Skip to content

3.1.36 - CVE fixes#1631

Open
suyadav1 wants to merge 13 commits intoci_prodfrom
suyadav/3.1.36-cves
Open

3.1.36 - CVE fixes#1631
suyadav1 wants to merge 13 commits intoci_prodfrom
suyadav/3.1.36-cves

Conversation

@suyadav1
Copy link
Copy Markdown
Contributor

@suyadav1 suyadav1 commented Apr 2, 2026

  • Added 2 new skills for enhancing productivity: backdoor-testing for testing changes on a branch, upgrade-telegraf for raising PR for dalec telegraf upgrade.

  • Fixed CVEs showing up due to old go version, telegraf.

  • Updated the ama-logs Helm template to inject the pod's metadata.uid as the AMCS_CLIENT_INSTALL_ID_OVERRIDE environment variable for tracking AMCS calls: https://dev.azure.com/msazure/InfrastructureInsights/_workitems/edit/36350426

Test results with the skill:

image

@suyadav1 suyadav1 requested a review from a team as a code owner April 2, 2026 21:59
Copy link
Copy Markdown
Contributor

@zanejohnson-azure zanejohnson-azure left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

left comments

@suyadav1
Copy link
Copy Markdown
Contributor Author

suyadav1 commented Apr 6, 2026

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

wanlonghenry
wanlonghenry previously approved these changes Apr 8, 2026
@suyadav1
Copy link
Copy Markdown
Contributor Author

suyadav1 commented Apr 8, 2026

/azp run

@suyadav1 suyadav1 enabled auto-merge (squash) April 8, 2026 20:35
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@suyadav1
Copy link
Copy Markdown
Contributor Author

suyadav1 commented Apr 8, 2026

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

…S vulnerability

The Trivy scan fails on opt/telegraf due to GHSA-xmrv-pmrh-hhx2 (MEDIUM) in
github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.64.2. The fix (v1.65.0)
is not yet available in the telegraf package.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@suyadav1
Copy link
Copy Markdown
Contributor Author

suyadav1 commented Apr 9, 2026

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

…erability

Trivy scan fails on opt/telegraf due to CVE-2026-39883 (HIGH) in
go.opentelemetry.io/otel/sdk v1.42.0. The fix (v1.43.0) is not yet
available in the telegraf package.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@suyadav1
Copy link
Copy Markdown
Contributor Author

suyadav1 commented Apr 9, 2026

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants