Skip to content

Conversation

@hardcoretime
Copy link
Contributor

@hardcoretime hardcoretime commented Dec 22, 2025

Description

  • Used the builder/golang-alt image instead of builder/alt and package installation.
  • Updated base image to Golang 1.24.11 to resolve CVE-2025-61729.
  • Updated golang.org/x/crypto to version 0.45.0 to resolve CVE-2025-47914.

Why do we need it, and what problem does it solve?

This is required to resolve CVE-2025-61729 and CVE-2025-47914.

What is the expected result?

The security check should pass.

Checklist

  • The code is covered by unit tests.
  • e2e tests passed.
  • Documentation updated according to the changes.
  • Changes were tested in the Kubernetes cluster manually.

Changelog entries

section: core
type: chore
summary: "Fix CVEs."
impact_level: low

@hardcoretime hardcoretime added this to the v1.4.0 milestone Dec 22, 2025
@hardcoretime hardcoretime force-pushed the chore/update-base-images-and-go-deps branch from 0284794 to c3c3d7a Compare December 23, 2025 14:30
@hardcoretime hardcoretime added the e2e/run Run e2e test on cluster of PR author label Dec 23, 2025
@deckhouse-BOaTswain
Copy link
Contributor

deckhouse-BOaTswain commented Dec 23, 2025

Workflow has started.
Follow the progress here: Workflow Run

The target step completed with status: failure.

@deckhouse-BOaTswain deckhouse-BOaTswain removed the e2e/run Run e2e test on cluster of PR author label Dec 23, 2025
@deckhouse-BOaTswain
Copy link
Contributor

deckhouse-BOaTswain commented Dec 23, 2025

Workflow has started.
Follow the progress here: Workflow Run

The target step completed with status: failure.

@hardcoretime hardcoretime added the e2e/run Run e2e test on cluster of PR author label Dec 23, 2025
@deckhouse-BOaTswain
Copy link
Contributor

deckhouse-BOaTswain commented Dec 23, 2025

Workflow has started.
Follow the progress here: Workflow Run

The target step completed with status: failure.

@deckhouse-BOaTswain deckhouse-BOaTswain removed the e2e/run Run e2e test on cluster of PR author label Dec 24, 2025
@hardcoretime hardcoretime added the e2e/run Run e2e test on cluster of PR author label Dec 25, 2025
@deckhouse-BOaTswain
Copy link
Contributor

deckhouse-BOaTswain commented Dec 25, 2025

Workflow has started.
Follow the progress here: Workflow Run

The target step completed with status: failure.

@deckhouse-BOaTswain deckhouse-BOaTswain removed the e2e/run Run e2e test on cluster of PR author label Dec 25, 2025
@hardcoretime hardcoretime force-pushed the chore/update-base-images-and-go-deps branch from c3c3d7a to ce350d7 Compare December 30, 2025 10:18
@hardcoretime hardcoretime added the e2e/run Run e2e test on cluster of PR author label Dec 30, 2025
@deckhouse-BOaTswain
Copy link
Contributor

deckhouse-BOaTswain commented Dec 30, 2025

Workflow has started.
Follow the progress here: Workflow Run

The target step completed with status: failure.

@deckhouse-BOaTswain deckhouse-BOaTswain removed the e2e/run Run e2e test on cluster of PR author label Dec 30, 2025
@hardcoretime hardcoretime added the e2e/run Run e2e test on cluster of PR author label Jan 12, 2026
Roman Sysoev added 3 commits January 12, 2026 10:29
Signed-off-by: Roman Sysoev <roman.sysoev@flant.com>
Signed-off-by: Roman Sysoev <roman.sysoev@flant.com>
- git
- binutils
- make
- gcc

Signed-off-by: Roman Sysoev <roman.sysoev@flant.com>
@hardcoretime hardcoretime force-pushed the chore/update-base-images-and-go-deps branch from ce350d7 to ccc2906 Compare January 12, 2026 07:40
@hardcoretime hardcoretime added e2e/run Run e2e test on cluster of PR author and removed e2e/run Run e2e test on cluster of PR author labels Jan 12, 2026
@deckhouse-BOaTswain
Copy link
Contributor

deckhouse-BOaTswain commented Jan 12, 2026

Workflow has started.
Follow the progress here: Workflow Run

The target step completed with status: failure.

@deckhouse-BOaTswain deckhouse-BOaTswain removed the e2e/run Run e2e test on cluster of PR author label Jan 12, 2026
@hardcoretime hardcoretime marked this pull request as ready for review January 12, 2026 15:35
@hardcoretime hardcoretime requested review from diafour and removed request for diafour January 12, 2026 15:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants