Bump the oc-mirror-v1-security-updates group across 1 directory with 10 updates - #1483
Conversation
…10 updates Bumps the oc-mirror-v1-security-updates group with 6 updates in the /v1 directory: | Package | From | To | | --- | --- | --- | | [github.com/containerd/containerd](https://github.com/containerd/containerd) | `1.7.27` | `1.7.33` | | [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.14.0` | `5.19.1` | | [github.com/google/cel-go](https://github.com/google/cel-go) | `0.23.2` | `0.29.0` | | [github.com/sigstore/fulcio](https://github.com/sigstore/fulcio) | `1.6.4` | `1.8.6` | | [github.com/sigstore/rekor](https://github.com/sigstore/rekor) | `1.3.6` | `1.5.2` | | [oras.land/oras-go/v2](https://github.com/oras-project/oras-go) | `2.6.0` | `2.6.2` | Updates `github.com/containerd/containerd` from 1.7.27 to 1.7.33 - [Release notes](https://github.com/containerd/containerd/releases) - [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md) - [Commits](containerd/containerd@v1.7.27...v1.7.33) Updates `github.com/go-git/go-git/v5` from 5.14.0 to 5.19.1 - [Release notes](https://github.com/go-git/go-git/releases) - [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md) - [Commits](go-git/go-git@v5.14.0...v5.19.1) Updates `golang.org/x/crypto` from 0.39.0 to 0.50.0 - [Commits](golang/crypto@v0.39.0...v0.50.0) Updates `github.com/go-git/go-billy/v5` from 5.6.2 to 5.9.0 - [Release notes](https://github.com/go-git/go-billy/releases) - [Commits](go-git/go-billy@v5.6.2...v5.9.0) Updates `github.com/google/cel-go` from 0.23.2 to 0.29.0 - [Release notes](https://github.com/google/cel-go/releases) - [Commits](cel-expr/cel-go@v0.23.2...v0.29.0) Updates `github.com/sigstore/fulcio` from 1.6.4 to 1.8.6 - [Release notes](https://github.com/sigstore/fulcio/releases) - [Changelog](https://github.com/sigstore/fulcio/blob/main/CHANGELOG.md) - [Commits](sigstore/fulcio@v1.6.4...v1.8.6) Updates `github.com/sigstore/rekor` from 1.3.6 to 1.5.2 - [Release notes](https://github.com/sigstore/rekor/releases) - [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md) - [Commits](sigstore/rekor@v1.3.6...v1.5.2) Updates `golang.org/x/net` from 0.40.0 to 0.54.0 - [Commits](golang/net@v0.40.0...v0.54.0) Updates `google.golang.org/grpc` from 1.68.1 to 1.81.1 - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.68.1...v1.81.1) Updates `oras.land/oras-go/v2` from 2.6.0 to 2.6.2 - [Release notes](https://github.com/oras-project/oras-go/releases) - [Changelog](https://github.com/oras-project/oras-go/blob/main/RELEASES.md) - [Commits](oras-project/oras-go@v2.6.0...v2.6.2) --- updated-dependencies: - dependency-name: github.com/containerd/containerd dependency-version: 1.7.33 dependency-type: direct:production dependency-group: oc-mirror-v1-security-updates - dependency-name: github.com/go-git/go-git/v5 dependency-version: 5.19.1 dependency-type: indirect dependency-group: oc-mirror-v1-security-updates - dependency-name: golang.org/x/crypto dependency-version: 0.50.0 dependency-type: indirect dependency-group: oc-mirror-v1-security-updates - dependency-name: github.com/go-git/go-billy/v5 dependency-version: 5.9.0 dependency-type: indirect dependency-group: oc-mirror-v1-security-updates - dependency-name: github.com/google/cel-go dependency-version: 0.29.0 dependency-type: indirect dependency-group: oc-mirror-v1-security-updates - dependency-name: github.com/sigstore/fulcio dependency-version: 1.8.6 dependency-type: indirect dependency-group: oc-mirror-v1-security-updates - dependency-name: github.com/sigstore/rekor dependency-version: 1.5.2 dependency-type: indirect dependency-group: oc-mirror-v1-security-updates - dependency-name: golang.org/x/net dependency-version: 0.54.0 dependency-type: indirect dependency-group: oc-mirror-v1-security-updates - dependency-name: google.golang.org/grpc dependency-version: 1.81.1 dependency-type: indirect dependency-group: oc-mirror-v1-security-updates - dependency-name: oras.land/oras-go/v2 dependency-version: 2.6.2 dependency-type: indirect dependency-group: oc-mirror-v1-security-updates ... Signed-off-by: dependabot[bot] <support@github.com>
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
WalkthroughUpdated ChangesGo module dependency refresh
Estimated code review effort: 2 (Simple) | ~10 minutes 🚥 Pre-merge checks | ✅ 15✅ Passed checks (15 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dependabot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @dependabot[bot]. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/ok-to-test |
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (1)
v1/go.mod (1)
5-267: 🔒 Security & Privacy | 🔵 TrivialVerify module and artifact integrity controls.
Confirm that
v1/go.sumcontains checksums for all changed modules and thatgo mod verifypasses. Confirm that the release build emits an SBOM with provenance attestation and signs the resulting artifact with Sigstore or cosign. The supplied build target shows compilation and copying only.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@v1/go.mod` around lines 5 - 267, Update the module and release build flow associated with the changed dependencies in v1/go.mod: regenerate and verify v1/go.sum entries, ensure go mod verify passes, and extend the release target beyond compilation/copying to emit an SBOM with provenance attestation and sign the resulting artifact using Sigstore or cosign.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@v1/go.mod`:
- Line 257: Update the google.golang.org/grpc dependency in go.mod from v1.81.1
to v1.82.1 or later, then run go mod tidy to refresh the module graph and
checksums while preserving the production dependency on
google.golang.org/grpc/internal/transport.
- Line 99: Update the direct dependency in the v1 module that introduces
github.com/docker/docker v27.5.0+incompatible, selecting a version that resolves
Docker to v29.5.1 or later, then run go mod tidy and verify the indirect Docker
entry is updated. If Docker packages are unreachable from the production binary,
document that exception instead of upgrading.
---
Nitpick comments:
In `@v1/go.mod`:
- Around line 5-267: Update the module and release build flow associated with
the changed dependencies in v1/go.mod: regenerate and verify v1/go.sum entries,
ensure go mod verify passes, and extend the release target beyond
compilation/copying to emit an SBOM with provenance attestation and sign the
resulting artifact using Sigstore or cosign.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 14c8332d-8100-4f8e-bfef-8d0ebf256aaa
⛔ Files ignored due to path filters (1)
v1/go.sumis excluded by!**/*.sum
📒 Files selected for processing (1)
v1/go.mod
| github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect | ||
| github.com/distribution/reference v0.6.0 // indirect | ||
| github.com/docker/distribution v2.8.3+incompatible // indirect | ||
| github.com/docker/docker v27.5.0+incompatible // indirect |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
# First, examine the go.mod file to see the full context
head -110 v1/go.mod | tail -20Repository: openshift/oc-mirror
Length of output: 1403
🏁 Script executed:
# Check if go.mod provides dependency comments showing which direct dependency pulls docker
grep -B2 -A2 "docker/docker" v1/go.modRepository: openshift/oc-mirror
Length of output: 500
🏁 Script executed:
# Use go mod graph to understand the dependency chain (read-only)
# This shows which direct dep pulls docker as indirect
if [ -d v1 ]; then
cd v1 && go mod graph 2>/dev/null | grep "docker" || echo "go mod graph unavailable in sandbox"
fiRepository: openshift/oc-mirror
Length of output: 149
🌐 Web query:
Moby github.com/docker/docker v27.5.0 CVE OSV vulnerabilities
💡 Result:
Moby version v27.5.0 is known to be affected by several security vulnerabilities discovered or disclosed after its release. Because version v27.5.0 was released prior to these findings, users are generally advised to update to version 29.5.1 or newer (or the relevant patched versions provided by their distribution) to mitigate these risks [1][2][3]. Key vulnerabilities affecting versions including v27.5.0 include: CVE-2026-41568 (GHSA-vp62-88p7-qqf5): A race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem [1][2]. This is patched in Docker Engine version 29.5.1 [2]. CVE-2026-41567 (GHSA-x86f-5xw2-fm2r): A vulnerability where the PUT /containers/{id}/archive API endpoint may execute container binaries on the host with daemon (root) privileges, particularly when handling compressed archives (e.g., xz, gzip) that trigger the use of external system binaries [3]. CVE-2024-29018: A vulnerability where external DNS requests from containers on 'internal' networks could potentially lead to data exfiltration [4][5][6]. Patches for this were included in later releases, such as 27.5.1 [5][6]. General Guidance: To maintain a secure environment, it is recommended to review the official Docker security announcements and your OS vendor's security advisories [7]. Because Moby/Docker frequently releases security patches, you should check for the latest stable version and apply updates promptly [7]. You can also verify specific vulnerability status for your environment via the Open Source Vulnerabilities (OSV) database or the GitHub Advisory Database using the provided CVE and GHSA identifiers [8][9][4].
Citations:
- 1: GHSA-vp62-88p7-qqf5
- 2: https://nvd.nist.gov/vuln/detail/CVE-2026-41568
- 3: GHSA-x86f-5xw2-fm2r
- 4: https://osv.dev/vulnerability/DEBIAN-CVE-2024-29018
- 5: https://osv.dev/vulnerability/SUSE-SU-2025:0776-1
- 6: https://lists.suse.com/pipermail/sle-security-updates/2025-March/020584.html
- 7: https://docs.docker.com/security/security-announcements/
- 8: https://osv.dev/vulnerability/GHSA-x744-4wpc-v9h2
- 9: https://osv.dev/vulnerability/GHSA-4vq8-7jfc-9cvp
🌐 Web query:
github.com/docker/docker security advisories July 2026
💡 Result:
As of July 31, 2026, there are no specific security advisories published directly in the moby/moby repository for the month of July 2026. Security advisories for the Moby/Docker project are tracked within the moby/moby GitHub repository's security advisory section [1]. While no advisories were published for Moby in July 2026, relevant recent activity in the broader container ecosystem includes: 1. Moby/BuildKit: A security advisory (GHSA-32pv-7hq5-qhwq / CVE-2026-15791) was published on July 16, 2026, affecting BuildKit (versions <= v0.31.1). This vulnerability involves a path traversal issue in the low-level build API that could be exploited to remove the contents of the host's /tmp directory. It was fixed in BuildKit v0.31.2 [2]. 2. General Ecosystem: Third-party security reporting has noted other vulnerabilities related to Docker products in July 2026, such as those listed by external threat intelligence sources (e.g., CVE-2026-52833, CVE-2026-54540, CVE-2026-34150) [3], and package maintainers (such as SUSE) have issued updates for Docker incorporating various fixes [4]. Users should refer to the official Docker Security Announcements page and the moby/moby security advisory repository for the most authoritative and up-to-date information regarding their specific deployments [1][5].
Citations:
- 1: https://github.com/moby/moby/security/advisories
- 2: GHSA-32pv-7hq5-qhwq
- 3: https://vuln.today/articles/docker-2026-07-17-4-new-docker-vulnerabilities-4-high-severity-1-with-poc
- 4: https://www.suse.com/support/update/announcement/2026/suse-su-202622513-1/
- 5: https://docs.docker.com/security/security-announcements/
Resolve Moby vulnerabilities in the indirect Docker dependency.
The pinned version github.com/docker/docker v27.5.0+incompatible is affected by multiple high-severity vulnerabilities:
- CVE-2026-41568 (GHSA-vp62-88p7-qqf5): Race condition in
docker cpallows malicious containers to create arbitrary files or directories on the host. - CVE-2026-41567 (GHSA-x86f-5xw2-fm2r): The PUT
/containers/{id}/archiveAPI endpoint may execute container binaries on the host with daemon privileges. - CVE-2024-29018: Containers on internal networks can make external DNS requests, leading to potential data exfiltration.
Patches exist in version 29.5.1 and later. Because this is an indirect dependency, identify and update the direct dependency that pulls docker/docker v27.5.0+incompatible, then run go mod tidy. If the Docker packages are not reachable from the production binary in the v1 module, document the exception before merging.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@v1/go.mod` at line 99, Update the direct dependency in the v1 module that
introduces github.com/docker/docker v27.5.0+incompatible, selecting a version
that resolves Docker to v29.5.1 or later, then run go mod tidy and verify the
indirect Docker entry is updated. If Docker packages are unreachable from the
production binary, document that exception instead of upgrading.
Sources: Path instructions, Learnings, Linters/SAST tools
| google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7 // indirect | ||
| google.golang.org/genproto/googleapis/api v0.0.0-20260414002931-afd174a4e478 // indirect | ||
| google.golang.org/genproto/googleapis/rpc v0.0.0-20260511170946-3700d4141b60 // indirect | ||
| google.golang.org/grpc v1.81.1 // indirect |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- v1/go.mod context ---'
sed -n '245,265p' v1/go.mod
printf '%s\n' '--- gRPC references ---'
rg -n --glob '!vendor/**' 'google\.golang\.org/grpc|grpc\.io|grpc' v1/go.mod v1/go.sum 2>/dev/null | head -200
printf '%s\n' '--- module files ---'
git ls-files '*go.mod' '*go.sum'
printf '%s\n' '--- go version/tool availability ---'
go version 2>&1 || true
printf '%s\n' '--- OSV query ---'
curl -fsS https://api.osv.dev/v1/query \
-H 'content-type: application/json' \
--data '{"package":{"name":"google.golang.org/grpc","ecosystem":"Go"},"version":"v1.81.1"}' |
python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps(d, indent=2, sort_keys=True))'Repository: openshift/oc-mirror
Length of output: 22301
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- gRPC imports in v1 source ---'
rg -n --glob '*.go' 'google\.golang\.org/grpc|grpc\.credentials|grpc\.status|grpc\.codes|grpc\.metadata|grpc\.credentials' v1 || true
printf '%s\n' '--- direct and indirect requirements ---'
sed -n '1,190p' v1/go.mod
printf '%s\n' '--- xDS references in v1 source ---'
rg -n --glob '*.go' 'xds|RBAC|NewClient|grpc\.Dial|grpc\.NewServer|grpc\.Serve|grpc\.ClientConn' v1 || trueRepository: openshift/oc-mirror
Length of output: 9531
🏁 Script executed:
#!/bin/bash
set -eu
cd v1
printf '%s\n' '--- module dependency path ---'
GOTOOLCHAIN=local GOPROXY=off go mod why -m google.golang.org/grpc 2>&1 || true
printf '%s\n' '--- dependency graph edges to gRPC ---'
GOTOOLCHAIN=local GOPROXY=off go mod graph 2>/dev/null |
awk '$2 ~ /^google\.golang\.org\/grpc(@|$)/ {print}' || true
printf '%s\n' '--- module replacements and exclusions ---'
rg -n '^(replace|exclude)\b|google\.golang\.org/grpc' go.modRepository: openshift/oc-mirror
Length of output: 1556
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- cached source locations ---'
GOMODCACHE="$(go env GOMODCACHE)"
find "$GOMODCACHE" -type f \( \
-path '*containerd*errdefs*/*.go' -o \
-path '*google.golang.org/grpc* v1.81.1*/*/codes/*.go' \
\) 2>/dev/null | head -50 || true
printf '%s\n' '--- containerd errdefs imports ---'
curl -fsSL https://raw.githubusercontent.com/containerd/containerd/v1.7.33/errdefs/grpc.go |
sed -n '1,100p'
