Skip to content

fix(nvca): bump grpc to remediate container OSS vuln SLA failures on v3.2 - #2118

Merged
apartha-nv merged 1 commit into
release-src/compute-plane-services/nvca/v3.2from
fix/nvca-v3.2-container-oss-vulns-sla
Sep 28, 2026
Merged

apartha-nv merged 1 commit into
release-src/compute-plane-services/nvca/v3.2from
fix/nvca-v3.2-container-oss-vulns-sla

Conversation

@apartha-nv

@apartha-nv apartha-nv commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • The nvca and nvca-operator 3.2.23 images failed the nSpect LaunchAPI container-oss-vulns-out-of-sla gate (9 out-of-SLA vulns each), blocking promotion to the public NGC catalog.
  • govulncheck identified google.golang.org/grpc@v1.79.3 as the only code-reachable vulnerable dependency on this branch:
    • GO-2026-6348: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
    • GO-2026-6061: xDS RBAC authorization engine and HTTP/2 transport server vulnerabilities
  • Bumped to google.golang.org/grpc@v1.83.1 (fixes both). govulncheck now reports 0 code-reachable vulnerabilities for cmd/nvca.

Notes for reviewers

  • vendor/ regenerated via go mod vendor; BUILD.bazel files were hand-updated since this nested/vendored module isn't wired into the monorepo's go.work.bazel — bazel run //:gazelle walks the entire repo instead of scoping to nvca in this environment. Worth double-checking with a proper gazelle run in CI/a correctly configured dev environment.
  • Verified locally: bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator} succeeds cleanly (489 actions, no missing-dependency errors).

Test plan

  • go build succeeds for nvca, nvca-operator, cluster-validator
  • bazel build succeeds for the same three targets
  • govulncheck ./cmd/nvca/... reports 0 vulnerabilities
  • gofmt clean (no new formatting issues)
  • Cut a new patch tag (e.g. v3.2.25) once merged, then update the ngc-publishing-configs MR to reference it instead of 3.2.23

Summary by CodeRabbit

  • Chores
    • Updated internal dependencies. No user-facing changes are noted.

…v3.2

The nvca and nvca-operator 3.2.23 images failed the nSpect LaunchAPI
container-oss-vulns-out-of-sla gate, blocking promotion to the public
NGC catalog. govulncheck identified google.golang.org/grpc@v1.79.3 as
the only code-reachable vulnerable dependency on this branch:

- GO-2026-6348: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame
  Fragmentation
- GO-2026-6061: xDS RBAC authorization engine and HTTP/2 transport
  server vulnerabilities

Bumped to google.golang.org/grpc@v1.83.1 (fixes both). govulncheck now
reports 0 code-reachable vulnerabilities for cmd/nvca.

vendor/ regenerated via `go mod vendor`; BUILD.bazel files hand-updated
(this nested/vendored module isn't wired into the monorepo's
go.work.bazel, so `bazel run //:gazelle` walks the whole repo instead
of scoping to nvca). Verified with:

  bazel build //src/compute-plane-services/nvca/cmd/{nvca,nvca-operator,cluster-validator}

which now succeeds cleanly (489 actions, no missing-dependency errors).

Closes NO-REF
@apartha-nv
apartha-nv requested a review from a team as a code owner September 28, 2026 08:17
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title follows Conventional Commits with the required scoped fix type. It accurately describes the gRPC dependency update and its vulnerability-remediation purpose.

Comment @coderabbitai help to get the list of available commands.

@apartha-nv
apartha-nv merged commit de669a2 into release-src/compute-plane-services/nvca/v3.2 Sep 28, 2026
12 checks passed
@apartha-nv
apartha-nv deleted the fix/nvca-v3.2-container-oss-vulns-sla branch September 28, 2026 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants