Skip to content

Conversation

@octo-sts
Copy link
Contributor

@octo-sts octo-sts bot commented Aug 17, 2025

helm-mapkubeapis/0.6.1-r2: fix GHSA-f9f8-9pmf-xv68

Advisory data: https://github.com/wolfi-dev/advisories/blob/main/helm-mapkubeapis.advisories.yaml


"Breadcrumbs" for this automated service

@octo-sts octo-sts bot added P1 This label indicates our scanning found High, Medium or Low CVEs for these packages. automated pr GHSA-f9f8-9pmf-xv68 go/bump helm-mapkubeapis request-cve-remediation labels Aug 17, 2025
…7f1c3eb7d61f7e0076

Signed-off-by: Vishal Choudhary <vishal.choudhary@chainguard.dev>
@vishal-chdhry vishal-chdhry self-assigned this Aug 18, 2025
@octo-sts
Copy link
Contributor Author

octo-sts bot commented Aug 18, 2025

📦 Build Failed: Missing Dependency

package github.com/docker/docker was not found on the go.mod file. Please remove the package or add it to the list of 'replaces'

Build Details

Category Details
Build System melange/go
Failure Point go/bump step - gobump command execution

Root Cause Analysis 🔍

The gobump tool is attempting to update the github.com/docker/docker package to version v28.0.0, but this package is not present in the go.mod file. This suggests either the package was removed from dependencies or the bump configuration is trying to update a package that doesn't exist in the current module dependencies.


Was this comment helpful? Please use 👍 or 👎 reactions on this comment.

@octo-sts octo-sts bot added the ai/skip-comment Stop AI from commenting on PR label Aug 18, 2025
Signed-off-by: Vishal Choudhary <vishal.choudhary@chainguard.dev>
@octo-sts octo-sts bot added bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. manual/review-needed labels Aug 18, 2025
@kbsteere kbsteere enabled auto-merge (squash) August 18, 2025 16:58
@kbsteere kbsteere merged commit f9b263b into main Aug 18, 2025
18 checks passed
@kbsteere kbsteere deleted the cve-helm-mapkubeapis-0.6.1-r2-45daddae2bbf227f1c3eb7d61f7e0076 branch August 18, 2025 16:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai/skip-comment Stop AI from commenting on PR automated pr bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. GHSA-f9f8-9pmf-xv68 go/bump helm-mapkubeapis manual/review-needed P1 This label indicates our scanning found High, Medium or Low CVEs for these packages. request-cve-remediation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants