From 2b2f7f0d2289195dca3b3159ecf506e3a50e1db7 Mon Sep 17 00:00:00 2001 From: "SUSE Observability AI (POC)" Date: Thu, 3 Sep 2026 11:57:47 +0000 Subject: [PATCH 1/2] Bump google.golang.org/grpc to v1.83.1 for CVE-2026-84304 The dev chart scan 33750416189 reports CVE-2026-84304 (HIGH) against google.golang.org/grpc v1.82.1 in quay.io/stackstate/stackstate-k8s-process-agent. v1.83.1 is the fixed version and is this repository's own direct dependency, not an inherited base-image package, so it is fixable here. The bump is version-only: no transitive module changed, `go mod verify` passes, and `go build -tags "kubelet kubeapiserver linux cri containerd linux_bpf" ./cmd/...` produces exactly the two pre-existing failures that master produces (undefined runtime.Tracer / runtime.RuntimeSecurity in the datadog-agent upstream eBPF compile assets, which the CI prebuild step generates and a bare checkout does not). Unit tests across pkg, config and model pass. The other findings the same scan attributes to this repository are not source work here. CVE-2026-56854 (x/crypto) was already fixed on master by 26dfc045; the scanned tag 3c6ccf04 predates it, so that row clears on the next image build. The openssl family is base-image packages that BCI.dockerfile installs unpinned via zypper update. --- go.mod | 4 ++-- go.sum | 7 +++++++ 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/go.mod b/go.mod index a4fd3ea7..bdd40b4c 100644 --- a/go.mod +++ b/go.mod @@ -146,7 +146,7 @@ require ( github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8 // indirect github.com/xor-gate/ar v0.0.0-20170530204233-5c72ae81e2b7 // indirect go.opencensus.io v0.24.0 // indirect - golang.org/x/crypto v0.55.0 // indirect + golang.org/x/crypto v0.55.0 golang.org/x/mod v0.38.0 // indirect golang.org/x/net v0.57.0 // indirect golang.org/x/oauth2 v0.36.0 // indirect @@ -156,7 +156,7 @@ require ( golang.org/x/tools v0.48.0 // indirect golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect google.golang.org/genproto v0.0.0-20240903143218-8af14fe29dc1 // indirect - google.golang.org/grpc v1.82.1 + google.golang.org/grpc v1.83.1 google.golang.org/protobuf v1.36.11 // indirect gopkg.in/inf.v0 v0.9.1 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect diff --git a/go.sum b/go.sum index 8ce29fd1..1447bccc 100644 --- a/go.sum +++ b/go.sum @@ -17,6 +17,7 @@ cloud.google.com/go v0.115.1 h1:Jo0SM9cQnSkYfp44+v+NQXHpcHqlnRJk2qxh6yvxxxQ= cloud.google.com/go v0.115.1/go.mod h1:DuujITeaufu3gL68/lOFIirVNJwQeyf5UXyi+Wbgknc= cloud.google.com/go/auth v0.9.5 h1:4CTn43Eynw40aFVr3GpPqsQponx2jv0BQpjvajsbbzw= cloud.google.com/go/auth v0.9.5/go.mod h1:Xo0n7n66eHyOWWCnitop6870Ilwo3PiZyodVkkH1xWM= +cloud.google.com/go/auth v0.18.2 h1:+Nbt5Ev0xEqxlNjd6c+yYUeosQ5TtEUaNcN/3FozlaM= cloud.google.com/go/auth/oauth2adapt v0.2.4 h1:0GWE/FUsXhf6C+jAkWgYm7X9tK8cuEIfy19DBn6B6bY= cloud.google.com/go/auth/oauth2adapt v0.2.4/go.mod h1:jC/jOpwFP6JBxhB3P5Rr0a9HLMC/Pe3eaL4NmdvqPtc= cloud.google.com/go/bigquery v1.0.1/go.mod h1:i/xbL2UlR5RvWAURpBYZTtm/cXjCha9lbfbpx4poX+o= @@ -901,6 +902,7 @@ github.com/google/pprof v0.0.0-20250403155104-27863c87afa6/go.mod h1:boTsfXsheKC github.com/google/renameio v0.1.0/go.mod h1:KWCgfxg9yswjAJkECMjeO8J8rahYeXnNhOm40UhjYkI= github.com/google/s2a-go v0.1.8 h1:zZDs9gcbt9ZPLV0ndSyQk6Kacx2g/X+SKYovpnz3SMM= github.com/google/s2a-go v0.1.8/go.mod h1:6iNWHTpQ+nfNRN5E00MSdfDwVesa8hhS32PhPO8deJA= +github.com/google/s2a-go v0.1.9 h1:LGD7gtMgezd8a/Xak7mEWL0PjoTQFvpRudN895yqKW0= github.com/google/subcommands v1.2.0/go.mod h1:ZjhPrFU+Olkh9WazFPsl27BQ4UPiG37m3yTrtFlrHVk= github.com/google/tink/go v1.7.0 h1:6Eox8zONGebBFcCBqkVmt60LaWZa6xg1cl/DwAh/J1w= github.com/google/tink/go v1.7.0/go.mod h1:GAUOd+QE3pgj9q8VKIGTCP33c/B7eb4NhxLcgTJZStM= @@ -915,10 +917,12 @@ github.com/google/wire v0.6.0 h1:HBkoIh4BdSxoyo9PveV8giw7ZsaBOvzWKfcg/6MrVwI= github.com/google/wire v0.6.0/go.mod h1:F4QhpQ9EDIdJ1Mbop/NZBRB+5yrR6qg3BnctaoUk6NA= github.com/googleapis/enterprise-certificate-proxy v0.3.4 h1:XYIDZApgAnrN1c855gTgghdIA6Stxb52D5RnLI1SLyw= github.com/googleapis/enterprise-certificate-proxy v0.3.4/go.mod h1:YKe7cfqYXjKGpGvmSg28/fFvhNzinZQm8DGnaburhGA= +github.com/googleapis/enterprise-certificate-proxy v0.3.11 h1:vAe81Msw+8tKUxi2Dqh/NZMz7475yUvmRIkXr4oN2ao= github.com/googleapis/gax-go/v2 v2.0.4/go.mod h1:0Wqv26UfaUD9n4G6kQubkQ+KchISgw+vpHVxEJEs9eg= github.com/googleapis/gax-go/v2 v2.0.5/go.mod h1:DWXyrwAJ9X0FpwwEdw+IPEYBICEFu5mhpdKc/us6bOk= github.com/googleapis/gax-go/v2 v2.13.0 h1:yitjD5f7jQHhyDsnhKEBU52NdvvdSeGzlAnDPT0hH1s= github.com/googleapis/gax-go/v2 v2.13.0/go.mod h1:Z/fvTZXF8/uw7Xu5GuslPw+bplx6SS338j1Is2S+B7A= +github.com/googleapis/gax-go/v2 v2.17.0 h1:RksgfBpxqff0EZkDWYuz9q/uWsTVz+kf43LsZ1J6SMc= github.com/gopherjs/gopherjs v0.0.0-20181017120253-0766667cb4d1/go.mod h1:wJfORRmW1u3UXTncJ5qlYoELFm8eSnnEO6hX4iZ3EWY= github.com/gopherjs/gopherjs v0.0.0-20200217142428-fce0ec30dd00 h1:l5lAOZEym3oK3SQ2HBHWsJUfbNBiTXJDeW2QDxw9AQ0= github.com/gopherjs/gopherjs v0.0.0-20200217142428-fce0ec30dd00/go.mod h1:wJfORRmW1u3UXTncJ5qlYoELFm8eSnnEO6hX4iZ3EWY= @@ -1433,6 +1437,7 @@ github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk= github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg= github.com/spiffe/go-spiffe/v2 v2.6.0 h1:l+DolpxNWYgruGQVV0xsfeya3CsC7m8iBzDnMpsbLuo= github.com/spiffe/go-spiffe/v2 v2.6.0/go.mod h1:gm2SeUoMZEtpnzPNs2Csc0D/gX33k1xIx7lEzqblHEs= +github.com/spiffe/go-spiffe/v2 v2.7.0 h1:uXe1MflJoHw58wAUvxVlcM7WpKtijWG7I1UidcGh6g4= github.com/square/certstrap v1.2.0 h1:ecgyABrbFLr8jSbOC6oTBmBek0t/HqtgrMUZCPuyfdw= github.com/square/certstrap v1.2.0/go.mod h1:CUHqV+fxJW0Y5UQFnnbYwQ7bpKXO1AKbic9g73799yw= github.com/streadway/amqp v1.1.0 h1:py12iX8XSyI7aN/3dUT8DFIDJazNJsVJdxNVEpnQTZM= @@ -2073,6 +2078,8 @@ google.golang.org/grpc v1.33.1/go.mod h1:fr5YgcSWrqhRRxogOsw7RzIpsmvOZ6IcH4kBYTp google.golang.org/grpc v1.33.2/go.mod h1:JMHMWHQWaTccqQQlmk3MJZS+GWXOdAesneDmEnv2fbc= google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE= google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA= +google.golang.org/grpc v1.83.1 h1:HIO0+BEtBP6soyqvqC8sNUjZ7bTs+0hFQuFF+RAy++Y= +google.golang.org/grpc v1.83.1/go.mod h1:kDyl6SKsiHKt0uylY5gtn5cEjkrIOhQOGDgIc4JGwzQ= google.golang.org/grpc/examples v0.0.0-20221020162917-9127159caf5a h1:p51n6zkL483uumoZhCSGtHCem9kDeU05G5jX/wYI9gw= google.golang.org/grpc/examples v0.0.0-20221020162917-9127159caf5a/go.mod h1:gxndsbNG1n4TZcHGgsYEfVGnTxqfEdfiDv6/DADXX9o= google.golang.org/protobuf v0.0.0-20200109180630-ec00e32a8dfd/go.mod h1:DFci5gLYBciE7Vtevhsrf46CRTquxDuWsQurQQe4oz8= From 7d1d12d2ad6f1a829cb4d0758eb22f827abd988e Mon