Skip to content

build(deps): Bump github.com/kubescape/storage from 0.0.185 to 0.2.0#2719

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/kubescape/storage-0.2.0
Open

build(deps): Bump github.com/kubescape/storage from 0.0.185 to 0.2.0#2719
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/kubescape/storage-0.2.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Jul 7, 2025

Bumps github.com/kubescape/storage from 0.0.185 to 0.2.0.

Release notes

Sourced from github.com/kubescape/storage's releases.

Release v0.0.263

Bumps github.com/cilium/cilium from 1.16.17 to 1.17.14.

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jul 7, 2025
@kusari-inspector
Copy link
Copy Markdown

kusari-inspector Bot commented Jul 7, 2025

Kusari Inspector

Kusari Analysis Results:

Do not proceed without addressing issues

Caution

Flagged Issues Detected
These changes contain flagged issues that may introduce security risks.

While the code analysis returned a clean result with zero vulnerabilities or secrets detected, the dependency analysis identified a critical blocking issue that must be resolved first. A high-severity container escape vulnerability (CVE-2025-52881) exists in the transitive dependency github.com/opencontainers/selinux v1.12.0, introduced via the chain: github.com/ossf/scorecard/v4 -> github.com/moby/buildkit -> github.com/opencontainers/selinux. This vulnerability allows an attacker to exploit arbitrary write gadgets and procfs write redirects in runc, potentially enabling full container breakout by misdirecting writes to dangerous files such as /proc/sysrq-trigger or /proc/sys/kernel/core_pattern. The CVSS impact scores are critically high across all vectors (VC:H/VI:H/VA:H/SC:H/SI:H/SA:H), representing a severe business risk for any containerized workload. The clean code analysis does not mitigate or invalidate this dependency risk, as the two analyses are independent. A fix path is available: update github.com/ossf/scorecard/v4 to its latest patched version and run go mod tidy to resolve the transitive dependency. This PR should not be merged until the vulnerable dependency is remediated.

Note

View full detailed analysis result for more information on the output and the checks that were run.

Required Dependency Mitigations

  • CRITICAL - CVE-2025-52881 in github.com/opencontainers/selinux v1.12.0: This is a container escape and denial of service vulnerability caused by arbitrary write gadgets and procfs write redirects in runc. An attacker can trick runc into misdirecting writes to /proc, potentially writing to dangerous files like /proc/sysrq-trigger or /proc/sys/kernel/core_pattern, enabling full container breakout. Dependency path: github.com/ossf/scorecard/v4 -> github.com/moby/buildkit -> github.com/opencontainers/selinux (vulnerable). Fix: Update the root parent dependency github.com/ossf/scorecard/v4 to a version that pulls in a patched or removed version of github.com/opencontainers/selinux. The vulnerabilityFixReport confirms this is fixable via a parent update. Run: go get github.com/ossf/scorecard/v4@<latest-patched-version> and then go mod tidy to resolve the transitive dependency.

@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: c44b5b7, performed at: 2026-04-01T14:39:43Z

Found this helpful? Give it a 👍 or 👎 reaction!

@stale
Copy link
Copy Markdown

stale Bot commented Sep 6, 2025

This pull request has been automatically marked as stale because it has not had recent activity (60 days of inactivity).
It will be closed in 30 days if no further activity occurs.
Thank you for your contribution!

@stale stale Bot added the wontfix This will not be worked on label Sep 6, 2025
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot rebase

@stale stale Bot removed the wontfix This will not be worked on label Sep 6, 2025
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 32eb074 to 1b297bf Compare September 6, 2025 16:50
@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 1b297bf performed at: 2025-09-06T16:55:27Z - link to updated analysis

@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 1b297bf to 6c672d3 Compare September 17, 2025 16:13
@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 6c672d3 performed at: 2025-09-17T16:15:34Z - link to updated analysis

@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 6c672d3 to 0878402 Compare September 17, 2025 23:40
@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 0878402 performed at: 2025-09-17T23:43:50Z - link to updated analysis

@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 0878402 to 1ffc2d4 Compare October 29, 2025 16:56
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 1ffc2d4 to 134ced5 Compare December 17, 2025 18:53
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 134ced5 to c7ac47d Compare January 9, 2026 17:27
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from c7ac47d to 88fb746 Compare February 11, 2026 02:58
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 88fb746 to 228a6f0 Compare February 11, 2026 03:13
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 228a6f0 to 4b1868f Compare February 12, 2026 15:42
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 4b1868f to 29dbc49 Compare February 25, 2026 14:51
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 29dbc49 to 00218b2 Compare February 25, 2026 15:05
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 00218b2 to 6296b42 Compare February 27, 2026 15:16
@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 6296b42 performed at: 2026-02-27T15:21:08Z - link to updated analysis

@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 6296b42 to 47c156a Compare February 27, 2026 15:26
@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 47c156a performed at: 2026-02-27T15:29:51Z - link to updated analysis

@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 47c156a to 3bc6b0c Compare February 27, 2026 15:48
@mihaimaruseac
Copy link
Copy Markdown
Member

@dependabot recreate

Bumps [github.com/kubescape/storage](https://github.com/kubescape/storage) from 0.0.166 to 0.2.0.
- [Release notes](https://github.com/kubescape/storage/releases)
- [Commits](https://github.com/kubescape/storage/commits)

---
updated-dependencies:
- dependency-name: github.com/kubescape/storage
  dependency-version: 0.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump github.com/kubescape/storage from 0.0.166 to 0.2.0 build(deps): Bump github.com/kubescape/storage from 0.0.185 to 0.2.0 Apr 1, 2026
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/kubescape/storage-0.2.0 branch from 3bc6b0c to c44b5b7 Compare April 1, 2026 14:37
@kusari-inspector
Copy link
Copy Markdown

Kusari PR Analysis rerun based on - c44b5b7 performed at: 2026-04-01T14:40:21Z - link to updated analysis

@gaganhr94
Copy link
Copy Markdown
Contributor

kubescape 0.2.0 has some changes where the functions have been renamed. So this requires some manual work for the upgrade. I'll raise another PR for this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code size/S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants