Package
kyverno-fips-1.19
Component
golang.org/x/crypto
Latest update
Aliases
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
This package is affected by GO-2026-5932 through its golang.org/x/crypto/openpgp dependency; remediation is pending upstream migrating to a supported openpgp library such as ProtonMail/go-crypto/openpgp. GO-2026-5932 is not a specific code vulnerability but a call-to-action in which golang.org/x/crypto/openpgp maintainers describe the dependency as "unsafe by design", "not maintained", and "should not be used".
Status
Impact
Govulncheck found vulnerable symbols in Go binary at usr/bin/kyverno.
Status