fix(nvca): bump grpc to remediate container OSS vuln SLA failures on v3.2 - #2118
Merged
apartha-nv merged 1 commit intoSep 28, 2026
Conversation
…v3.2
The nvca and nvca-operator 3.2.23 images failed the nSpect LaunchAPI
container-oss-vulns-out-of-sla gate, blocking promotion to the public
NGC catalog. govulncheck identified google.golang.org/grpc@v1.79.3 as
the only code-reachable vulnerable dependency on this branch:
- GO-2026-6348: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame
Fragmentation
- GO-2026-6061: xDS RBAC authorization engine and HTTP/2 transport
server vulnerabilities
Bumped to google.golang.org/grpc@v1.83.1 (fixes both). govulncheck now
reports 0 code-reachable vulnerabilities for cmd/nvca.
vendor/ regenerated via `go mod vendor`; BUILD.bazel files hand-updated
(this nested/vendored module isn't wired into the monorepo's
go.work.bazel, so `bazel run //:gazelle` walks the whole repo instead
of scoping to nvca). Verified with:
bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator}
which now succeeds cleanly (489 actions, no missing-dependency errors).
Closes NO-REF
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Comment |
vrv3814
approved these changes
Sep 28, 2026
apartha-nv
merged commit Sep 28, 2026
de669a2
into
release-src/compute-plane-services/nvca/v3.2
12 checks passed
This was referenced Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
nvcaandnvca-operator3.2.23images failed the nSpect LaunchAPIcontainer-oss-vulns-out-of-slagate (9 out-of-SLA vulns each), blocking promotion to the public NGC catalog.govulncheckidentifiedgoogle.golang.org/grpc@v1.79.3as the only code-reachable vulnerable dependency on this branch:GO-2026-6348: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame FragmentationGO-2026-6061: xDS RBAC authorization engine and HTTP/2 transport server vulnerabilitiesgoogle.golang.org/grpc@v1.83.1(fixes both).govulnchecknow reports 0 code-reachable vulnerabilities forcmd/nvca.Notes for reviewers
vendor/regenerated viago mod vendor;BUILD.bazelfiles were hand-updated since this nested/vendored module isn't wired into the monorepo'sgo.work.bazel—bazel run //:gazellewalks the entire repo instead of scoping tonvcain this environment. Worth double-checking with a proper gazelle run in CI/a correctly configured dev environment.bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator}succeeds cleanly (489 actions, no missing-dependency errors).Test plan
go buildsucceeds fornvca,nvca-operator,cluster-validatorbazel buildsucceeds for the same three targetsgovulncheck ./cmd/nvca/...reports 0 vulnerabilitiesgofmtclean (no new formatting issues)v3.2.25) once merged, then update thengc-publishing-configsMR to reference it instead of3.2.23Summary by CodeRabbit