Status
Justification
Impact
This vulnerability applies to the git-repo volume provisioner, not the k8s client itself.
Status
Impact
The k8s.io CVE affecting this package is still under upstream triage. See the related PR at https://github.com/kubernetes/kubernetes/issues/130786. The current upstream build remains on kubernetes@v1.31.x to retain support for k8s.io/kubelet/pkg/apis/dra/v1beta1, which was removed in v1.32.x.
Status