printf '%s\n' '--- grpc/codes imports ---'
curl -fsSL https://raw.githubusercontent.com/grpc/grpc-go/v1.81.1/codes/codes.go |
sed -n '1,80p'Repository: openshift/oc-mirror
Length of output: 7550
🏁 Script executed:
#!/bin/bash
set -eu
cd v1
printf '%s\n' '--- all selected gRPC packages in the build graph ---'
GOTOOLCHAIN=local GOPROXY=off go list -deps -e ./... 2>/dev/null |
awk '/^google\.golang\.org\/grpc(\/|$)/ {print}' |
sort -u
printf '%s\n' '--- affected OSV package paths present in the build graph ---'
GOTOOLCHAIN=local GOPROXY=off go list -deps -e ./... 2>/dev/null |
awk '
$0 == "google.golang.org/grpc/internal/transport" ||
$0 == "google.golang.org/grpc/internal/xds/rbac" {print}
' |
sort -uRepository: openshift/oc-mirror
Length of output: 2910
🏁 Script executed:
#!/bin/bash
set -eu
cd v1
printf '%s\n' '--- shortest paths to affected gRPC packages ---'
for pkg in \
google.golang.org/grpc \
google.golang.org/grpc/internal/transport \
google.golang.org/grpc/internal/xds/rbac
do
printf '\n[%s]\n' "$pkg"
GOTOOLCHAIN=local GOPROXY=off go mod why "$pkg" 2>&1 || true
done
printf '%s\n' '--- direct source imports of gRPC server/client APIs ---'
rg -n --glob '*.go' \
'google\.golang\.org/grpc(/|")|grpc\.(NewServer|Serve|Dial|DialContext|NewClient)' \
. --glob '!vendor/**' --glob '!**/testdata/**' | head -200 || trueRepository: openshift/oc-mirror
Length of output: 2771
🏁 Script executed:
#!/bin/bash
set -eu
cd v1
GOTOOLCHAIN=local GOPROXY=off go list -deps -json -e ./... 2>/dev/null |
python3 - <<'PY'
import json
import sys
targets = {
"google.golang.org/grpc",
"google.golang.org/grpc/internal/transport",
"google.golang.org/grpc/internal/xds/rbac",
}
records = []
decoder = json.JSONDecoder()
data = sys.stdin.read()
pos = 0
while pos < len(data):
while pos < len(data) and data[pos].isspace():
pos += 1
if pos >= len(data):
break
try:
obj, end = decoder.raw_decode(data, pos)
except json.JSONDecodeError:
break
records.append(obj)
pos = end
for target in sorted(targets):
print(f"[importers of {target}]")
found = False
for obj in records:
if target in obj.get("Imports", []):
print(obj.get("ImportPath", "<unknown>"))
found = True
if not found:
print("<none>")
PY
printf '%s\n' '--- production status imports ---'
sed -n '1,100p' "$(go env GOMODCACHE)/google.golang.org/grpc@v1.81.1/status/status.go"Repository: openshift/oc-mirror
Length of output: 3951
🏁 Script executed:
#!/bin/bash
set -eu
cd v1
python3 - <<'PY'
import json
import os
import subprocess
cmd = [
"go", "list", "-deps", "-json", "-e", "./...",
]
env = os.environ.copy()
env.update({"GOTOOLCHAIN": "local", "GOPROXY": "off"})
raw = subprocess.run(cmd, env=env, text=True, capture_output=True, check=False).stdout
decoder = json.JSONDecoder()
pos = 0
records = []
while pos < len(raw):
while pos < len(raw) and raw[pos].isspace():
pos += 1
if pos >= len(raw):
break
obj, pos = decoder.raw_decode(raw, pos)
records.append(obj)
targets = {
"google.golang.org/grpc",
"google.golang.org/grpc/internal/transport",
"google.golang.org/grpc/internal/xds/rbac",
}
for target in sorted(targets):
print(f"[importers of {target}]")
importers = sorted(
obj.get("ImportPath", "<unknown>")
for obj in records
if target in obj.get("Imports", [])
)
print("\n".join(importers) if importers else "<none>")
PYRepository: openshift/oc-mirror
Length of output: 1123
Upgrade google.golang.org/grpc before release.
