Skip to content

Getting critical vulnerability for "github.com/grafana/grafana-plugin-sdk-go" package #41

@vw-satyam-gopale

Description

@vw-satyam-gopale

Hi,

We are using Grafana as fronend in our project and we have installed "golioth-websocket-datasource" plugin with "1.0.2" latest version. But when we deploy grafana with required plugin on AWS environemnt, we start getting critical vulnerability to update "grafana-plugin-sdk-go" package even we are using latest one. Please refer below vulnerability detail.

Affected packages
Name: github.com/grafana/grafana-plugin-sdk-go
Installed version / Fixed version: 0:v0.142.0 / 0.250.0
Package manager: GOBINARY
File paths:
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_linux_arm64
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_darwin_amd64
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_windows_amd64.exe
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_linux_amd64
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_linux_arm
var/lib/grafana/plugins/golioth-websocket-datasource/gpx_websocket_darwin_arm64

Could you please update "grafana-plugin-sdk-go" versions to latest?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions