Every finding cites a file and a line and says what to change. Clean files come back short rather than padded out.
bugpkg/kubelet/stats/cri_stats_provider.go:361
A nil sandbox stat panics the kubelet
ListPodCPUAndMemoryStats drops the nil check that its sibling loop does make at line 249, so one nil element in a CRI response takes the stats API down.
- podSandbox, found := podSandboxMap[criSandboxStat.Attributes.Id]
+ if criSandboxStat == nil || criSandboxStat.Attributes == nil { continue }
securitypkg/api/annotations.go:378
Any signed-in user can panic the mass-delete handler
MassDeleteAnnotations dereferences DashboardUID with no nil check, and an org-scoped annotation has none. The panic happens before the permission check runs.
- dashboardUID = *annotation.DashboardUID
+ if uid := annotation.DashboardUID; uid != nil { dashboardUID = *uid }
performancedaemon/command/daemon.go:1030
Sixteen seconds of sleep per host at daemon start
Both deprecation-warning sleeps sit inside the loop over cfg.Hosts, so three insecure TCP hosts stall startup for 48 seconds before anything listens.
- time.Sleep(15 * time.Second) // inside the host loop
+ time.Sleep(15 * time.Second) // once, after the loop
0 findingssrc/runtime/mprof.go
Clean file. 1,723 lines reviewed, nothing to flag.
You still pay for the tokens ($0.022 here), and you get a clear answer instead of filler.
ok nothing to change
Real captures from runs over the Go, Kubernetes, Grafana and Moby repositories. Open the cited line and check.