The production build graph includes google.golang.org/grpc/internal/transport. Upgrade from v1.81.1 to v1.82.1 or later, then run go mod tidy. The xDS RBAC package is not included, but the HTTP/2 transport finding remains.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@v1/go.mod` at line 257, Update the google.golang.org/grpc dependency in
go.mod from v1.81.1 to v1.82.1 or later, then run go mod tidy to refresh the
module graph and checksums while preserving the production dependency on
google.golang.org/grpc/internal/transport.
Sources: Path instructions, Learnings, Linters/SAST tools
|
@dependabot[bot]: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Bumps the oc-mirror-v1-security-updates group with 6 updates in the /v1 directory:
1.7.271.7.335.14.05.19.10.23.20.29.01.6.41.8.61.3.61.5.22.6.02.6.2Updates
github.com/containerd/containerdfrom 1.7.27 to 1.7.33Release notes
Sourced from github.com/containerd/containerd's releases.
... (truncated)
Changelog
Sourced from github.com/containerd/containerd's changelog.
... (truncated)
Commits
e8b1a9bMerge pull request #13631 from samuelkarp/prepare-1.7.337517e67Prepare release notes for v1.7.33ab30651Merge commit from fork0962898Merge pull request #13615 from k8s-infra-cherrypick-robot/cherry-pick-13606-t...74c728cupdate runc binary to v1.3.6d34cdafMerge commit from fork1e9806fMerge commit from fork9ab2b7aBound user-database file reads in openBoundedUserFiled805d96Merge pull request #13579 from akhilerm/1.7-go1.26.4947caa4update go to 1.26.4/1.25.11Updates
github.com/go-git/go-git/v5from 5.14.0 to 5.19.1Release notes
Sourced from github.com/go-git/go-git/v5's releases.
... (truncated)
Commits
3c3be60Merge pull request #2137 from go-git/validate-v53fba897plumbing: format/packfile, cap delta chain depth in parsera97d660Merge pull request #2125 from hiddeco/v5/format-input-boundsaeaa125plumbing: format/objfile, require Header before Read1f38e17plumbing: format/packfile, bound inflate sizef7545a0plumbing: format/idxfile, bound nr by file size170b881Merge pull request #2116 from pjbgf/symlink-v57b6d994Merge pull request #2117 from hiddeco/v5/worktree-fs-mkdirall-root-noopf0709b3git: Stop validating symlink target paths776d00fgit: Allow MkdirAll on worktree-root pathsUpdates
golang.org/x/cryptofrom 0.39.0 to 0.50.0Commits
03ca0dcgo.mod: update golang.org/x dependencies8400f4assh: respect signer's algorithm preference in pickSignatureAlgorithm81c6cb3ssh: swap cbcMinPaddingSize to cbcMinPacketSize to get encLength982eaa6go.mod: update golang.org/x dependencies159944fssh,acme: clean up tautological/impossible nil conditionsa408498acme: only require prompt if server has terms of servicecab0f71all: upgrade go directive to at least 1.25.0 [generated]2f26647x509roots/fallback: update bundlee08b067go.mod: update golang.org/x dependencies7d0074cscrypt: fix panic on parameters <= 0Updates
github.com/go-git/go-billy/v5from 5.6.2 to 5.9.0Release notes
Sourced from github.com/go-git/go-billy/v5's releases.
Commits
237e529Merge pull request #206 from pjbgf/v5-improvements04edb39build: Add go-git integration testd8efefdosfs: preserve empty ChrootOS base07f2a0bMerge pull request #205 from pjbgf/v5-improvements25207c8build: Bump Go versions in workflows2fda229osfs: ChrootOS eval baseDir on creation427b27fMerge pull request #203 from pjbgf/v5-improvements7d5a23echroot: Reject symlink loops2c2287autil: avoid following symlinks in RemoveAll fallbackcbd88e9Fix mount path handlingUpdates
github.com/google/cel-gofrom 0.23.2 to 0.29.0Release notes
Sourced from github.com/google/cel-go's releases.
