Skip to content

ROX-36083: Bump Go 1.26.5 and dependencies (release-2.40) - #3549

Open
janisz wants to merge 1 commit into
release-2.40from
chore/bump-deps-fedramp-release-2.40
Open

ROX-36083: Bump Go 1.26.5 and dependencies (release-2.40)#3549
janisz wants to merge 1 commit into
release-2.40from
chore/bump-deps-fedramp-release-2.40

Conversation

@janisz

@janisz janisz commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump Go from 1.26.3 to 1.26.5 and update golang.org/x/text, golang.org/x/net, google.golang.org/grpc, klauspost/compress to fix FedRAMP GovCloud CVEs (ROX-36081, ROX-36083).

CVEs fixed:

Partially generated by AI.

Bump Go from 1.26.3 to 1.26.5 and update golang.org/x/text,
golang.org/x/net, google.golang.org/grpc, klauspost/compress
to fix FedRAMP GovCloud CVEs:
- CVE-2026-42504, CVE-2026-27145, CVE-2026-39822 (Go stdlib)
- CVE-2026-56852 (x/text)
- CVE-2026-46600 (x/net)
- GHSA-hrxh-6v49-42gf (grpc-go)
- GHSA-259r-337f-4rfw (klauspost/compress)

Partially generated by AI.
@openshift-ci

openshift-ci Bot commented Aug 5, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@janisz
janisz marked this pull request as ready for review August 5, 2026 14:47
@janisz
janisz requested a review from a team as a code owner August 5, 2026 14:47
@openshift-ci

openshift-ci Bot commented Aug 5, 2026

Copy link
Copy Markdown

@janisz: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/slim-e2e-tests f891311 link false /test slim-e2e-tests

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants