From 341ab2601408637f8d05f958b0f4312144b05a0a Mon Sep 17 00:00:00 2001 From: sraybee Date: Wed, 29 Apr 2026 03:14:07 +0530 Subject: [PATCH] CBP-41330: Upgrade Go stdlib to 1.26.2 to mitigate CVE-2026-27143 --- .github/workflows/ci.yaml | 2 +- Dockerfile | 2 +- Dockerfile-refresher | 2 +- go.mod | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index c757ed0..8ce1735 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -6,7 +6,7 @@ on: pull_request: env: - GO_VERSION: '1.26.0' + GO_VERSION: '1.26.2' permissions: contents: read diff --git a/Dockerfile b/Dockerfile index 8901515..3a3b84b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -3,7 +3,7 @@ ARG GID=1000 FROM --platform=$BUILDPLATFORM tonistiigi/xx:1.2.1@sha256:8879a398dedf0aadaacfbd332b29ff2f84bc39ae6d4e9c0a1109db27ac5ba012 AS xx -FROM --platform=$BUILDPLATFORM golang:1.26.0-alpine3.22 AS builder +FROM --platform=$BUILDPLATFORM golang:1.26.2-alpine3.22 AS builder ARG UID ARG GID diff --git a/Dockerfile-refresher b/Dockerfile-refresher index a0dcdb6..b5b1e5e 100644 --- a/Dockerfile-refresher +++ b/Dockerfile-refresher @@ -3,7 +3,7 @@ ARG GID=1000 FROM --platform=$BUILDPLATFORM tonistiigi/xx:1.2.1@sha256:8879a398dedf0aadaacfbd332b29ff2f84bc39ae6d4e9c0a1109db27ac5ba012 AS xx -FROM --platform=$BUILDPLATFORM golang:1.26.0-alpine3.22 AS builder +FROM --platform=$BUILDPLATFORM golang:1.26.2-alpine3.22 AS builder ARG UID ARG GID diff --git a/go.mod b/go.mod index b952c7e..d3fa06c 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module github.com/banzaicloud/imps -go 1.26.0 +go 1.26.2 replace ( k8s.io/api => k8s.io/api v0.31.0