No CVEs found across 25 repos — nothing to remediate.
🚨 Needs attention
📦 Per-repo findings 25 repos
| Repo | Crit | High | Med | Total | Status |
|---|---|---|---|---|---|
| kairos-io/AuroraBoot | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/cluster-api-provider-kairos | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/entangle | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/entangle-proxy | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/go-nodepair | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/go-ukify | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/hadron | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/immucore | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/kairos | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/kairos-agent | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/kairos-init | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/kairos-installer | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/kairos-lab | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/kairos-operator | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/kairos-sdk | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/kcrypt-discovery-challenger | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/netboot | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/provider-kairos | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/provider-kubernetes | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| kairos-io/tpm-helpers | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| mauromorales/xpasswd | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| mudler/edgevpn | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| mudler/entities | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| mudler/go-pluggable | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
| mudler/yip | 0 | 0 | 0 | 0 | clean (no crit/high/med) |
ℹ️ Informational — not counted 48
These findings are separated from the counts above: CVEs we are already past, or components accepted as pinned risk.
| Package | Current | Fixed | Severity | CVE | Why |
|---|---|---|---|---|---|
| openssl-fips | 3.1.2 | 3.3.7 | critical | CVE-2026-31789 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| busybox | 1.37.0 | 1.37.0 | low | CVE-2025-46394 | already-fixed |
| openssl-fips | 3.1.2 | 3.1.6 | critical | CVE-2024-5535 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.7 | high | CVE-2026-9076 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.5 | medium | CVE-2025-9231 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| glib | 2.86.2 | 2.66.6 | high | CVE-2021-27219 | already-fixed |
| openssl-fips | 3.1.2 | 3.3.6 | medium | CVE-2025-69418 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.1 | medium | CVE-2025-4575 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.3 | medium | CVE-2024-12797 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.7 | high | CVE-2026-45447 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.7 | medium | CVE-2026-45446 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.8 | high | CVE-2025-9230 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.5 | medium | CVE-2024-4603 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.7 | high | CVE-2026-7383 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.4 | medium | CVE-2024-0727 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.4 | medium | CVE-2023-5678 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.8 | medium | CVE-2025-9232 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.6 | high | CVE-2025-69420 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.4 | medium | CVE-2023-6129 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.4 | medium | CVE-2023-6237 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.7 | medium | CVE-2026-42766 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.7 | low | CVE-2026-42770 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.4 | high | CVE-2023-5363 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.7 | high | CVE-2024-6119 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| perl | 5.44.0 | 5.26.3 | unknown | CVE-2018-18311 | already-fixed |
| openssl-fips | 3.1.2 | 3.5.7 | critical | CVE-2026-34182 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.7 | high | CVE-2026-28387 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.6 | high | CVE-2025-15467 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| libxml2 | 2.15.3 | 2.13.8 | high | CVE-2025-32414 | already-fixed |
| openssl-fips | 3.1.2 | 3.3.7 | high | CVE-2026-28388 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.7 | high | CVE-2026-28389 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.6 | medium | CVE-2025-68160 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.7 | medium | CVE-2024-9143 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| libxml2 | 2.15.3 | 2.13.8 | high | CVE-2025-32415 | already-fixed |
| openssl-fips | 3.1.2 | 3.3.7 | high | CVE-2026-28390 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.6 | medium | CVE-2026-22796 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.7 | high | CVE-2026-34180 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.6 | high | CVE-2025-69421 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| busybox | 1.37.0 | 1.37.0 | low | CVE-2024-58251 | already-fixed |
| openssl-fips | 3.1.2 | 3.3.6 | high | CVE-2025-69419 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.4 | medium | CVE-2024-2511 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.6 | medium | CVE-2026-22795 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.3.7 | high | CVE-2026-31790 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.7 | high | CVE-2026-45445 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.8 | medium | CVE-2024-13176 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.5.7 | medium | CVE-2026-42767 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| openssl-fips | 3.1.2 | 3.1.6 | high | CVE-2024-4741 | accepted-component: FIPS 140-3 validated module, pinned at 3.1.2; cannot bump without revalidation |
| perl | 5.44.0 | 5.26.3 | unknown | CVE-2018-18312 | already-fixed |
📋 Open PRs CVE-related
No CVE-related PRs open.
