build(deps): Bump github.com/google/go-containerregistry from 0.20.6 to 0.21.9 - #792
Security Analysis Passed
No security issues found
Details
Kusari Analysis Results:
✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.
Both dependency and code analyses recommend proceeding with no critical concerns. The dependency update (github.com/google/go-containerregistry v0.20.6 to v0.21.9) is a net security improvement: the transitive update of github.com/klauspost/compress from v1.18.0 to v1.19.1 remediates GO-2026-5841 (OOB read in s2), which was present in the prior version. Three indirect dependencies (github.com/docker/distribution, github.com/vbatts/tar-split, github.com/containerd/stargz-snapshotter/estargz) were cleanly removed with no associated risk. The newly introduced transitive dependency gotest.tools/v3 v3.5.2 has no known vulnerabilities and is testing-scoped, so maintenance scorecard concerns do not warrant blocking. All licenses remain permissive (Apache-2.0, BSD-3-Clause, MIT). The code analysis detected no security issues, exposed secrets, or workflow concerns. The combined risk profile is favorable and this PR improves the overall security posture.
Note
View full detailed analysis result for more information on the output and the checks that were run.
@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 0ffb260, performed at: 2026-08-10T19:15:16Z