Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Descriptions
I have updated go modules to eliminate vulnerable modules (For some modules, since the signature of functions are changed, I modified the according modifications on the code).
Now the dependant alerts reduced to two alerts (https://github.com/yana1205/compliance-to-policy/security/dependabot).
require github.com/docker/docker v24.0.9
github.com/hashicorp/go-retryablehttp v0.7.5
These two modules comes from Kyverno module (v1.12.5). The latest commits on Kyverno release-1.12 branch (go.mod) contain these vulnerable modules. I will wait for the next version of Kyverno (v1.12.6) to be released.
Verification
Test passed.