Package
k8sgpt
Component
github.com/ollama/ollama
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
Not vulnerable. GHSA-89qx-m49c-8crf / CVE-2024-12055 affects github.com/ollama/ollama <= 0.3.14 only; upstream records no fixed version because later releases are not affected. This package ships ollama 0.17.1-0.30.10, above the affected range. The detection originates from the Go vulnerability database record (GO-2025-3558) omitting the last_affected 0.3.14 bound carried by the GHSA/OSV data, causing the scanner to over-match.
Status