Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Backport candidate: CVE-2025-13888 fix not present on v1.13 branch

Offen
#1,139 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Anfängerfreundlichkeit
52/100
Issue-Typ
Bug
Klarheit
Größtenteils klar
Aktivitätsstatus
Ruhig
Tech-Stack
go
Bereich
release, security

Rechercherichtung

Prüfe zuerst, ob der v1.13-Branch noch unterstützt wird. Falls ja, untersuche controllers/argocd_metrics_controller.go in v1.13 und vergleiche ihn mit Commit bc6ac3e0 aus PR #897; abgeschlossen bedeutet, dass der namespace-isolation-Fix in v1.13 vorhanden ist oder ein gleichwertiger Backport bereitgestellt wird. Falls der Branch EOL ist, dokumentiere stattdessen diesen Status.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Hi maintainers,

While auditing supported branches for CVE backports, I noticed that the fix for CVE-2025-13888 (PR #897, commit bc6ac3e0, "fix CVE namespace-isolation break") does not appear to be present on the v1.13 branch.

What I checked

  • The v1.13 branch HEAD does not contain the new symbols introduced by the fix:
    • userDefinedMonitoringLabel constant — not present in controllers/argocd_metrics_controller.go on v1.13
    • openshift.io/user-monitoring label literal — not present
    • strings.HasPrefix(namespace.Name, "openshift-") guard — not present
  • The pre-fix code path (namespace.Labels[clusterMonitoringLabel] = "true" unconditional) is still present.
  • git compare v1.13...bc6ac3e0 reports the branch is 16 commits behind the fix commit and the fix is not in the merged set.

Why this matters

Without the openshift- prefix guard, the operator may add the cluster-monitoring label to namespaces it shouldn't, which is the namespace-isolation issue described in the advisory. If v1.13 is still a supported maintenance branch, a cherry-pick of bc6ac3e0 (or an equivalent fix) would close that gap.

If v1.13 is no longer supported / EOL, please feel free to close — happy to know either way.

Thanks for your work on this project.

— @vulgraph

Vorherrschende Sprache
Go
Sterne
188
Forks
359
Ø Merge
4 T. 6 Std.
Gemergte PRs (30 T.)
27

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus redhat-developer/gitops-operator

Alle Issues in redhat-developer/gitops-operator

Ähnliche Issues

Weitere Issues zu Go

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.