Skip to content

[Please don't merge, generated by RAVEN bot] : fix: Security updates for ibm/ibm-object-csi-driver-operator - Issue #303187 - #139

Open
balraj111 wants to merge 1 commit into
raven-demo-v1from
raven-sec-fix-ibm-object-csi-driver-operator-v0.12.26
Open

[Please don't merge, generated by RAVEN bot] : fix: Security updates for ibm/ibm-object-csi-driver-operator - Issue #303187#139
balraj111 wants to merge 1 commit into
raven-demo-v1from
raven-sec-fix-ibm-object-csi-driver-operator-v0.12.26

Conversation

@balraj111

Copy link
Copy Markdown
Collaborator

CVE Security Fixes for Issue #303187

Image: ibm/ibm-object-csi-driver-operator

Fixed CVEs:

  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get github.com/IBM/ibm-object-csi-driver-operator@latest
    • Output: Command failed: go: package github.com/IBM/ibm-object-csi-driver-operator is in the main module, so can't request version latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get github.com/onsi/ginkgo/v2@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get github.com/onsi/gomega@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get github.com/openshift/api@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get github.com/openshift/client-go@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get github.com/presslabs/controller-util@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get github.com/prometheus/client_golang@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get github.com/prometheus/common@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get golang.org/x/crypto@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get golang.org/x/tools@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get k8s.io/api@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get k8s.io/apiextensions-apiserver@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get k8s.io/apimachinery@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get k8s.io/client-go@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get k8s.io/kube-openapi@latest
  • CVE-2026-33814 - golang.org/x/net/http2

    • Command: go get sigs.k8s.io/controller-runtime@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/IBM/ibm-object-csi-driver-operator@latest
    • Output: Command failed: go: package github.com/IBM/ibm-object-csi-driver-operator is in the main module, so can't request version latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/gorilla/websocket@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/grpc-ecosystem/go-grpc-middleware/providers/prometheus@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/grpc-ecosystem/go-grpc-middleware/v2@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/grpc-ecosystem/grpc-gateway/v2@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/onsi/ginkgo/v2@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/onsi/gomega@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/openshift/api@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/openshift/client-go@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/presslabs/controller-util@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/prometheus/client_golang@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get github.com/prometheus/common@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get go.etcd.io/etcd/api/v3@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get go.etcd.io/etcd/client/v3@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get go.opentelemetry.io/proto/otlp@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get golang.org/x/crypto@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get golang.org/x/tools@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get google.golang.org/genproto/googleapis/api@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get google.golang.org/grpc@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get k8s.io/api@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get k8s.io/apiextensions-apiserver@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get k8s.io/apimachinery@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get k8s.io/apiserver@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get k8s.io/client-go@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get k8s.io/component-base@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get k8s.io/kms@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get k8s.io/streaming@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get sigs.k8s.io/apiserver-network-proxy/konnectivity-client@latest
  • CVE-2026-39821 - golang.org/x/net/idna

    • Command: go get sigs.k8s.io/controller-runtime@latest
  • golang_version - go (go.mod)

    • Command: go version upgrade → 1.26.5
    • Output: go.mod updated: go 1.26.0 → go 1.26.5

Go Version Info:

  • Current Version: 1.26.5
  • Upgrade Required: False
  • Recommended Version: 1.26.5
  • Reason: go 1.26.5 meets the minimum requirement (1.26) — no upgrade needed.

Additional Actions:

  • Go mod tidy executed: ✅

Generated by RAVEN BOT


Generated by RAVEN BOT

Fixed CVEs: CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-33814, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, CVE-2026-39821, golang_version

Generated by RAVEN BOT
@balraj111 balraj111 added the RAVEN_BOT Auto-generated by RAVEN bot label Jul 24, 2026
@balraj111
balraj111 requested a review from mssachan July 24, 2026 13:08
@balraj111

Copy link
Copy Markdown
Collaborator Author

@mssachan watch this demo

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

RAVEN_BOT Auto-generated by RAVEN bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant