Commit d9b0f66
fix(cve): CVE-2026-32280, CVE-2026-32281 - update Go from 1.25.8 to 1.25.9
- Update Go from 1.25.8 to 1.25.9 to address Go stdlib vulnerabilities
- CVE-2026-32280 (CVSS 7.5 HIGH): crypto/x509 DoS via certificate chain building
All Go versions < 1.25.9 affected; fixed in 1.25.9
- CVE-2026-32281 (CVSS 7.5 HIGH): crypto/x509 DoS via inefficient certificate
chain validation; fixed in Go 1.25.9
Changes:
- go.mod: go 1.25.8 → go 1.25.9
- go mod tidy, go mod verify, go mod vendor completed
Resolves: SRVKP-12045, SRVKP-12003
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: divyansh42 <diagrawa@redhat.com>1 parent d6b0e56 commit d9b0f66
550 files changed
Lines changed: 77186 additions & 1 deletion
File tree
- third_party/VENDOR-LICENSE
- cel.dev/expr
- cloud.google.com/go
- auth
- oauth2adapt
- compute/metadata
- firestore
- iam
- internal
- kms
- longrunning
- monitoring
- storage
- contrib.go.opencensus.io/exporter
- ocagent
- prometheus
- github.com
- AlecAivazis/survey/v2
- terminal
- AliyunContainerService/ack-ram-tool/pkg/credentials/provider
- AzureAD/microsoft-authentication-library-for-go/apps
- Azure
- azure-sdk-for-go
- sdk
- azcore
- azidentity
- internal
- security/keyvault
- azkeys
- internal
- go-autorest
- autorest
- adal
- azure
- auth
- cli
- date
- logger
- tracing
- GoogleCloudPlatform/opentelemetry-operations-go
- detectors/gcp
- exporter/metric
- internal/resourcemapping
- IBM/sarama
- Netflix/go-expect
- alibabacloud-go
- alibabacloud-gateway-spi/client
- cr-20160607/client
- cr-20181201/client
- darabonba-openapi/client
- debug/debug
- endpoint-util/service
- openapi-util/service
- tea-utils/service
- tea-xml/service
- tea
- aliyun/credentials-go/credentials
- antlr4-go/antlr/v4
- asaskevich/govalidator
- awslabs/amazon-ecr-credential-helper/ecr-login
- aws
- aws-sdk-go-v2
- config
- credentials
- feature/ec2/imds
- internal
- configsources
- endpoints/v2
- ini
- sync/singleflight
- service
- ecrpublic
- ecr
- internal
- accept-encoding
- presigned-url
- kms
- signin
- ssooidc
- sso
- sts
- aws-sdk-go
- internal/sync/singleflight
- smithy-go
- internal/sync/singleflight
- beorn7/perks/quantile
- blang/semver
- blendle/zapdriver
- cenkalti/backoff
- v4
- v5
- census-instrumentation/opencensus-proto/gen-go
- cespare/xxhash/v2
- chrismellard/docker-credential-acr-env/pkg
- clbanning/mxj/v2
- clipperhouse
- stringish
- uax29/v2
- cloudevents/sdk-go/v2
- cncf/xds/go
- common-nighthawk/go-figure
- containerd/stargz-snapshotter/estargz
- coreos/go-oidc/v3/oidc
- cpuguy83/go-md2man/md2man
- creack/pty
- cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
- davecgh/go-spew/spew
- digitorus
- pkcs7
- timestamp
- dimchansky/utfbom
- docker
- cli/cli/config
- distribution/registry/client/auth/challenge
- docker-credential-helpers
- docker/pkg/homedir
- dustin/go-humanize
- eapache
- go-resiliency/breaker
- go-xerial-snappy
- queue
- emicklei/go-restful/v3
- envoyproxy
- go-control-plane/envoy
- protoc-gen-validate/validate
- evanphx/json-patch
- v5
- fatih/color
- felixge/httpsnoop
- fsnotify/fsnotify
- fxamacker/cbor/v2
- gdamore
- encoding
- tcell/v2
- go-chi/chi/v5
- go-errors/errors
- go-jose/go-jose/v4
- json
- go-kit/log
- go-logfmt/logfmt
- go-logr
- logr
- stdr
- go-openapi
- analysis
- errors
- jsonpointer
- jsonreference
- loads
- runtime
- middleware/denco
- spec
- strfmt
- swag
- cmdutils
- conv
- fileutils
- jsonname
- jsonutils
- loading
- mangling
- netutils
- stringutils
- typeutils
- yamlutils
- validate
- go-viper/mapstructure/v2
- gogo/protobuf
- golang-jwt/jwt
- v4
- v5
- golang
- groupcache/lru
- protobuf/ptypes
- snappy
- googleapis
- enterprise-certificate-proxy/client
- gax-go/v2
- google
- btree
- cel-go
- certificate-transparency-go
- gnostic-models
- go-cmp/cmp
- go-containerregistry
- pkg/authn
- k8schain
- kubernetes
- go-github/v73/github
- go-querystring/query
- s2a-go
- shlex
- uuid
- wire
- gorilla/websocket
- grafeas/grafeas
- gregjones/httpcache
- grpc-ecosystem/grpc-gateway/v2
- hako/durafmt
- hashicorp
- errwrap
- go-cleanhttp
- go-multierror
- go-retryablehttp
- go-rootcerts
- go-secure-stdlib
- parseutil
- strutil
- go-sockaddr
- go-uuid
- golang-lru
- simplelru
- hcl
- hcl
- ast
- parser
- scanner
- strconv
- token
- json
- parser
- scanner
- token
- vault/api
- cliconfig
- tokenhelper
- hinshun/vt10x
- imdario/mergo
- in-toto
- attestation/go/v1
- in-toto-golang/in_toto
- jcmturner
- aescts/v2
- dnsutils/v2
- gofork
- gokrb5/v8
- rpc/v2
- jedisct1/go-minisign
- jellydator/ttlcache/v3
- jmespath/go-jmespath
- joho/godotenv
- jonboulle/clockwork
- json-iterator/go
- kballard/go-shellquote
- kelseyhightower/envconfig
- klauspost/compress
- internal/snapref
- zstd/internal/xxhash
- ktr0731
- go-ansisgr
- go-fuzzyfinder
- kylelemons/godebug
- letsencrypt/boulder
- core
- proto
- goodkey
- identifier
- probs
- revocation
- liggitt/tabwriter
- lucasb-eyer/go-colorful
- mattn
- go-colorable
- go-isatty
- go-runewidth
- mgutz/ansi
- mitchellh
- go-homedir
- mapstructure
- moby/term
- modern-go
- concurrent
- reflect2
- monochromegane/go-gitignore
- montanaflynn/stats
- mozillazg/docker-credential-acr-helper/pkg
- munnerz/goautoneg
- natefinch/atomic
- nozzle/throttler
- nsf/termbox-go
- oklog/ulid
- opencontainers
- go-digest
- image-spec/specs-go
- opentracing/opentracing-go/log
- openzipkin/zipkin-go/model
- pelletier/go-toml/v2
- peterbourgon/diskv
- pierrec/lz4/v4
- pkg
- browser
- errors
- pmezard/go-difflib/difflib
- prometheus
- client_golang
- internal/github.com/golang/gddo/httputil
- prometheus
- client_model/go
- common
- procfs
- statsd_exporter/pkg
- rcrowley/go-metrics
- russross/blackfriday
- ryanuber/go-glob
- sagikazarmark/locafero
- sassoftware/relic/lib
- secure-systems-lab/go-securesystemslib
- shibumi/go-pathspec
- sigstore
- cosign/v2
- fulcio/pkg/api
- protobuf-specs/gen/pb-go
- rekor-tiles/v2
- rekor/pkg
- sigstore-go/pkg
- sigstore/pkg
- signature/kms
- aws
- azure
- gcp
- hashivault
- timestamp-authority/v2/pkg/verification
- sirupsen/logrus
- sourcegraph/conc
- spf13
- afero
- cast
- cobra
- pflag
- viper
- spiffe/go-spiffe/v2
- stoewer/go-strcase
- subosito/gotenv
- syndtr/goleveldb/leveldb
- tektoncd
- chains
- cli
- hub/api
- pipeline
- triggers
- theupdateframework/go-tuf
- v2/metadata
- titanous/rocacheck
- tjfoc/gmsm/sm3
- transparency-dev
- formats/log
- merkle
- vbatts/tar-split/archive/tar
- x448/float16
- xdg-go
- pbkdf2
- scram
- stringprep
- xlab/treeprint
- youmark/pkcs8
- gitlab.com/gitlab-org/api/client-go
- go.mongodb.org/mongo-driver
- go.opencensus.io
- go.opentelemetry.io
- auto/sdk
- contrib
- detectors/gcp
- instrumentation
- google.golang.org/grpc/otelgrpc
- net/http/otelhttp
- otel
- metric
- sdk
- metric
- trace
- go.starlark.net
- go.uber.org
- multierr
- zap
- go.yaml.in/yaml
- v2
- v3
- goa.design/goa/v3
- gocloud.dev
- docstore/mongodocstore
- pubsub/kafkapubsub
- golang.org/x
- crypto
- exp
- mod
- net
- oauth2
- sync
- sys
- term
- text
- time/rate
- xerrors
- gomodules.xyz/jsonpatch/v2
- google.golang.org
- api
- internal/third_party/uritemplates
- genproto
- googleapis
- api
- rpc
- grpc
- protobuf
- gopkg.in
- evanphx/json-patch.v4
- inf.v0
- ini.v1
- yaml.v2
- gotest.tools
- internal/difflib
- v3
- internal/difflib
- k8s.io
- apiextensions-apiserver/pkg/apis/apiextensions
- apimachinery
- pkg
- third_party/forked/golang
- api
- cli-runtime/pkg
- client-go
- third_party/forked/golang/template
- klog/v2
- kube-openapi/pkg
- internal/third_party/go-json-experiment/json
- validation/spec
- utils
- internal/third_party/forked/golang
- knative.dev
- eventing/pkg/reconciler/source
- networking/pkg
- pkg
- serving/pkg
- sigs.k8s.io
- json
- kustomize
- api
- kyaml
- internal/forked/github.com
- go-yaml/yaml
- qri-io/starlib/util
- randfill
- release-utils/version
- structured-merge-diff/v6
- yaml
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
0 commit comments