Skip to content

fix: CVE-2025-66506 - upgrade cosign to 2.6.2#1528

Merged
anithapriyanatarajan merged 1 commit into
tektoncd:release-v0.20.xfrom
infernus01:cosign-upgrade-v0.20
Feb 3, 2026
Merged

fix: CVE-2025-66506 - upgrade cosign to 2.6.2#1528
anithapriyanatarajan merged 1 commit into
tektoncd:release-v0.20.xfrom
infernus01:cosign-upgrade-v0.20

Conversation

@infernus01
Copy link
Copy Markdown
Member

Changes

Scope of this fix is to address CVE-2025-66506 by upgrading cosign from version 2.6.0 to 2.6.2 which has indirect dependency on fulcio 1.8.4

/kind bug

Submitter Checklist

As the author of this PR, please check off the items in this checklist:

  • Has Docs included if any changes are user facing
  • Has Tests included if any functionality added or changed
  • Follows the commit message standard
  • Meets the Tekton contributor standards (including
    functionality, content, code)
  • Release notes block below has been updated with any user facing changes (API changes, bug fixes, changes requiring upgrade notices or deprecation warnings)
  • Release notes contains the string "action required" if the change requires additional action from users switching to the new release

Release Notes

NONE

@tekton-robot tekton-robot added the kind/bug Categorizes issue or PR as related to a bug. label Jan 23, 2026
@tekton-robot tekton-robot added the size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. label Jan 23, 2026
@anithapriyanatarajan
Copy link
Copy Markdown
Contributor

/ok-to-test

@anithapriyanatarajan
Copy link
Copy Markdown
Contributor

/hold

@tekton-robot tekton-robot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jan 27, 2026
@anithapriyanatarajan
Copy link
Copy Markdown
Contributor

/ok-to-test

@anithapriyanatarajan
Copy link
Copy Markdown
Contributor

/hold cancel

@tekton-robot tekton-robot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Feb 2, 2026
@vdemeester
Copy link
Copy Markdown
Member

@anithapriyanatarajan it probably will need a rebase to pickup the fixes in #1542.

@tekton-robot tekton-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Feb 2, 2026
@anithapriyanatarajan
Copy link
Copy Markdown
Contributor

@infernus01 could you rebase

@infernus01 infernus01 force-pushed the cosign-upgrade-v0.20 branch from 9d0ac0b to eca9dd1 Compare February 3, 2026 09:17
@tekton-robot tekton-robot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Feb 3, 2026
@infernus01 infernus01 force-pushed the cosign-upgrade-v0.20 branch from eca9dd1 to aea7ee6 Compare February 3, 2026 09:39
Signed-off-by: Shubham Bhardwaj <shubbhar@redhat.com>
@infernus01 infernus01 force-pushed the cosign-upgrade-v0.20 branch from aea7ee6 to 8326a4f Compare February 3, 2026 09:43
@anithapriyanatarajan
Copy link
Copy Markdown
Contributor

/approve

@anithapriyanatarajan
Copy link
Copy Markdown
Contributor

/lgtm

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Feb 3, 2026
@anithapriyanatarajan
Copy link
Copy Markdown
Contributor

/approve
/lgtm

@tekton-robot
Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: anithapriyanatarajan
To complete the pull request process, please assign wlynch after the PR has been reviewed.
You can assign the PR to them by writing /assign @wlynch in a comment when ready.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@anithapriyanatarajan anithapriyanatarajan merged commit 9343090 into tektoncd:release-v0.20.x Feb 3, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/bug Categorizes issue or PR as related to a bug. lgtm Indicates that a PR is ready to be merged. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants