Repository: StackVista/stackstate-process-agent
Scan state
Run 30536723587 reports 0 Critical, 12 High, 44 Medium and 4 Low occurrences in stackstate-k8s-process-agent:b9f7fe00.
Required fixes
Refresh the image so it contains at least:
- GLib 2.78.6-150600.4.38.1
- wget 1.24.5-150700.3.6.1
- libssh 0.9.8-150600.11.15.1
- libudev1 254.27-150600.4.71.2
- libgcrypt 1.11.0-150700.5.10.1
- gpg2 2.4.4-150600.3.18.1
The image also still embeds go.opentelemetry.io/otel v1.43.0 for CVE-2026-41178. Align all OTel modules to a fixed coherent release, using v1.44.0 or newer rather than mixing module versions.
Keep UNKNOWN GO-2026-5841 visible until klauspost/compress is upgraded to v1.18.7 or the finding receives a reviewed disposition.
Acceptance criteria
- Source dependencies and BCI packages are updated, tested and published as an immutable multi-architecture image.
- go version -m confirms the corrected OTel dependency graph in the built binary.
- A process-agent startup/smoke test passes.
- VEX-aware Trivy and Grype scans have no unapproved scored findings and Trivy secret scanning is clean.
- The replacement image reaches the development agent chart.
STAC-25486
Repository: StackVista/stackstate-process-agent
Scan state
Run 30536723587 reports 0 Critical, 12 High, 44 Medium and 4 Low occurrences in stackstate-k8s-process-agent:b9f7fe00.
Required fixes
Refresh the image so it contains at least:
The image also still embeds go.opentelemetry.io/otel v1.43.0 for CVE-2026-41178. Align all OTel modules to a fixed coherent release, using v1.44.0 or newer rather than mixing module versions.
Keep UNKNOWN GO-2026-5841 visible until klauspost/compress is upgraded to v1.18.7 or the finding receives a reviewed disposition.
Acceptance criteria