OCPBUGS-78658: Update Go to 1.25.8 for CVE-2026-25679 (release-1.2)#134
Conversation
|
@Thealisyed: This pull request references Jira Issue OCPBUGS-78658, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/jira refresh |
|
@Thealisyed: This pull request references Jira Issue OCPBUGS-78658, which is invalid:
Comment DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
I keep following up on ExtDNS work. Especially 1-2 and 1-1 releases which we never did before. I'm going to have a look at this one until it's released. /assign |
alebedev87
left a comment
There was a problem hiding this comment.
Please squash/fixup the commits as the only change you need is in Konflux Contrainerfile. Also, can you please change the PR description to reflect the changes. The PR changes golang from 1.25.7 to 1.25.8, not from 1.18.z.
There was a problem hiding this comment.
Why this change? We keep using rhel8 on 1.2 release. 4.22 was the right OCP version.
Bump go-toolset from 1.25.7 to 1.25.8 in Konflux Containerfile to fix CVE-2026-25679 (incorrect parsing of IPv6 host literals in net/url). Co-assisted-by: Claude
9a1f0d4 to
fa42d4d
Compare
|
@Thealisyed: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: alebedev87 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
@Thealisyed: Jira Issue OCPBUGS-78658: All pull requests linked via external trackers have merged: Jira Issue OCPBUGS-78658 has been moved to the MODIFIED state. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
Summary
CVE Details
net/url.Parse— accepted malformed IPv6 host literalsChanges
Containerfile.externaldnsgo-toolset:1.25.7→go-toolset:1.25.8