... (truncated)
Commits
fa16799avoid repeated construction of cost tracker (#1357)ea3d5c0feat(ext): add json encoder (#1340)a4d0d64startsWith / endsWith runtime cost agreement with checked cost (#1351)d4efa77Ensure receiver and global matches cost estimates agree (#1350)13cff33ext/lists: add max size check to genRange() to prevent OOM (#1310)f0ffa7eExecution frame integration with updated IntepretableV2 (#1344)f1ec2f6guard int32/uint32 map key narrowing in qualifyInternal (#1337)258e7c8Managed execution frame with async call foundations (#1316)14f6746validate offset on empty-string path in indexOf and lastIndexOf (#1335)783267dreject out-of-range minutes in timezone offset parsing (#1336)Updates
github.com/sigstore/fulciofrom 1.6.4 to 1.8.6Release notes
Sourced from github.com/sigstore/fulcio's releases.
... (truncated)
Changelog
Sourced from github.com/sigstore/fulcio's changelog.
... (truncated)
Commits
378c654Block cross-host redirects and restrict bearer token to expected host (#2354)7a5d3e3bump builder image to use go1.26.3 (#2353)a05982ebuild(deps): bump go.step.sm/crypto from 0.75.0 to 0.81.0 (#2348)dfa63a8build(deps): bump golang from313faaeto2d6c802(#2344)7b3a344build(deps): bump google.golang.org/api from 0.279.0 to 0.280.0 (#2349)9290f7fbuild(deps): bump the all group with 2 updates (#2350)423d535build(deps): bump nginx from 1.31.0 to 1.31.1 in the all group (#2352)19a3f8ebuild(deps): bump the all group across 1 directory with 6 updates (#2337)6b597cebuild(deps): bump google.golang.org/api from 0.276.0 to 0.279.0 (#2338)0d1dc79build(deps): bump nginx from 1.29.8 to 1.31.0 in the all group (#2342)Updates
github.com/sigstore/rekorfrom 1.3.6 to 1.5.2Release notes
Sourced from github.com/sigstore/rekor's releases.
... (truncated)
Changelog
Sourced from github.com/sigstore/rekor's changelog.
... (truncated)
Commits
3b75cd9build(deps): Bump the all group across 1 directory with 7 updates (#2829)759b98ealpine: Enforce max size limit on decompression (#2831)c7e77eeSupport restricting kinds on insertion (#2814)a10818afix(trillianclient): strip dns:/// scheme from TLS ServerName in gRPC dial (#...c31f3fcbuild(deps): Bump cloud.google.com/go/profiler from 0.4.3 to 0.6.0f2a9fb0build(deps): Bump go.uber.org/zap from 1.27.1 to 1.28.0e3ba248build(deps): Bump golang in the all group across 1 directory62e5dddbuild(deps): Bump github.com/go-openapi/swag from 0.25.5 to 0.26.0f4f91d5build(deps): Bump github.com/tink-crypto/tink-go-awskms/v2 to v3 (#2827)9bc540fbuild(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2820)Updates
golang.org/x/netfrom 0.40.0 to 0.54.0Commits
b138e06go.mod: update golang.org/x dependencies689f70aquic: fix wrong final size being used for RESET_STREAM frame208f306http3: increase handshake timeout49810dahttp2: enable net/http wrapping when go >= 1.275e11a5aquic: fix data race in streamForFrame8c63081http2: use empty Transport rather than DefaultTransport in http2wrapfc7b466http2: add http2wrap test15c2cb1http2: avoid overflowing 32-bit int when http2wrap enabled6465188http2: add wrapped Server72f419ahttp2: add wrapped ClientConnUpdates
google.golang.org/grpcfrom 1.68.1 to 1.81.1Release notes
Sourced from google.golang.org/grpc's releases.
... (truncated)
Commits
caf0772Change version from 1.81.1-dev to 1.81.1 (#9122)6ccbeebCherry-pick #9111 into v1.81.x (#9121)b33c29eCherry-pick #9081 into v1.81.x (#9102)c45fae6Change version to 1.81.1-dev (#9063)Summary by CodeRabbit