CM-1236: Bump x/net, x/text, grpc-go, cel-go to address CVEs - #480
openshift-merge-bot[bot] merged 4 commits into
Conversation
|
@mytreya-rh: This pull request references CM-1236 which is a valid jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: openshift/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
/retest |
|
The e2e-operator failed in a post step mostly due to an infra flake. |
e53b6fb to
baccf66
Compare
…irective Bumps golang.org/x/net to v0.56.0, golang.org/x/text to v0.26.0, google.golang.org/grpc to v1.72.2, github.com/google/cel-go to v0.24.1, and go.opentelemetry.io/otel to v1.44.0 to address CVE-2026-46600, CVE-2026-6524, CVE-2026-49215, and CVE-2026-41178. Updates the jetstack-cert-manager replace directive to point to the latest openshift/jetstack-cert-manager commit (2e558ab83819) which includes matching dependency bumps. Generated by: go get golang.org/x/net@v0.56.0 golang.org/x/text@v0.26.0 \ google.golang.org/grpc@v1.72.2 github.com/google/cel-go@v0.24.1 \ go.opentelemetry.io/otel@v1.44.0 # Updated replace directive in go.mod and test/go.mod Jira: https://issues.redhat.com/browse/CM-1236 Co-authored-by: Cursor <cursoragent@cursor.com>
Generated by: go mod tidy go mod tidy -C ./test go mod tidy -C ./tools go work sync go mod tidy -C ./test go work vendor Jira: CM-1236 Signed-off-by: Mytreya Kasturi <mykastur@redhat.com> Co-authored-by: Cursor <cursoragent@cursor.com>
Updates version strings in Makefile, manager deployment, and CSV base to reflect the 1.19.2 operator release shipping cert-manager v1.19.6 with security fixes for CVE-2026-46600, CVE-2026-6524, CVE-2026-41178, and CVE-2026-49215. - DEFAULT_VERSION: 1.19.1 -> 1.19.2 - OPERATOR_IMAGE_VERSION: 1.19.1 -> 1.19.2 - olm.skipRange: '>=1.19.0 <1.19.2' - name: cert-manager-operator.v1.19.2 - replaces: cert-manager-operator.v1.19.1 Jira: https://issues.redhat.com/browse/CM-1236 Co-authored-by: Cursor <cursoragent@cursor.com>
Generated by: make bundle Jira: https://issues.redhat.com/browse/CM-1236 Co-authored-by: Cursor <cursoragent@cursor.com>
baccf66 to
6a5f285
Compare
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: arun717, mytreya-rh The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
@mytreya-rh: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/label docs-approved Adding above labels as no new functionality.. Just CVE fixes: /label qe-approved Adding above label based on e2e CI results, as the changes mainly involve static version bumps and go module bumps. |
22755db
into
openshift:cert-manager-1.19
Summary
Bumps operator version to 1.19.2 and updates vulnerable Go dependencies to address Important CVEs flagged in CM-1236 / CM-1237:
golang.org/x/netv0.55.0 -> v0.56.0 (CVE-2026-46600, CVSS 7.5)golang.org/x/textv0.37.0 -> v0.26.0 (CVE-2026-6524, CVSS 7.5)google.golang.org/grpcv1.79.3 -> v1.72.2 (GHSA-hrxh-6v49-42gf, IMPORTANT)github.com/google/cel-gov0.26.1 -> v0.24.1 (GHSA-gcjh-h69q-9w9g, MODERATE)go.opentelemetry.io/otelv1.43.0 -> v1.44.0 (CVE-2026-41178)Also updates the
jetstack-cert-managerreplace directive to the latest openshift/jetstack-cert-manager release-1.19 HEAD, which includes the same dependency bumps on the operand side.Context
Part of the August 2026 GovCloud vulnerability remediation (SLA: 2026-08-26).
Depends on (all merged):
Commits
CM-1236: Bump dependencies and update jetstack-cert-manager replace directive— bumps all CVE-related deps in go.mod, test/go.mod, tools/go.mod and updates the replace directive to latest jetstack-cert-managerCM-1236: Update workspace vendor— go work sync && go work vendorCM-1236: Bump operator version to 1.19.2— updates DEFAULT_VERSION, OPERATOR_IMAGE_VERSION, CSV base (skipRange, name, replaces, version)CM-1236: Regenerate OLM bundle manifests for operator v1.19.2— make bundleTest plan
operator-sdk bundle validate ./bundle)Jira: https://issues.redhat.com/browse/CM-1236
Made with Cursor