Skip to content

fix: remediate Harbor dependency vulnerabilities#190

Merged
yuzichen12123 merged 2 commits into
alauda-1.18from
fix/harbor-vuln-remediation-20260602
Jun 3, 2026
Merged

fix: remediate Harbor dependency vulnerabilities#190
yuzichen12123 merged 2 commits into
alauda-1.18from
fix/harbor-vuln-remediation-20260602

Conversation

@yuzichen12123

Copy link
Copy Markdown
Collaborator

Summary

  • Update github.com/Azure/go-ntlmssp in subtree/harbor/src.
  • Update GOLANG_IMAGE_VERSION from 1.26.2 to 1.26.3 in Tekton and patch scripts.
  • Keep Photon base image unchanged for now; a follow-up PR will update it after a fixed Photon tag is published.

Verification

  • GOTOOLCHAIN=auto GOPROXY=https://proxy.golang.org,direct go test ./... in subtree/harbor/src was attempted and stopped at github.com/goharbor/harbor/src/common/dao because POSTGRESQL_HOST is not set.
  • Non-testing go.mod scan: only LOW github.com/jackc/pgx/v4 CVE-2026-41889 remains, with no fixed version in Trivy DB.

@Tongcaiyun

Copy link
Copy Markdown

/lgtm

@edge-katanomi-app2 edge-katanomi-app2 Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM Status - Ready to Merge

This PR has received 1/1 valid LGTM approvals and meets the approval threshold.

LGTM Summary:

User Permission Valid
@Tongcaiyun read

The PR is now ready for merge! 🎉

⚠️ Check Runs Status - Some checks are not passing

Check Name Status
Pipelines as Code CI / harbor-all-in-one failure

Note: All checks must pass before this PR can be merged.

@yuzichen12123 yuzichen12123 merged commit e7b1046 into alauda-1.18 Jun 3, 2026
3 of 4 checks passed
@yuzichen12123 yuzichen12123 deleted the fix/harbor-vuln-remediation-20260602 branch June 3, 2026 07:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants