Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Backport candidate: CVE-2025-13888 fix not present on v1.13 branch

クローズ
#1,139 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
52/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
静か
技術スタック
go
領域
release, security

調査の方向性

まず、v1.13 ブランチがまだサポートされているか確認してください。サポートされている場合は、v1.13 の controllers/argocd_metrics_controller.go を調査し、PR #897 のコミット bc6ac3e0 と比較してください。完了の条件は、namespace-isolation fix が v1.13 に存在すること、または同等のバックポートが提供されていることです。ブランチが EOL の場合は、代わりにそのステータスを記録してください。

索引モデルが issue の本文から書いたものです。

説明

Hi maintainers,

While auditing supported branches for CVE backports, I noticed that the fix for CVE-2025-13888 (PR #897, commit bc6ac3e0, "fix CVE namespace-isolation break") does not appear to be present on the v1.13 branch.

What I checked

  • The v1.13 branch HEAD does not contain the new symbols introduced by the fix:
    • userDefinedMonitoringLabel constant — not present in controllers/argocd_metrics_controller.go on v1.13
    • openshift.io/user-monitoring label literal — not present
    • strings.HasPrefix(namespace.Name, "openshift-") guard — not present
  • The pre-fix code path (namespace.Labels[clusterMonitoringLabel] = "true" unconditional) is still present.
  • git compare v1.13...bc6ac3e0 reports the branch is 16 commits behind the fix commit and the fix is not in the merged set.

Why this matters

Without the openshift- prefix guard, the operator may add the cluster-monitoring label to namespaces it shouldn't, which is the namespace-isolation issue described in the advisory. If v1.13 is still a supported maintenance branch, a cherry-pick of bc6ac3e0 (or an equivalent fix) would close that gap.

If v1.13 is no longer supported / EOL, please feel free to close — happy to know either way.

Thanks for your work on this project.

— @vulgraph

主要言語
Go
スター
188
フォーク
362
平均マージ
5日 4時間
マージ済み PR(30日)
27

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

redhat-developer/gitops-operator のほかの issue

redhat-developer/gitops-operator の issue をすべて見る

似ている issue

Go の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。