Package
k8sgpt
Component
helm.sh/helm/v3
Latest update
Fixed version
0.4.38-r3
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
0.4.38-r3Status
Impact
Govulncheck found vulnerable symbols in Go binary at usr/bin/k8sgpt.
Status
Status
Fixed version
0.4.36-r1Status
Impact
The vulnerability originates from the Helm dependency. Upgrading Helm breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.
Status