fix go module vulnerability in metrics capability #2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Address go module vulnerabilities flagged for cadvisor in metrics capability https://portal.microsofticm.com/imp/v5/incidents/details/585665116/summary
Query
ScanResult
#table cols="5"
Package Installed_Version Required_Version Language Install_Path
golang.org/x/crypto v0.21.0 0.31.0 Go usr/local/bin/node__exporter
golang.org/x/crypto v0.21.0 0.31.0 Go usr/local/bin/pushgateway
golang.org/x/crypto v0.24.0 0.31.0 Go usr/local/bin/cadvisor
golang.org/x/crypto v0.24.0 0.31.0 Go usr/local/bin/prometheus
#table cols="5"
Package Installed_Version Required_Version Language Install_Path
golang.org/x/net v0.23.0 0.33.0 Go usr/local/bin/node__exporter
golang.org/x/net v0.26.0 0.33.0 Go usr/local/bin/prometheus
golang.org/x/net v0.26.0 0.33.0 Go usr/local/bin/cadvisor
golang.org/x/net v0.23.0 0.33.0 Go usr/local/bin/pushgateway
#table cols="5"
Package Installed_Version Required_Version Language Install_Path
google.golang.org/grpc v1.64.0 1.64.1 Go usr/local/bin/prometheus
google.golang.org/grpc v1.64.0 1.64.1 Go usr/local/bin/cadvisor
#table cols="5"
Package Installed_Version Required_Version Language Install_Path
github.com/docker/docker v26.1.3+incompatible 26.1.5 Go usr/local/bin/prometheus
github.com/docker/docker v27.0.0+incompatible 27.1.1 Go usr/local/bin/cadvisor