🔎 Bot-PR reviews
kairos-io/AuroraBoot
- #409 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/foxboron/sbctl 0.0.0-20240526163235-64e649b31c8e→0.0.0-20260316200809-1b913e78d38c: compare 64e649b31c8e...1b913e78d38c ✓ 40000 bytes
- github.com/fatih/color 1.15.0→1.17.0: compare v1.15.0...v1.17.0 ✓ 9976 bytes
- context: 58368 bytes
- #594 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- facebook/react eslint-plugin-react-hooks@7.1.0..eslint-plugin-react-hooks@7.1.1 (PR body): compare eslint-plugin-react-hooks@7.1.0...eslint-plugin-react-hooks@7.1.1 ✓ 24066 bytes
- facebook/react 408b38ef7304faf022d2a37110c57efce12c6bad..eslint-plugin-react-hooks@7.1.0 (PR body): compare 408b38ef7304faf022d2a37110c57efce12c6bad...eslint-plugin-react-hooks@7.1.0 ✓ 40000 bytes
- context: 100023 bytes
- #599 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- eslint/eslint v10.0.0..v10.0.1 (PR body): compare v10.0.0...v10.0.1 ✓ 40000 bytes
- context: 77813 bytes
- #668 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- cypress-io/cypress v15.18.1..v15.19.0 (PR body): compare v15.18.1...v15.19.0 ✓ 40000 bytes
- context: 42668 bytes
- #669 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- kairos-io/kairos-init v0.16.0..v0.16.1 (PR body): compare v0.16.0...v0.16.1 ✓ 315 bytes
- kairos-io/kairos-init v0.15.3..v0.16.0 (PR body): compare v0.15.3...v0.16.0 ✓ 17599 bytes
- kairos-io/kairos-init v0.15.2..v0.16.0 (PR body): compare v0.15.2...v0.16.0 ✓ 17599 bytes
- kairos-io/kairos-init v0.15.2..v0.15.3 (PR body): compare v0.15.2...v0.15.3 ✓ 2322 bytes
- context: 42733 bytes
- #670 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/diskfs/go-diskfs 1.9.3→1.9.4: compare v1.9.3...v1.9.4 ✓ 40000 bytes
- github.com/kairos-io/kairos-sdk 0.23.3→0.24.0: compare v0.23.3...v0.24.0 ✓ 40000 bytes
- context: 88231 bytes
- #671 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- actions/setup-go v7.0.0..v7.0.0 (PR body): compare v7.0.0...v7.0.0 failed/empty (no upstream diff)
- actions/setup-go v6..v7.0.0 (PR body): compare v6...v7.0.0 ✓ 40000 bytes
- actions/setup-go v6.5.0..v7.0.0 (PR body): compare v6.5.0...v7.0.0 ✓ 40000 bytes
- context: 84713 bytes
- #672 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- actions/setup-node v7.0.0..v7.0.0 (PR body): compare v7.0.0...v7.0.0 failed/empty (no upstream diff)
- actions/setup-node v6..v7.0.0 (PR body): compare v6...v7.0.0 ✓ 40000 bytes
- actions/setup-node v6.5.0..v7.0.0 (PR body): compare v6.5.0...v7.0.0 ✓ 40000 bytes
- context: 84942 bytes
- #673 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- testing-library/jest-dom cae44df901cf8e92e3febc0af6fa667b10be6d6a..1e39089d850408a583c83495d00d8aa27078933f (PR body): compare cae44df901cf8e92e3febc0af6fa667b10be6d6a...1e39089d850408a583c83495d00d8aa27078933f ✓ 417 bytes
- testing-library/jest-dom v6.10.0..v7.0.0 (PR body): compare v6.10.0...v7.0.0 ✓ 417 bytes
- testing-library/jest-dom v6.9.1..cae44df901cf8e92e3febc0af6fa667b10be6d6a (PR body): compare v6.9.1...cae44df901cf8e92e3febc0af6fa667b10be6d6a ✓ 40000 bytes
- testing-library/jest-dom v6.9.1..v6.10.0 (PR body): compare v6.9.1...v6.10.0 ✓ 40000 bytes
- context: 85392 bytes