Sep 17 00:00:00 2001 From: "SUSE Observability AI (POC)" Date: Sun, 6 Sep 2026 11:19:49 +0000 Subject: [PATCH 2/2] Bump golang.org/x/crypto to v0.56.0 for CVE-2026-56855 and CVE-2026-78662 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The rebuilt image at 2b2f7f0d reports two unmanaged findings that the dev chart scan 34027081656 could not see, because that scan measured the stale tag 3c6ccf04 at v0.53.0: CVE-2026-56855 [UNKNOWN] pkg:golang/golang.org/x/crypto@v0.55.0 [grype,trivy] CVE-2026-78662 [UNKNOWN] pkg:golang/golang.org/x/crypto@v0.55.0 [grype,trivy] Both are golang.org/x/crypto/ssh channel-deadlock DoS advisories (GO-2026-6355 and GO-2026-6354) whose fixed version is v0.56.0. x/crypto/ssh is not linked here — the only module packages in the command graph are ocsp, pbkdf2 and scrypt — so neither advisory is reachable in this binary. Bumping anyway for the same reason as 26dfc045: a compatible fixed version exists, which is cheaper and more durable than a suppression. Version-only, no transitive module moved. The `// indirect` marker that 2b2f7f0d dropped from this line is restored, because nothing in this repository imports x/crypto directly. The GO-2026-5932 exception's component purl moves with the module. The evaluator keys exceptions on image and vulnerability id, so the bump could not have unmatched it, but a stale purl would misstate which artifact the accepted risk covers. Its expiry is deliberately left alone: GO-2026-5932 has introduced: 0 and no fixed event in any version, so renewing it or replacing it with a vexhub statement is an exception decision, not remediation. CVE ticket: https://github.com/StackVista/cve-reporter/issues/69 --- exceptions/GO-2026-5932.yaml | 2 +- go.mod | 2 +- go.sum | 2 ++ 3 files changed, 4 insertions(+), 2 deletions(-) diff --git a/exceptions/GO-2026-5932.yaml b/exceptions/GO-2026-5932.yaml index 01022348..f2620443 100644 --- a/exceptions/GO-2026-5932.yaml +++ b/exceptions/GO-2026-5932.yaml @@ -6,7 +6,7 @@ product: consumer: stackstate-process-agent image: quay.io/stackstate/stackstate-k8s-process-agent component: - purl: pkg:golang/golang.org/x/crypto@v0.55.0 + purl: pkg:golang/golang.org/x/crypto@v0.56.0 paths: - opt/stackstate-agent/bin/agent/process-agent status: accepted_with_compensating_control diff --git a/go.mod b/go.mod index bdd40b4c..f2ef1725 100644 --- a/go.mod +++ b/go.mod @@ -146,7 +146,7 @@ require ( github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8 // indirect github.com/xor-gate/ar v0.0.0-20170530204233-5c72ae81e2b7 // indirect go.opencensus.io v0.24.0 // indirect - golang.org/x/crypto v0.55.0 + golang.org/x/crypto v0.56.0 // indirect golang.org/x/mod v0.38.0 // indirect golang.org/x/net v0.57.0 // indirect golang.org/x/oauth2 v0.36.0 // indirect diff --git a/go.sum b/go.sum index 1447bccc..88326f6f 100644 --- a/go.sum +++ b/go.sum @@ -1690,6 +1690,8 @@ golang.org/x/crypto v0.53.0 h1:QZ4Muo8THX6CizN2vPPd5fBGHyogrdK9fG4wLPFUsto= golang.org/x/crypto v0.53.0/go.mod h1:DNLU434OwVakk9PzuwV8w62mAJpRJL3vsgcfp4Qnsio= golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= golang.org/x/exp v0.0.0-20190306152737-a1d7652674e8/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= golang.org/x/exp v0.0.0-20190510132918-efd6b22b2522/go.mod h1:ZjyILWgesfNpC6sMxTJOJm9Kp84zZh5NQWvqDGG3Qr8=