canonical / canonical/microceph

[vuln-scan] govulncheck found called-path vulnerabilities

Open
#806 55 comments 0 reactions 0 assignees View on GitHub
security
Dominant language
Go
Stars
396
Forks
74
Avg merge
2d 20h
Merged PRs (30d)
7

Description

Daily govulncheck scan of `microceph/` on `main` (commit `b8f87722eeb291dd0f8fc6ae7ea38d963e8f49e5`).

Workflow run: https://github.com/canonical/microceph/actions/runs/29898358972

## Called-path vulnerabilities: 1

```
GO-2026-5970
```

See the workflow run logs for full call-stack traces.

Contributor guide

Open the contributing guide

Research direction

Start with the linked workflow run logs for the full call-stack trace, then trace the GO-2026-5970 called path under microceph/ at commit b8f87722eeb291dd0f8fc6ae7ea38d963e8f49e5. Determine the appropriate remediation and verify that govulncheck no longer reports the vulnerability.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.