cve: the cadvisor decision cited a commit that never touched it

I wrote that v0.55.1 was waiting in 516641b. It is not — cadvisor is not in this
compose file at all; it runs in the portainer stack next door, so nothing here
sets its version. The finding stands and the measurement stands, but the reason
attached to it was false, and a decision is only worth its reason.

Same shape as the portainer agent: measured, outside our deployment path, and
therefore dated with the others rather than with this week's rollout.
This commit is contained in:
Thore Cimbal
2026-08-21 12:00:00 +00:00
parent 1ce4b55b75
commit 2c0caacfb0
+2 -2
View File
@@ -33,8 +33,8 @@
{
"ziel": "gcr.io/cadvisor/cadvisor:v0.49.1",
"art": "geplant",
"grund": "v0.55.1 liegt im Repo (516641b), gemessen 5 CRITICAL -> 4. Wirkt mit dem Ausrollen auf dem Betriebs-Host.",
"pruefen_am": "2026-08-28",
"grund": "Laeuft im Portainer-Stack 'thread-net-git', NICHT aus diesem Repo - die Fassung wird hier gar nicht gesetzt. GEMESSEN: v0.55.1 traegt 4 statt 5 CRITICAL, also ein schwacher Gewinn. Die Aktualisierung liegt wie beim portainer-agent bei sorb auf dem Betriebs-Host.",
"pruefen_am": "2026-09-21",
"cves": [
"CVE-2024-24790",
"CVE-2024-37371",