fix(dep): upgrade grpcGo to v1.79.3, fix CVE-2026-33186#66
fix(dep): upgrade grpcGo to v1.79.3, fix CVE-2026-33186#66openshift-merge-bot[bot] merged 3 commits intoredhat-developer:masterfrom
Conversation
Signed-off-by: Kanika Rana <krana@redhat.com>
|
@ranakan19: The label(s) DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
cluster initation failed for ci/prow/v4.13-e2e : retesting /retest |
|
/approve |
|
/lgtm |
|
/approve |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: anandf, svghadi The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
ci/prow/v4.14-e2e failing with, retesting /retest |
|
/retest |
|
seems to be impacting other jobs as well /retest |
Signed-off-by: Kanika Rana <krana@redhat.com>
|
build10 image registry was down, seems to have been fixed, retrying now |
|
/retest |
|
/test v4.13-e2e v4.12-e2e |
|
/lgtm |
1212ec2
into
redhat-developer:master
What type of PR is this?
/kind bug
What does this PR do / why we need it:
fix CVE-2026-33186[gRPC-Go auth bypass (HTTP/2 path validation)] by upgrading google.golang.org/grpc dependcy to 1.79.3
Have you updated the necessary documentation?
N/A
Which issue(s) this PR fixes:
https://redhat.atlassian.net/browse/GITOPS-9319
How to test changes / Special notes to the reviewer:
other dependency changes are from
go mod tidy