Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PB-6455 :: Metrics Inspect Response Updated #238

Merged
merged 1 commit into from
Apr 2, 2024
Merged

PB-6455 :: Metrics Inspect Response Updated #238

merged 1 commit into from
Apr 2, 2024

Conversation

vikasit12
Copy link
Collaborator

  • last_sync_time added to MetricsInspectResponse
  • total_namespaces added to MetricsInspectResponseStats

What this PR does / why we need it:

Which issue(s) this PR fixes (optional)
Closes #237

Special notes for your reviewer:

- last_sync_time added to MetricsInspectResponse
- total_namespaces added to MetricsInspectResponseStats

Signed-off-by: Vikas Kumar <vikas_it@hotmail.com>
Copy link

github-actions bot commented Apr 2, 2024

OSS Scan Results:

Title Severity Package Name CVEs Fix version Introduced
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/rest@0.25.1', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/rest@0.25.1', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'google.golang.org/grpc@1.57.0', 'google.golang.org/grpc/internal/transport@1.57.0', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'google.golang.org/grpc@1.57.0', 'google.golang.org/grpc/internal/transport@1.57.0', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/tools/clientcmd@0.25.1', 'k8s.io/client-go/tools/auth@0.25.1', 'k8s.io/client-go/rest@0.25.1', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/tools/clientcmd@0.25.1', 'k8s.io/client-go/tools/auth@0.25.1', 'k8s.io/client-go/rest@0.25.1', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/rest@0.25.1', 'k8s.io/client-go/transport@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/rest@0.25.1', 'k8s.io/client-go/transport@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/cli-runtime/pkg/printers@0.25.1', 'k8s.io/apimachinery/pkg/watch@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/cli-runtime/pkg/printers@0.25.1', 'k8s.io/apimachinery/pkg/watch@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/portworx/sched-ops/k8s/core@#2e0ef25efadd', 'k8s.io/client-go/tools/remotecommand@0.25.1', 'k8s.io/client-go/transport/spdy@0.25.1', 'k8s.io/client-go/rest@0.25.1', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/portworx/sched-ops/k8s/core@#2e0ef25efadd', 'k8s.io/client-go/tools/remotecommand@0.25.1', 'k8s.io/client-go/transport/spdy@0.25.1', 'k8s.io/client-go/rest@0.25.1', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/portworx/sched-ops/k8s/core@#2e0ef25efadd', 'k8s.io/client-go/tools/remotecommand@0.25.1', 'k8s.io/client-go/transport/spdy@0.25.1', 'k8s.io/client-go/rest@0.25.1', 'k8s.io/client-go/transport@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/portworx/sched-ops/k8s/core@#2e0ef25efadd', 'k8s.io/client-go/tools/remotecommand@0.25.1', 'k8s.io/client-go/transport/spdy@0.25.1', 'k8s.io/client-go/rest@0.25.1', 'k8s.io/client-go/transport@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/tools/clientcmd/api/latest@0.25.1', 'k8s.io/apimachinery/pkg/runtime/serializer/versioning@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1/unstructured@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1@0.25.1', 'k8s.io/apimachinery/pkg/watch@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/tools/clientcmd/api/latest@0.25.1', 'k8s.io/apimachinery/pkg/runtime/serializer/versioning@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1/unstructured@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1@0.25.1', 'k8s.io/apimachinery/pkg/watch@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'sigs.k8s.io/aws-iam-authenticator/pkg/token@0.5.5', 'k8s.io/client-go/pkg/apis/clientauthentication/v1beta1@0.25.1', 'k8s.io/client-go/pkg/apis/clientauthentication@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1@0.25.1', 'k8s.io/apimachinery/pkg/watch@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'sigs.k8s.io/aws-iam-authenticator/pkg/token@0.5.5', 'k8s.io/client-go/pkg/apis/clientauthentication/v1beta1@0.25.1', 'k8s.io/client-go/pkg/apis/clientauthentication@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1@0.25.1', 'k8s.io/apimachinery/pkg/watch@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high golang.org/x/net/http2 ['CVE-2023-44487'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/tools/clientcmd@0.25.1', 'k8s.io/client-go/tools/clientcmd/api/latest@0.25.1', 'k8s.io/apimachinery/pkg/runtime/serializer/versioning@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1/unstructured@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1@0.25.1', 'k8s.io/apimachinery/pkg/watch@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Allocation of Resources Without Limits or Throttling medium golang.org/x/net/http2 ['CVE-2023-39325'] ['0.17.0'] ['github.com/portworx/px-backup-api@0.0.0', 'k8s.io/client-go/tools/clientcmd@0.25.1', 'k8s.io/client-go/tools/clientcmd/api/latest@0.25.1', 'k8s.io/apimachinery/pkg/runtime/serializer/versioning@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1/unstructured@0.25.1', 'k8s.io/apimachinery/pkg/apis/meta/v1@0.25.1', 'k8s.io/apimachinery/pkg/watch@0.25.1', 'k8s.io/apimachinery/pkg/util/net@0.25.1', 'golang.org/x/net/http2@0.10.0']
Denial of Service (DoS) high google.golang.org/grpc ['CVE-2023-44487'] ['1.56.3', '1.57.1', '1.58.3'] ['github.com/portworx/px-backup-api@0.0.0', 'google.golang.org/grpc@1.57.0']
Stack-based Buffer Overflow medium google.golang.org/protobuf/encoding/protojson [] ['1.32.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/grpc-ecosystem/grpc-gateway/runtime@1.16.0', 'github.com/golang/protobuf/jsonpb@1.5.3', 'google.golang.org/protobuf/encoding/protojson@1.31.0']
Infinite loop medium google.golang.org/protobuf/encoding/protojson ['CVE-2024-24786'] ['1.33.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/grpc-ecosystem/grpc-gateway/runtime@1.16.0', 'github.com/golang/protobuf/jsonpb@1.5.3', 'google.golang.org/protobuf/encoding/protojson@1.31.0']
Stack-based Buffer Overflow medium google.golang.org/protobuf/encoding/protojson [] ['1.32.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-openapiv2/options@2.6.0', 'google.golang.org/protobuf/types/known/structpb@1.31.0', 'google.golang.org/protobuf/encoding/protojson@1.31.0']
Infinite loop medium google.golang.org/protobuf/encoding/protojson ['CVE-2024-24786'] ['1.33.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-openapiv2/options@2.6.0', 'google.golang.org/protobuf/types/known/structpb@1.31.0', 'google.golang.org/protobuf/encoding/protojson@1.31.0']
Stack-based Buffer Overflow medium google.golang.org/protobuf/encoding/protojson [] ['1.32.0'] ['github.com/portworx/px-backup-api@0.0.0', 'google.golang.org/grpc@1.57.0', 'google.golang.org/grpc/internal/transport@1.57.0', 'google.golang.org/grpc/internal/pretty@1.57.0', 'google.golang.org/protobuf/encoding/protojson@1.31.0']
Infinite loop medium google.golang.org/protobuf/encoding/protojson ['CVE-2024-24786'] ['1.33.0'] ['github.com/portworx/px-backup-api@0.0.0', 'google.golang.org/grpc@1.57.0', 'google.golang.org/grpc/internal/transport@1.57.0', 'google.golang.org/grpc/internal/pretty@1.57.0', 'google.golang.org/protobuf/encoding/protojson@1.31.0']
Stack-based Buffer Overflow medium google.golang.org/protobuf/encoding/protojson [] ['1.32.0'] ['github.com/portworx/px-backup-api@0.0.0', 'google.golang.org/grpc@1.57.0', 'google.golang.org/grpc/internal/transport@1.57.0', 'google.golang.org/grpc/internal/pretty@1.57.0', 'github.com/golang/protobuf/jsonpb@1.5.3', 'google.golang.org/protobuf/encoding/protojson@1.31.0']
Infinite loop medium google.golang.org/protobuf/encoding/protojson ['CVE-2024-24786'] ['1.33.0'] ['github.com/portworx/px-backup-api@0.0.0', 'google.golang.org/grpc@1.57.0', 'google.golang.org/grpc/internal/transport@1.57.0', 'google.golang.org/grpc/internal/pretty@1.57.0', 'github.com/golang/protobuf/jsonpb@1.5.3', 'google.golang.org/protobuf/encoding/protojson@1.31.0']
Infinite loop medium google.golang.org/protobuf/internal/encoding/json ['CVE-2024-24786'] ['1.33.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/grpc-ecosystem/grpc-gateway/runtime@1.16.0', 'github.com/golang/protobuf/jsonpb@1.5.3', 'google.golang.org/protobuf/encoding/protojson@1.31.0', 'google.golang.org/protobuf/internal/encoding/json@1.31.0']
Infinite loop medium google.golang.org/protobuf/internal/encoding/json ['CVE-2024-24786'] ['1.33.0'] ['github.com/portworx/px-backup-api@0.0.0', 'github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-openapiv2/options@2.6.0', 'google.golang.org/protobuf/types/known/structpb@1.31.0', 'google.golang.org/protobuf/encoding/protojson@1.31.0', 'google.golang.org/protobuf/internal/encoding/json@1.31.0']
Infinite loop medium google.golang.org/protobuf/internal/encoding/json ['CVE-2024-24786'] ['1.33.0'] ['github.com/portworx/px-backup-api@0.0.0', 'google.golang.org/grpc@1.57.0', 'google.golang.org/grpc/internal/transport@1.57.0', 'google.golang.org/grpc/internal/pretty@1.57.0', 'google.golang.org/protobuf/encoding/protojson@1.31.0', 'google.golang.org/protobuf/internal/encoding/json@1.31.0']
Improper Input Validation high sigs.k8s.io/aws-iam-authenticator/pkg/token ['CVE-2022-2385'] ['0.5.9'] ['github.com/portworx/px-backup-api@0.0.0', 'sigs.k8s.io/aws-iam-authenticator/pkg/token@0.5.5']

Total issues: 33

Copy link

github-actions bot commented Apr 2, 2024

License Evaluation Results:

Title Package Name Package Version Severity License Info Introduced Dependency Type

Total License Issues: 0

@vikasit12 vikasit12 merged commit b83ec02 into master Apr 2, 2024
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants