Skip to content

[CP 1272] [Fix] upgrade grpc to address CVE-2026-33186#499

Closed
ci-penbot-01 wants to merge 1 commit intoROCm:mainfrom
ci-penbot-01:CP.O2O.pensando.gpu-operator.1272.rocm.gpu-operator.main
Closed

[CP 1272] [Fix] upgrade grpc to address CVE-2026-33186#499
ci-penbot-01 wants to merge 1 commit intoROCm:mainfrom
ci-penbot-01:CP.O2O.pensando.gpu-operator.1272.rocm.gpu-operator.main

Conversation

@ci-penbot-01
Copy link
Copy Markdown
Contributor

cp of pensando/gpu-operator#1272


Source PR Description (pensando/gpu-operator#1272):

after this fix there is 0 CVE from the controller manager binary

Report Summary

┌──────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                              Target                              │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ registry.test.pensando.io:5000/amd-gpu-operator:dev (redhat 9.7) │  redhat  │       81        │    -    │
├──────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ usr/local/bin/kubectl                                            │ gobinary │        3        │    -    │
├──────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ usr/local/bin/manager                                            │ gobinary │        0        │    -    │
└──────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘

Cherrypick triggered by: ACP-Automation

Signed-off-by: yansun1996 <Yan.Sun3@amd.com>
(cherry picked from commit e53234bb65be10296ef944673f64b0e97974e5b5)
Copy link
Copy Markdown
Contributor

@spraveenio spraveenio left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lgtm

@yansun1996
Copy link
Copy Markdown
Member

#505

@yansun1996 yansun1996 closed this Apr 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants