ROX-36083: Bump Go 1.26.5 and dependencies (release-2.39) - #3550
Conversation
Bump Go from 1.26.3 to 1.26.5 and update golang.org/x/text, golang.org/x/net, google.golang.org/grpc, klauspost/compress to fix FedRAMP GovCloud CVEs: - CVE-2026-42504, CVE-2026-27145, CVE-2026-39822 (Go stdlib) - CVE-2026-56852 (x/text) - CVE-2026-46600 (x/net) - GHSA-hrxh-6v49-42gf (grpc-go) - GHSA-259r-337f-4rfw (klauspost/compress) Partially generated by AI.
|
Skipping CI for Draft Pull Request. |
|
/retest scanner-slim-on-push |
|
@github-actions[bot]: The Use DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/retest scanner-on-push |
|
@github-actions[bot]: The Use DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Summary
Bump Go from 1.26.3 to 1.26.5 and update golang.org/x/text, golang.org/x/net, google.golang.org/grpc, klauspost/compress to fix FedRAMP GovCloud CVEs (ROX-36081, ROX-36083).
CVEs fixed:
Partially generated by AI.