Skip to content

fix(security): remediate CVE vulnerabilities in Go stdlib - #348

Merged
ulucinar merged 1 commit into
release-0.10from
fix/cve-remediation-release-0.10-20260825-091258
Aug 25, 2026
Merged

fix(security): remediate CVE vulnerabilities in Go stdlib#348
ulucinar merged 1 commit into
release-0.10from
fix/cve-remediation-release-0.10-20260825-091258

Conversation

@upbound-bot

Copy link
Copy Markdown

Summary

This PR fixes CVE vulnerabilities identified by security scanning.

Vulnerabilities Fixed

CVE/GHSA Severity Package Fixed Version
GO-2026-5026 High stdlib go1.25.13
GO-2026-5972 High stdlib go1.25.13
GO-2026-6088 High stdlib go1.25.13
GO-2026-6089 High stdlib go1.25.13
GO-2026-6090 High stdlib go1.25.13
GO-2026-6218 Medium stdlib go1.25.13
GO-2026-6091 Medium stdlib go1.25.13

Changes Made

  • Updated Go version from 1.25.12 to 1.25.13 in go.mod
  • Updated CI workflow Go version to 1.25.13 in .github/workflows/ci.yml
  • Ran go mod tidy to update dependencies

References

Verification

  • Rescanned with cve-scan skill after fixes
  • All listed vulnerabilities resolved

- Update Go version to 1.25.13 (fixes GO-2026-5026, GO-2026-5972, GO-2026-6088, GO-2026-6089, GO-2026-6090, GO-2026-6218, GO-2026-6091)
- Update CI workflow Go version to 1.25.13

Signed-off-by: Alper Rifat Ulucinar <ulucinar@users.noreply.github.com>
@ulucinar
ulucinar merged commit 75229ee into release-0.10 Aug 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants