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5020", | |
| "name": "GO-2026-5020", | |
| "shortDescription": { | |
| "text": "GO-2026-5020 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5020", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5021", | |
| "name": "GO-2026-5021", | |
| "shortDescription": { | |
| "text": "GO-2026-5021 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5021", | |
| "properties": { | |
| "security-severity": "9.1", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5023", | |
| "name": "GO-2026-5023", | |
| "shortDescription": { | |
| "text": "GO-2026-5023 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5023", | |
| "properties": { | |
| "security-severity": "10.0", | |
| "severity": "CRITICAL", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "error" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5033", | |
| "name": "GO-2026-5033", | |
| "shortDescription": { | |
| "text": "GO-2026-5033 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5033", | |
| "properties": { | |
| "security-severity": "5.3", | |
| "severity": "MEDIUM", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| }, | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5005", | |
| "ruleIndex": 0, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5005 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5006", | |
| "ruleIndex": 1, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5006 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5013", | |
| "ruleIndex": 2, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5013 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5014", | |
| "ruleIndex": 3, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5014 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5015", | |
| "ruleIndex": 4, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5015 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5016", | |
| "ruleIndex": 5, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5016 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5017", | |
| "ruleIndex": 6, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5017 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5018", | |
| "ruleIndex": 7, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5018 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5019", | |
| "ruleIndex": 8, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5019 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5020", | |
| "ruleIndex": 9, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5020 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5021", | |
| "ruleIndex": 10, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5021 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5023", | |
| "ruleIndex": 11, | |
| "level": "error", | |
| "message": { | |
| "text": "GO-2026-5023 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5033", | |
| "ruleIndex": 12, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5033 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab). Fixed in 0.52.0" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "fixed_version": "0.52.0", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 13, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.51.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/local/bin/rke2-cloud-provider" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.51.0", | |
| "status": "not_present", | |
| "version": "v0.51.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:56:38.984942418Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.52.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "snapshot-controller" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.52.0", | |
| "status": "not_present", | |
| "version": "v0.52.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:56:43.209446649Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-snapshot-controller:v8.6.0-build20260722" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.52.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "traefik" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.52.0", | |
| "status": "not_present", | |
| "version": "v0.52.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:56:49.389732785Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-traefik:v3.7.8-build20260717" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "calicoctl" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "opt/cni/bin/calico" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "opt/cni/bin/calico-ipam" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/calico-node" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| }, | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "usr/bin/kube-controllers" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:57:15.640756788Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-calico:v3.32.1-build20260722" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json", | |
| "version": "2.1.0", | |
| "runs": [ | |
| { | |
| "tool": { | |
| "driver": { | |
| "name": "vexscan", | |
| "version": "(devel)", | |
| "informationUri": "https://github.com/cwayne18/vexscan", | |
| "rules": [ | |
| { | |
| "id": "GO-2026-5932", | |
| "name": "GO-2026-5932", | |
| "shortDescription": { | |
| "text": "GO-2026-5932 in golang.org/x/crypto" | |
| }, | |
| "helpUri": "https://osv.dev/vulnerability/GO-2026-5932", | |
| "properties": { | |
| "severity": "UNKNOWN", | |
| "tags": [ | |
| "security", | |
| "vulnerability", | |
| "golang" | |
| ] | |
| }, | |
| "defaultConfiguration": { | |
| "level": "warning" | |
| } | |
| } | |
| ] | |
| } | |
| }, | |
| "results": [ | |
| { | |
| "ruleId": "GO-2026-5932", | |
| "ruleIndex": 0, | |
| "level": "warning", | |
| "message": { | |
| "text": "GO-2026-5932 affects golang.org/x/crypto v0.53.0 (status: not_present, pclntab)" | |
| }, | |
| "locations": [ | |
| { | |
| "physicalLocation": { | |
| "artifactLocation": { | |
| "uri": "opt/bin/flanneld" | |
| } | |
| } | |
| } | |
| ], | |
| "suppressions": [ | |
| { | |
| "kind": "external", | |
| "justification": "vulnerable_code_not_present" | |
| } | |
| ], | |
| "properties": { | |
| "ecosystem": "golang", | |
| "justification": "vulnerable_code_not_present", | |
| "method": "pclntab", | |
| "package": "golang.org/x/crypto", | |
| "purl": "pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0", | |
| "status": "not_present", | |
| "version": "v0.53.0" | |
| } | |
| } | |
| ], | |
| "properties": { | |
| "advisories_as_of": "2026-08-07T17:57:21.518678858Z", | |
| "mode": "image", | |
| "target": "docker.io/rancher/hardened-flannel:v0.28.8-build20260722" | |
| } | |
| } | |
| ] | |
| } | |
| ] |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment