-
Notifications
You must be signed in to change notification settings - Fork 16
Description
Hi,
We are using Grafana as fronend in our project and we have installed "golioth-websocket-datasource" plugin with "1.0.2" latest version. But when we deploy grafana with required plugin on AWS environemnt, we start getting critical vulnerability to update "grafana-plugin-sdk-go" package even we are using latest one. Please refer below vulnerability detail.
Affected packages
Name: github.com/grafana/grafana-plugin-sdk-go
Installed version / Fixed version: 0:v0.142.0 / 0.250.0
Package manager: GOBINARY
File paths:
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_linux_arm64
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_darwin_amd64
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_windows_amd64.exe
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_linux_amd64
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_linux_arm
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_darwin_arm64
Could you please update "grafana-plugin-sdk-go" versions to latest?