Bug 2530053 (CVE-2026-87052)

Summary: CVE-2026-87052 operator-foundry: operator-foundry: No automated dependency-update or vulnerability-scanning configuration
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: gbenhaim, niyer, twaugh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in operator-foundry. The absence of automated dependency-update and vulnerability-scanning configurations in the repository increases the risk of undetected security vulnerabilities. This lack of automated security checks could potentially lead to the inclusion of known vulnerable components, which might then be exploited by an attacker if those underlying vulnerabilities are present and exploitable.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-08 19:05:46 UTC
## No automated dependency-update or vulnerability-scanning configuration

**Component:** operator-foundry

The repository has no Dependabot/Renovate configuration for Go modules or GitHub Actions, and no automated Go vulnerability scanning step in CI.

### Remediation
Add `.github/dependabot.yml` with `gomod` and `github-actions` ecosystems (or enable Konflux MintMaker/Renovate). Add a `govulncheck ./...` step to `.github/workflows/ci.yaml`.

---
*Source: Ex-Wing/Glasswing Konflux CI security assessment (Mythos), finding FIND-004*