- #674 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- microsoft/TypeScript v6.0.3..2bd066d87f5bafd315be9f40889d0a60b9e58e0b (PR body): compare v6.0.3...2bd066d87f5bafd315be9f40889d0a60b9e58e0b failed/empty (no upstream diff)
- microsoft/TypeScript v6.0.2..v6.0.3 (PR body): compare v6.0.2...v6.0.3 ✓ 40000 bytes
- microsoft/TypeScript v5.9.3..v6.0.2 (PR body): compare v5.9.3...v6.0.2 ✓ 40000 bytes
- context: 84322 bytes
kairos-io/cluster-api-provider-kairos
- #38 ✅ good — This pull request is a routine dependency update for golang.org/x/oauth2. Updating to a newer version is standard practice and generally safe, as it addresses potential minor issues or security patches without introducing significant risk.
kairos-io/entangle
- #13 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/emicklei/go-restful 2.9.5+incompatible→2.16.0+incompatible: compare v2.9.5+incompatible...v2.16.0+incompatible failed/empty (no upstream diff)
- golang.org/x/crypto 0.52.0→0.53.0: compare v0.52.0...v0.53.0 ✓ 40000 bytes
- golang.org/x/net 0.55.0→0.56.0: compare v0.55.0...v0.56.0 ✓ 40000 bytes
- context: 97666 bytes
kairos-io/entangle-proxy
- #5 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/onsi/gomega 1.40.0→1.42.1: compare v1.40.0...v1.42.1 ✓ 40000 bytes
- golang.org/x/crypto 0.52.0→0.53.0: compare v0.52.0...v0.53.0 ✓ 40000 bytes
- context: 88243 bytes
- #6 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- sigs.k8s.io/controller-runtime 0.12.1→0.24.1: compare v0.12.1...v0.24.1 ✓ 40000 bytes
- context: 98801 bytes
- #14 ✅ good — This pull request primarily updates several dependencies to newer versions, including core packages like `golang.org/x` and `google.golang.org/protobuf`. Updating dependencies is a crucial security practice to ensure that known vulnerabilities are patched. The changes appear to be dependency hygiene improvements and do not introduce any obvious security risks.
- #18 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- docker/build-push-action v7.2.0..v7.3.0 (PR body): compare v7.2.0...v7.3.0 ✓ 40000 bytes
- context: 83719 bytes
- #20 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- k8s.io/api 0.24.0→0.36.3: compare v0.24.0...v0.36.3 ✓ 40000 bytes
- context: 126088 bytes
- #23 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- actions/checkout v7.0.0..v7.0.0 (PR body): compare v7.0.0...v7.0.0 failed/empty (no upstream diff)
- actions/checkout v6.0.3..v7.0.0 (PR body): compare v6.0.3...v7.0.0 ✓ 40000 bytes
- context: 63254 bytes
- #25 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/go-logr/logr 1.4.3→1.4.4: compare v1.4.3...v1.4.4 ✓ 40000 bytes
- context: 44091 bytes
kairos-io/go-nodepair
- #27 ✅ good — The changes involve updating several core dependencies across the project. The changelogs indicate that these updates include important security patches, such as restricting RSA key sizes in go-libp2p and fixing memory exhaustion attacks in quic-go. This is standard maintenance and security hygiene.
↳ This pull request updates several core dependencies, including go-libp2p, quic-go, golang.org/x/crypto, golang.org/x/image, golang.org/x/net, and google.golang.org/protobuf. The updates include critical security fixes, such as mitigating a DoS attack in go-libp2p and addressing memory exhaustion issues in quic-go.
- #65 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- ipfs/go-log v2.9.1..v2.9.2 (PR body): compare v2.9.1...v2.9.2 ✓ 12110 bytes
- ipfs/go-log v2.9.0..v2.9.1 (PR body): compare v2.9.0...v2.9.1 ✓ 2149 bytes
- ipfs/go-log v2.8.2..v2.9.0 (PR body): compare v2.8.2...v2.9.0 ✓ 40000 bytes
- context: 70615 bytes
- #66 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- actions/setup-go v6.5.0..v7.0.0 (PR body): compare v6.5.0...v7.0.0 ✓ 40000 bytes
- actions/setup-go v7.0.0..v7.0.0 (PR body): compare v7.0.0...v7.0.0 failed/empty (no upstream diff)
- context: 42046 bytes
kairos-io/go-ukify
- #59 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- securego/gosec v2.27.1..v2.28.0 (PR body): compare v2.27.1...v2.28.0 ✓ 40000 bytes
- context: 44536 bytes
- #60 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- actions/setup-go v6.5.0..v7.0.0 (PR body): compare v6.5.0...v7.0.0 ✓ 40000 bytes
- actions/setup-go v7.0.0..v7.0.0 (PR body): compare v7.0.0...v7.0.0 failed/empty (no upstream diff)
- context: 42433 bytes
- #61 ✅ good — This is a routine dependency version update. The context provided suggests that the dependency is undergoing a repository migration, which is a planned change. There are no immediate security red flags or major version changes indicated that would warrant manual review. Therefore, it is safe to auto-approve.
↳ This PR updates the dependency `github.com/ThalesGroup/crypto11` from version v1.6.2 to v1.6.5. The upstream context indicates this update is part of a project migration to `github.com/eclipse-keypont/crypto11`. This is a standard version bump for a third-party library.
review trace
- github.com/ThalesGroup/crypto11 1.6.2→1.6.5: compare v1.6.2...v1.6.5 ✓ 1245 bytes
- ThalesGroup/crypto11 v1.6.4..v1.6.5 (PR body): compare v1.6.4...v1.6.5 ✓ 309 bytes
- eclipse-keypont/crypto11 v1.6.3..v1.6.5 (PR body): compare v1.6.3...v1.6.5 ✓ 314 bytes
- ThalesGroup/crypto11 v1.6.3..v1.6.4 (PR body): compare v1.6.3...v1.6.4 ✓ 377 bytes
- ThalesGroup/crypto11 v1.6.2..v1.6.3 (PR body): compare v1.6.2...v1.6.3 ✓ 1316 bytes
- context: 6745 bytes
kairos-io/immucore
- #597 ✅ good — This is a configuration change to adjust the behavior of a security scanning tool within the CI pipeline. It does not introduce any new security risks or change the underlying security logic of the project. The change aligns with the stated goal of making the scan report-only instead of build-blocking.
↳ This change modifies the GitHub Actions workflow for OSV scanning to set `fail-on-vuln: false`. This prevents the CI job from failing when vulnerabilities are detected, ensuring that scanning reports are still published while maintaining CI flow.
review trace
- no upstream comparisons available (no go.mod bumps or compare links in the PR body)
- context: 1327 bytes
- #598 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- no upstream comparisons available (no go.mod bumps or compare links in the PR body)
- context: 20241 bytes
kairos-io/kairos
- #4229 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- docker/login-action c99871dec2022cc055c062a10cc1a1310835ceb4..af1e73f918a031802d376d3c8bbc3fe56130a9b0 (PR body): compare c99871dec2022cc055c062a10cc1a1310835ceb4...af1e73f918a031802d376d3c8bbc3fe56130a9b0 ✓ 40000 bytes
- context: 43062 bytes
- #4234 ✅ good — This is a routine minor version bump from a trusted dependency, and the changes are documented in the upstream release notes. The update is applied consistently across all relevant workflow files, suggesting a safe and necessary maintenance update.
↳ This PR updates the dependency `kairos-io/kairos-factory-action` from v1.1.3 to v1.2.0. This update incorporates changes from the upstream release, including updates to `actions/checkout` and `github/codeql-action`. The change is applied across multiple CI/CD workflow files.
review trace
- kairos-io/kairos-factory-action v1.1.3..v1.2.0 (PR body): compare v1.1.3...v1.2.0 ✓ 7319 bytes
- context: 15709 bytes
- #4256 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- actions/checkout v7.0.0..v7.0.1 (PR body): compare v7.0.0...v7.0.1 ✓ 40000 bytes
- context: 48520 bytes
- #4259 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- aws-actions/configure-aws-credentials 517a711dbcd0e402f90c77e7e2f81e849156e31d..e6de054238d6b7531b4efff3b6587d9aade6a06c (PR body): compare 517a711dbcd0e402f90c77e7e2f81e849156e31d...e6de054238d6b7531b4efff3b6587d9aade6a06c ✓ 40000 bytes
- context: 42305 bytes
- #4262 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- ossf/scorecard-action v2.4.3..v2.4.4 (PR body): compare v2.4.3...v2.4.4 ✓ 40000 bytes
- context: 42648 bytes
kairos-io/kairos-operator
- #149 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- docker/login-action 06fb636fac595d6fb4b28a5dfcb21a6f5091859c..abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 (PR body): compare 06fb636fac595d6fb4b28a5dfcb21a6f5091859c...abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 ✓ 40000 bytes
- context: 43269 bytes
kairos-io/kcrypt-discovery-challenger
- #41 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- k8s.io/api 0.27.2→0.36.0: compare v0.27.2...v0.36.0 ✓ 40000 bytes
- context: 123081 bytes
- #190 ✅ good — Updating core infrastructure dependencies like Kubernetes components to the latest stable version is a crucial security and stability practice. This change incorporates bug fixes and security patches from the upstream, making the project more resilient. Therefore, it is safe to auto-approve.
↳ This PR updates the core Kubernetes dependencies, k8s.io/api, k8s.io/apimachinery, and k8s.io/client-go, to version v0.36.2. This brings the project up to a recent, patched version of the Kubernetes ecosystem components.
review trace
- k8s.io/apimachinery 0.27.4→0.27.2: compare v0.27.4...v0.27.2 failed: <nil> (no upstream diff)
- github.com/emicklei/go-restful/v3 3.10.1→3.13.0: compare v3.10.1...v3.13.0 ✓ 40000 bytes
- context: 131955 bytes
- #247 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/go-logr/logr 1.4.3→1.4.4: compare v1.4.3...v1.4.4 ✓ 40000 bytes
- context: 44037 bytes
kairos-io/netboot
- #45 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- golang.org/x/crypto 0.53.0→0.54.0: compare v0.53.0...v0.54.0 ✓ 40000 bytes
- golang.org/x/sys 0.46.0→0.47.0: compare v0.46.0...v0.47.0 ✓ 33531 bytes
- context: 76977 bytes
- #46 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- golang.org/x/crypto 0.53.0→0.54.0: compare v0.53.0...v0.54.0 ✓ 40000 bytes
- golang.org/x/net 0.56.0→0.57.0: compare v0.56.0...v0.57.0 ✓ 40000 bytes
- context: 83965 bytes
- #47 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- actions/setup-go v7.0.0..v7.0.0 (PR body): compare v7.0.0...v7.0.0 failed/empty (no upstream diff)
- actions/setup-go v6..v7.0.0 (PR body): compare v6...v7.0.0 ✓ 40000 bytes
- actions/setup-go v6.5.0..v7.0.0 (PR body): compare v6.5.0...v7.0.0 ✓ 40000 bytes
- context: 83203 bytes
mauromorales/xpasswd
- #53 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- actions/setup-go v6.5.0..v7.0.0 (PR body): compare v6.5.0...v7.0.0 ✓ 40000 bytes
- actions/setup-go v7.0.0..v7.0.0 (PR body): compare v7.0.0...v7.0.0 failed/empty (no upstream diff)
- context: 42399 bytes
mudler/edgevpn
- #804 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- c-robinson/iplib v2.0.4..v2.0.5 (PR body): compare v2.0.4...v2.0.5 ✓ 6378 bytes
- c-robinson/iplib v2.0.3..v2.0.4 (PR body): compare v2.0.3...v2.0.4 ✓ 3273 bytes
- c-robinson/iplib v2.0.2..v2.0.3 (PR body): compare v2.0.2...v2.0.3 ✓ 9999 bytes
- c-robinson/iplib v2.0.1..v2.0.2 (PR body): compare v2.0.1...v2.0.2 ✓ 15662 bytes
- c-robinson/iplib v2.0.0..v2.0.1 (PR body): compare v2.0.0...v2.0.1 ✓ 1844 bytes
- context: 44543 bytes
- #805 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- go-yaml/yaml v3.0.0..v3.0.1 (PR body): compare v3.0.0...v3.0.1 ✓ 2202 bytes
- go-yaml/yaml v2.4.0..v3.0.0 (PR body): compare v2.4.0...v3.0.0 ✓ 40000 bytes
- context: 44433 bytes
- #905 ✅ good — This is a routine dependency bump for a tool used in the CI/CD workflow. The changelog indicates that version 2.4.0 includes various maintenance updates and fixes, suggesting this is a safe and necessary update. There are no immediate security red flags indicated by the context.
↳ This pull request updates the version of the `dependabot/fetch-metadata` dependency from 2.3.0 to 2.4.0. This upgrade incorporates various fixes, updates to actions, and improvements to the dependency fetching mechanism.
review trace
- dependabot/fetch-metadata v2..v2.4.0 (PR body): compare v2...v2.4.0 failed/empty (no upstream diff)
- dependabot/fetch-metadata v2.3.0..v2.4.0 (PR body): compare v2.3.0...v2.4.0 ✓ 40000 bytes
- context: 49729 bytes
- #923 ⚠️ needs_human_verification — review endpoint unreachable: Post "http://localhost:8080/v1/chat/completions": context deadline exceeded
review trace
- github.com/miekg/dns 1.1.66→1.1.68: compare v1.1.66...v1.1.68 ✓ 40000 bytes
- miekg/dns v1.1.64..v1.1.68 (PR body): compare v1.1.64...v1.1.68 ✓ 40000 bytes
- context: 86107 bytes
- #927 ✅ good — This is a standard dependency upgrade to a newer major version, which is generally a positive security and maintenance practice. The changes include necessary updates to workflows to use the new action version and Node.js version, as well as internal code refactoring to align with the v5 API. No security regressions are apparent.
↳ This pull request bumps the `actions/checkout` dependency from version 4 to 5.0.0 and updates related configurations across workflows and source code. It also updates the Node.js version used in workflows to 24.x and refactors the URL helper logic for improved handling of GitHub Enterprise Cloud and other hostnames.
review trace
- actions/checkout v4..v5.0.0 (PR body): compare v4...v5.0.0 ✓ 11870 bytes
- actions/checkout v4..v4.3.0 (PR body): compare v4...v4.3.0 failed/empty (no upstream diff)
- actions/checkout v4.2.1..v4.2.2 (PR body): compare v4.2.1...v4.2.2 ✓ 9872 bytes
- actions/checkout v4.2.0..v4.2.1 (PR body): compare v4.2.0...v4.2.1 ✓ 3510 bytes
- actions/checkout v4..v5 (PR body): compare v4...v5 ✓ 40000 bytes
- context: 84131 bytes
- #939 ✅ good — The change is a dependency bump for a widely used action, which is a standard maintenance task. The changelog indicates breaking changes, specifically a Node.js runtime upgrade, which requires verification in the CI pipeline. Assuming the project's CI passes successfully after this update, the change is safe to auto-approve.
