Skip to content

update the go version and dependencies to fix the CVE's #90

update the go version and dependencies to fix the CVE's

update the go version and dependencies to fix the CVE's #90

Triggered via push February 27, 2026 00:01
Status Failure
Total duration 1m 11s
Artifacts

deps.yml

on: push
dependency-review
5s
dependency-review
govulncheck
1m 8s
govulncheck
Fit to window
Zoom out
Zoom in

Annotations

11 errors and 2 warnings
dependency-review
Dependency review is not supported on this repository. Please ensure that Dependency graph is enabled, see https://github.com/kmala/cloud-provider-aws/settings/security_analysis
govulncheck
providers.IsAWSErrorInstanceNotFound calls warnings.List.Error, which eventually calls trace.nonRecordingSpan.AddEvent
govulncheck
providers.recordAWSMetric calls metrics.HistogramVec.With, which eventually calls trace.logDropped[go.opentelemetry.io/otel/sdk/trace.Link]
govulncheck
providers.recordAWSMetric calls metrics.HistogramVec.With, which eventually calls trace.logDropped[go.opentelemetry.io/otel/sdk/trace.Event]
govulncheck
aws.init calls options.init, which eventually calls trace.init
govulncheck
providers.recordAWSMetric calls metrics.HistogramVec.With, which eventually calls trace.init
govulncheck
tagging.init calls app.init, which eventually calls trace.TracerProvider.Tracer
govulncheck
aws.init calls options.init, which eventually calls sdk.init
govulncheck
aws.init calls options.init, which eventually calls resource.init
govulncheck
aws.init calls options.init, which eventually calls instrumentation.init
govulncheck
aws.init calls options.init, which eventually calls env.init
govulncheck
Failed to restore: Cache service responded with 400
govulncheck
Both go-version and go-version-file inputs are specified, only go-version will be used