Skip to content

chore(deps): update module github.com/spiffe/spire to v1.14.6#1425

Merged
arpad-csepi merged 1 commit into
mainfrom
renovate/spire
Apr 28, 2026
Merged

chore(deps): update module github.com/spiffe/spire to v1.14.6#1425
arpad-csepi merged 1 commit into
mainfrom
renovate/spire

Conversation

@agntcy-automation
Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/spiffe/spire 1.14.51.14.6 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

spiffe/spire (github.com/spiffe/spire)

v1.14.6

Compare Source

Security
  • Fixed an issue in the aws_iid server node attestor plugin where the RSA-2048 PKCS7 attestation path verified the PKCS7 signature against its embedded content but returned the identity document parsed from a separate, attacker-controlled field of the attestation data. An attacker who controlled any EC2 instance could impersonate any other EC2 instance during node attestation, with all downstream attestation decisions operating on the forged identity. Thank you Tianshuo Han for reporting this issue.
  • Fixed a TOCTOU issue in the join token data store path where concurrent attestations using the same token could each succeed because tx.Delete() did not report when no row was deleted. The fix uses a read-modify-write transaction with row locking and verifies that exactly one row was deleted. Thank you Tianshuo Han for reporting this issue.

@agntcy-automation agntcy-automation Bot requested a review from a team as a code owner April 28, 2026 13:08
@agntcy-automation agntcy-automation Bot added build dependencies Pull requests that update a dependency file labels Apr 28, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 28, 2026

The latest Buf updates on your PR. Results from workflow Buf CI / verify-proto (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed⏩ skipped⏩ skipped✅ passedApr 28, 2026, 1:08 PM

@github-actions github-actions Bot added size/XS Denotes a PR that changes 0-49 lines and removed dependencies Pull requests that update a dependency file build labels Apr 28, 2026
@arpad-csepi arpad-csepi merged commit cf77b5d into main Apr 28, 2026
84 of 89 checks passed
@arpad-csepi arpad-csepi deleted the renovate/spire branch April 28, 2026 14:52
keraron pushed a commit to keraron/dir that referenced this pull request May 5, 2026
…#1425)

Co-authored-by: agntcy-automation[bot] <269490587+agntcy-automation[bot]@users.noreply.github.com>
Signed-off-by: Aron Kerekes <arkereke@cisco.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XS Denotes a PR that changes 0-49 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant