GHSA-r44j-crv5-q35m / NVD's own CPE match pins this to the single
exact version percona-toolkit:3.6.0, with no version range -- the
advisory is "unreviewed" and carries no upper bound, so CPE-based
scanners (Trivy/Grype/Wiz) treat it as affecting every later version
too. The vulnerable code (weak SHA-256-as-KDF password hashing in
src/go/pt-secure-collect/encrypt.go) was replaced with a proper HKDF
derivation upstream in commit 78f20304 ("Use KDF instead of hash"),
first shipped in v3.7.0 and present in our v3.7.1 build. Independent
of the version question, this package never builds pt-secure-collect
at all -- only pt-online-schema-change (a separate Perl tool); the
build step explicitly drops the manifypods->gotools coupling so Go
tools are never compiled.