↳ This PR upgrades the `actions/setup-go` dependency from version 5 to 6. This involves updating references in various GitHub Actions workflow files to use the new action version and incorporates breaking changes from v6.0.0, such as upgrading the Node.js runtime to node 24.x in affected workflows.
review trace
- actions/setup-go v5..v6.0.0 (PR body): compare v5...v6.0.0 ✓ 40000 bytes
- actions/setup-go v5..v5.5.0 (PR body): compare v5...v5.5.0 failed/empty (no upstream diff)
- actions/setup-go v5..v6 (PR body): compare v5...v6 ✓ 40000 bytes
- context: 92926 bytes
- #942 ✅ good — This is a routine dependency update to a newer minor version of a well-known testing library. The changes primarily involve version bumps and internal code refactoring, which are typical for dependency maintenance. Since this is a standard update and the changes appear to be focused on compatibility and minor fixes, it is safe to auto-approve.
↳ This PR bumps github.com/onsi/gomega to version 1.38.2 and updates several related dependencies, including golang.org/x/net, google.golang.org/protobuf, and gopkg.in/yaml.v3. It also includes internal refactoring in gstruct to improve handling of unexported fields and updates to internal error handling.
review trace
- github.com/onsi/gomega 1.37.0→1.38.2: compare v1.37.0...v1.38.2 ✓ 34194 bytes
- github.com/Masterminds/semver/v3 3.3.1→3.4.0: compare v3.3.1...v3.4.0 ✓ 40000 bytes
- context: 89137 bytes
- #943 ✅ good — This is a routine dependency update for a well-known action. The changes are confined to updating the version number, and the upstream changes detailed in the changelog appear to be standard maintenance and minor feature updates, posing no immediate security risk.
↳ This pull request updates the `codecov/codecov-action` dependency from version 5.5.0 to 5.5.1. This version bump incorporates several underlying dependency updates for related actions, such as `actions/checkout` and `github/codeql-action`.
review trace
- codecov/codecov-action v5.5.0..v5.5.1 (PR body): compare v5.5.0...v5.5.1 ✓ 10680 bytes
- context: 21031 bytes
- #946 ⚠️ needs_human_verification — review endpoint unreachable: Post "http://localhost:8080/v1/chat/completions": context deadline exceeded
review trace
- github.com/libp2p/go-libp2p-kad-dht 0.36.0→0.39.0: compare v0.36.0...v0.39.0 ✓ 40000 bytes
- golang.org/x/sys 0.41.0→0.42.0: compare v0.41.0...v0.42.0 ✓ 28932 bytes
- context: 212268 bytes
- #951 ✅ good — This is a standard dependency bump for a widely used GitHub Action. The changes primarily involve updating the version number and migrating usage patterns in workflows, which is typical for dependency maintenance. The noted breaking change regarding Node v24.x support is documented, making the update safe to proceed with for automated approval.
↳ This PR bumps the dependency `actions/download-artifact` from version 5 to 6. It updates the dependency version in the configuration, modifies usage in workflow files to use the new version, and updates internal code imports. The release notes indicate a breaking change related to Node v24.x support.
review trace
- actions/download-artifact v5..v6.0.0 (PR body): compare v5...v6.0.0 ✓ 40000 bytes
- actions/download-artifact v5..v6 (PR body): compare v5...v6 ✓ 40000 bytes
- context: 88447 bytes
- #961 ✅ good — The changes are a dependency bump to a newer minor version of a well-maintained library. The diffs show internal refactoring, modernization of logging, and the addition of new features (GossipSub v1.3 support and peer extensions). There are no apparent security regressions or breaking API changes that would warrant manual review.
