Skip to content

CM-1236: Bump x/net, x/text, grpc-go, cel-go to address CVEs - #480

Merged
openshift-merge-bot[bot] merged 4 commits into
openshift:cert-manager-1.19from
mytreya-rh:cm-1236-cert-manager-1.19
Aug 25, 2026
Merged

openshift-merge-bot[bot] merged 4 commits into
openshift:cert-manager-1.19from
mytreya-rh:cm-1236-cert-manager-1.19

Conversation

@mytreya-rh

@mytreya-rh mytreya-rh commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Bumps operator version to 1.19.2 and updates vulnerable Go dependencies to address Important CVEs flagged in CM-1236 / CM-1237:

Also updates the jetstack-cert-manager replace directive to the latest openshift/jetstack-cert-manager release-1.19 HEAD, which includes the same dependency bumps on the operand side.

Context

Part of the August 2026 GovCloud vulnerability remediation (SLA: 2026-08-26).

Depends on (all merged):

Commits

  1. CM-1236: Bump dependencies and update jetstack-cert-manager replace directive — bumps all CVE-related deps in go.mod, test/go.mod, tools/go.mod and updates the replace directive to latest jetstack-cert-manager
  2. CM-1236: Update workspace vendor — go work sync && go work vendor
  3. CM-1236: Bump operator version to 1.19.2 — updates DEFAULT_VERSION, OPERATOR_IMAGE_VERSION, CSV base (skipRange, name, replaces, version)
  4. CM-1236: Regenerate OLM bundle manifests for operator v1.19.2 — make bundle

Test plan

  • CI passes (go build, unit tests, e2e)
  • No breaking API changes from the bumps
  • OLM bundle validates successfully (operator-sdk bundle validate ./bundle)

Jira: https://issues.redhat.com/browse/CM-1236

Made with Cursor

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Aug 24, 2026
@openshift-ci-robot

openshift-ci-robot commented Aug 24, 2026 •

Copy link
Copy Markdown

@mytreya-rh: This pull request references CM-1236 which is a valid jira issue.

Details

In response to this:

Summary

Bumps vulnerable Go dependencies to address Important CVEs flagged in CM-1237:

  • golang.org/x/net v0.55.0 -> v0.56.0 (CVE-2026-46600, CVSS 7.5)
  • golang.org/x/text v0.37.0 -> v0.39.0 (CVE-2026-56852, CVSS 7.5)
  • google.golang.org/grpc v1.79.3 -> v1.82.1 (GHSA-hrxh-6v49-42gf, IMPORTANT)
  • github.com/google/cel-go v0.26.1 -> v0.29.0 (GHSA-gcjh-h69q-9w9g, MODERATE)

Also updates the jetstack-cert-manager replace directive to the merge commit of openshift/jetstack-cert-manager#47, which includes the same dependency bumps on the operand side.

Context

Part of the August 2026 GovCloud vulnerability remediation (SLA: 2026-08-26).
Depends on (now merged):

Commits

  1. CM-1236: Bump x/net, x/text, grpc-go, cel-go to address CVEs — bumps deps in go.mod, test/go.mod, tools/go.mod
  2. CM-1236: Update jetstack-cert-manager to v1.19.7-0.20260824122751-0002fc673b6f — updates replace directive
  3. CM-1236: Update workspace vendor — go work vendor

Test plan

  • CI passes (go build, unit tests, e2e)
  • No breaking API changes from the bumps

Made with Cursor

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 24, 2026
@coderabbitai

coderabbitai Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: e11aab89-b5f6-4e60-8828-f6d195aed5e7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@mytreya-rh

Copy link
Copy Markdown
Contributor Author

/retest

@mytreya-rh

Copy link
Copy Markdown
Contributor Author

The e2e-operator failed in a post step mostly due to an infra flake.
The e2e test itself passed: https://gcsweb-ci.apps.ci.l2s4.p1.openshiftapps.com/gcs/test-platform-results/pr-logs/pull/openshift_cert-manager-operator/480/pull-ci-openshift-cert-manager-operator-cert-manager-1.19-e2e-operator/2091875724179804160/artifacts/e2e-operator/test/build-log.txt
cc: @arun717

@mytreya-rh
mytreya-rh force-pushed the cm-1236-cert-manager-1.19 branch from e53b6fb to baccf66 Compare August 25, 2026 10:50
mytreya-rh and others added 4 commits August 25, 2026 16:37
…irective

Bumps golang.org/x/net to v0.56.0, golang.org/x/text to v0.26.0,
google.golang.org/grpc to v1.72.2, github.com/google/cel-go to v0.24.1,
and go.opentelemetry.io/otel to v1.44.0 to address CVE-2026-46600,
CVE-2026-6524, CVE-2026-49215, and CVE-2026-41178.

Updates the jetstack-cert-manager replace directive to point to the
latest openshift/jetstack-cert-manager commit (2e558ab83819) which
includes matching dependency bumps.

Generated by:
  go get golang.org/x/net@v0.56.0 golang.org/x/text@v0.26.0 \
    google.golang.org/grpc@v1.72.2 github.com/google/cel-go@v0.24.1 \
    go.opentelemetry.io/otel@v1.44.0
  # Updated replace directive in go.mod and test/go.mod

Jira: https://issues.redhat.com/browse/CM-1236
Co-authored-by: Cursor <cursoragent@cursor.com>
Generated by:
  go mod tidy
  go mod tidy -C ./test
  go mod tidy -C ./tools
  go work sync
  go mod tidy -C ./test
  go work vendor

Jira: CM-1236
Signed-off-by: Mytreya Kasturi <mykastur@redhat.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Updates version strings in Makefile, manager deployment, and CSV base
to reflect the 1.19.2 operator release shipping cert-manager v1.19.6
with security fixes for CVE-2026-46600, CVE-2026-6524, CVE-2026-41178,
and CVE-2026-49215.

- DEFAULT_VERSION: 1.19.1 -> 1.19.2
- OPERATOR_IMAGE_VERSION: 1.19.1 -> 1.19.2
- olm.skipRange: '>=1.19.0 <1.19.2'
- name: cert-manager-operator.v1.19.2
- replaces: cert-manager-operator.v1.19.1

Jira: https://issues.redhat.com/browse/CM-1236
Co-authored-by: Cursor <cursoragent@cursor.com>
Generated by:
  make bundle

Jira: https://issues.redhat.com/browse/CM-1236
Co-authored-by: Cursor <cursoragent@cursor.com>
@mytreya-rh
mytreya-rh force-pushed the cm-1236-cert-manager-1.19 branch from baccf66 to 6a5f285 Compare August 25, 2026 11:07
@arun717

arun717 commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Aug 25, 2026
@openshift-ci

openshift-ci Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: arun717, mytreya-rh

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

@mytreya-rh: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@mytreya-rh

Copy link
Copy Markdown
Contributor Author

/label docs-approved
/label px-approved

Adding above labels as no new functionality.. Just CVE fixes:

/label qe-approved

Adding above label based on e2e CI results, as the changes mainly involve static version bumps and go module bumps.
In stage builds, we need to test again because the builder image used in CI tests registry.ci.openshift.org/ocp/builder:rhel-9-golang-1.25-openshift-4.21 is still based off of go 1.25.11
Whereas we plan to use builder image: brew.registry.redhat.io/rh-osbs/openshift-golang-builder:rhel_9.4_golang_1.25

@openshift-ci openshift-ci Bot added docs-approved Signifies that Docs has signed off on this PR px-approved Signifies that Product Support has signed off on this PR qe-approved Signifies that QE has signed off on this PR labels Aug 25, 2026
@openshift-merge-bot
openshift-merge-bot Bot merged commit 22755db into openshift:cert-manager-1.19 Aug 25, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. docs-approved Signifies that Docs has signed off on this PR jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. px-approved Signifies that Product Support has signed off on this PR qe-approved Signifies that QE has signed off on this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants