chore(deps): upgrade go-containerregistry v0.20.8 - #789
Security Analysis Passed
No security issues found
Details
Kusari Analysis Results:
✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.
Both independent analyses return clean results with no security concerns. The dependency analysis confirms that all 6 dependency changes (bumping github.com/google/go-containerregistry from v0.20.6 to v0.20.8 and its transitive updates) carry zero advisories, zero known vulnerabilities, no deprecated or end-of-life packages, and no blocked packages. All licenses are permissive (Apache-2.0, BSD-3-Clause, MIT). The code analysis scanned 60 files and found zero code issues, zero exposed secrets, and zero workflow issues. The changes are limited to vendor dependency updates (compression, container registry, and OAuth2 libraries) alongside go.mod and go.sum updates. There are no combined risk factors that would elevate the overall risk profile beyond what each individual analysis found. This PR is safe to merge.
Note
View full detailed analysis result for more information on the output and the checks that were run.
@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: d5f364b, performed at: 2026-06-10T05:45:32Z