Skip to content

Current images have many Go related CVEs #290

Description

@scottmuc-mo

Environment

Chart Version: 2.4.1

Helm Version: 3.2 (helm Terraform provider version)

Kubernetes Version: 1.35.5

This issue

I wasn't sure how to categorize this report so I'm going with a blank one.

We run the 1password-connect serve and operator in our GKE k8s clusters. The Google Security Command Center is reporting as of Jul 20th 2026 that there are 148 HIGH/CRIT findings in the connect-server deployment.

Sampling some of the findings, it looks like vulnerabilities in the underlying go dependencies such as golang.org/x/crypto.

Normally, I rely on bumps to the helm chart to bump the deployed images to resolve these findings, but I haven't seen this chart updated since March 2026. Are these helm charts unfit for production use-cases right now?

Let me know what information about our deployments would help flesh out the details you need to address this.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions