ROX-36083: Bump Go 1.26.5 and dependencies (master) - #3548
Conversation
Bump Go from 1.26.3 to 1.26.5 and update golang.org/x/text, google.golang.org/grpc, klauspost/compress to fix FedRAMP GovCloud CVEs: - CVE-2026-42504, CVE-2026-27145, CVE-2026-39822 (Go stdlib) - CVE-2026-56852 (x/text) - GHSA-hrxh-6v49-42gf (grpc-go) - GHSA-259r-337f-4rfw (klauspost/compress) Partially generated by AI.
|
Skipping CI for Draft Pull Request. |
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe module Go version changed from 1.26.3 to 1.26.5. Several direct and indirect dependency versions also changed in ChangesGo module updates
Estimated code review effort: 1 (Trivial) | ~2 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
/retest scanner-db-on-push |
|
@github-actions[bot]: The Use DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Summary
Bump Go from 1.26.3 to 1.26.5 and update golang.org/x/text, google.golang.org/grpc, klauspost/compress to fix FedRAMP GovCloud CVEs (ROX-36081, ROX-36083).
CVEs fixed:
Note: golang.org/x/net was already at 0.56.0 on master (CVE-2026-46600 already fixed).
Partially generated by AI.