Add support for jsonl in bnd push - #178
Security Analysis Passed
No security issues found
Details
Kusari Analysis Results:
✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.
Both analyses support proceeding. Dependency analysis found no vulnerabilities introduced by this PR - the only CVE data present (GHSA-2v4p-qf9q-27wj, GHSA-qc2q-p7wx-3px3, GHSA-vp52-pcj8-j9qc on google.golang.org/grpc) reflects issues REMEDIATED by the update from 1.83.0 to 1.83.2, not new risk. No blocked, deprecated, or EOL packages were found. Some transitive dependencies are flagged 'isRisky' due to low scorecard maintenance scores, and several MPL-2.0 weak copyleft licensed transitive packages (e.g. hashicorp go-sockaddr, errwrap, hcl, vault/api, go-secure-stdlib/parseutil, go-secure-stdlib/strutil, go-rootcerts, go-multierror) are present via sigstore/vault dependency chains - these are worth tracking for license compliance but are indirect, pre-existing transitive deps rather than direct risky additions, and are not blocking. Code analysis found no code issues, exposed secrets, or workflow issues. Combined, there are no critical or actionable security concerns; this PR is safe to merge, with a recommendation to confirm MPL-2.0 license acceptability for your distribution model as a follow-up action item.
Note
View full detailed analysis result for more information on the output and the checks that were run.
@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 03d400b, performed at: 2026-09-11T05:39:33Z