↳ This PR bumps `go-libp2p-pubsub` to version 0.15.0, which includes internal refactoring for logging (migrating to `log/slog`), the addition of support for GossipSub protocol version 1.3, and the implementation of a new Peer Extensions mechanism for testing. These changes are primarily internal improvements and feature additions.
review trace
- github.com/libp2p/go-libp2p-pubsub 0.14.2→0.15.0: compare v0.14.2...v0.15.0 ✓ 40000 bytes
- libp2p/go-libp2p-pubsub v0.14.3..v0.15.0 (PR body): compare v0.14.3...v0.15.0 ✓ 40000 bytes
- context: 116011 bytes
- #1006 ✅ good — The upgrade is to a newer minor version (4.15.1) which includes security enhancements, such as the new CSRF middleware features detailed in the release notes. There are no immediate red flags or known critical vulnerabilities associated with this specific version jump. Therefore, this change is safe to auto-approve.
↳ This pull request updates the dependency `github.com/labstack/echo/v4` from version 4.13.3 to 4.15.1. This upgrade incorporates several enhancements, including improved CSRF protection features and minor internal fixes related to time comparison logic.
review trace
- github.com/labstack/echo/v4 4.13.3→4.15.1: compare v4.13.3...v4.15.1 ✓ 40000 bytes
- github.com/mattn/go-colorable 0.1.13→0.1.14: compare v0.1.13...v0.1.14 ✓ 6350 bytes
- golang.org/x/time 0.12.0→0.14.0: compare v0.12.0...v0.14.0 ✓ 606 bytes
- context: 76092 bytes
- #1054 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- urfave/cli v3.10.0..v3.10.1 (PR body): compare v3.10.0...v3.10.1 ✓ 17319 bytes
- urfave/cli v3.9.1..v3.10.0 (PR body): compare v3.9.1...v3.10.0 ✓ 40000 bytes
- context: 100504 bytes
- #1056 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/libp2p/go-libp2p-pubsub 0.16.0→0.17.0: compare v0.16.0...v0.17.0 ✓ 40000 bytes
- context: 45662 bytes
- #1057 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- actions/setup-go v7.0.0..v7.0.0 (PR body): compare v7.0.0...v7.0.0 failed/empty (no upstream diff)
- actions/setup-go v6..v7.0.0 (PR body): compare v6...v7.0.0 ✓ 40000 bytes
- actions/setup-go v6.5.0..v7.0.0 (PR body): compare v6.5.0...v7.0.0 ✓ 40000 bytes
- context: 84157 bytes
- #1058 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/labstack/echo/v5 5.3.0→5.3.1: compare v5.3.0...v5.3.1 ✓ 35382 bytes
- golang.org/x/crypto 0.53.0→0.54.0: compare v0.53.0...v0.54.0 ✓ 40000 bytes
- context: 107813 bytes
- #1059 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/libp2p/go-libp2p-kad-dht 0.41.0→0.42.1: compare v0.41.0...v0.42.1 ✓ 40000 bytes
- github.com/ipfs/boxo 0.39.0→0.41.0: compare v0.39.0...v0.41.0 ✓ 40000 bytes
- context: 99296 bytes
- #1060 ⚠️ needs_human_verification — review endpoint returned HTTP 500
review trace
- github.com/labstack/echo/v5 5.3.0→5.3.1: compare v5.3.0...v5.3.1 ✓ 35382 bytes
- golang.org/x/crypto 0.53.0→0.54.0: compare v0.53.0...v0.54.0 ✓ 40000 bytes
- context: 86707 bytes
- #1061 ✅ good — This change is a routine dependency update, specifically updating the digest of `go-libp2p-pubsub`. There are no apparent security risks introduced by this version bump, and it aligns with standard dependency maintenance practices.
↳ This PR updates the dependency `github.com/mudler/go-libp2p-pubsub` by changing its digest from `205ded1` to `2a31b5e`. This is a routine maintenance update to ensure the project uses the latest version of this library.
review trace
- no upstream comparisons available (no go.mod bumps or compare links in the PR body)
- context: 2511 bytes
🤖 Bot PR ledger
No bot PRs yet.
🌊 Waterfall fronts shared root causes
None.
📋 This run
- Scanned 25 repos
- Findings 0 — 0 critical / 0 high / 0 medium / 0 low / 0 unknown
- Remediation 0 open · 0 superseded · 0 merged · 0 need-human