Skip to content

Commit 478a5b4

Browse files
fix(cloud-provider-gcp-cloud-controller-manager): CVE-2026-39821 35.0.5-r10 (#110155)
* Automated fixes: - CVE-2026-39821: os/cloud-provider-gcp-cloud-controller-manager.yaml - remediate CVE-2026-39821 for cloud-provider-gcp-cloud-controller-manager@35.0.5-r10 * fix(cloud-provider-gcp-cloud-controller-manager): remove incompatible go.opentelemetry.io/otel/sdk@v1.43.0 bump * fix(cloud-provider-gcp-cloud-controller-manager): bump k8s.io/kubernetes to v1.34.2 and update replaces to v0.34.2 * fix(cloud-provider-gcp-cloud-controller-manager): add k8s.io/endpointslice replace directive for v1.34.2 * fix(cloud-provider-gcp-cloud-controller-manager): add k8s.io/externaljwt replace for v1.34.2 * fix(cloud-provider-gcp-cloud-controller-manager): add k8s.io/kms replace directive for v1.34.2 --------- Co-authored-by: cve-remediation <cve-remediation@chainguard.dev> Export: 308f772350a600dc229f33f9ff76f122c8554f4b
1 parent ef09f01 commit 478a5b4

1 file changed

Lines changed: 19 additions & 27 deletions

File tree

cloud-provider-gcp-cloud-controller-manager.yaml

Lines changed: 19 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
package:
22
name: cloud-provider-gcp-cloud-controller-manager
33
version: "35.0.5"
4-
epoch: 10 # toolchain rebuild for go-1.25-1.25.11
4+
epoch: 11 # CVE-2026-39821
55
description: cloud-provider-gcp contains several projects used to run Kubernetes in Google Cloud
66
copyright:
77
- license: Apache-2.0
@@ -19,45 +19,37 @@ pipeline:
1919
tag: ccm/v${{package.version}}
2020
expected-commit: 5ad4222f1d178e1386111fe41f635742b2604567
2121

22-
- uses: go/bump
22+
- uses: bump
2323
with:
2424
deps: |-
2525
google.golang.org/grpc@v1.79.3
26-
modroot: providers
27-
tidy: false
28-
29-
- uses: go/bump
30-
with:
31-
deps: |-
32-
google.golang.org/grpc@v1.79.3
33-
go.opentelemetry.io/otel/sdk@v1.43.0
34-
work: true
26+
k8s.io/kubernetes@v1.34.2
27+
golang.org/x/net@v0.55.0
28+
replaces: |-
29+
k8s.io/mount-utils=k8s.io/mount-utils@v0.34.2
30+
k8s.io/cri-client=k8s.io/cri-client@v0.34.2
31+
k8s.io/dynamic-resource-allocation=k8s.io/dynamic-resource-allocation@v0.34.2
32+
k8s.io/kube-scheduler=k8s.io/kube-scheduler@v0.34.2
33+
k8s.io/csi-translation-lib=k8s.io/csi-translation-lib@v0.34.2
34+
k8s.io/endpointslice=k8s.io/endpointslice@v0.34.2
35+
k8s.io/externaljwt=k8s.io/externaljwt@v0.34.2
36+
k8s.io/kms=k8s.io/kms@v0.34.2
37+
modroot: |-
38+
providers
39+
.
40+
test/e2e
3541
3642
- runs: |
3743
# Explicitly update go.work to use the installed Go version
3844
go work edit -go=$(go version | awk '{print $3}' | sed 's/go//')
3945
40-
- uses: go/bump
41-
with:
42-
deps: |-
43-
k8s.io/kubernetes@v1.33.2
44-
google.golang.org/grpc@v1.79.3
45-
go.opentelemetry.io/otel/sdk@v1.43.0
46-
modroot: test/e2e
47-
replaces: |-
48-
k8s.io/mount-utils=k8s.io/mount-utils@v0.33.3
49-
k8s.io/cri-client=k8s.io/cri-client@v0.33.3
50-
k8s.io/dynamic-resource-allocation=k8s.io/dynamic-resource-allocation@v0.33.3
51-
k8s.io/kube-scheduler=k8s.io/kube-scheduler@v0.33.3
52-
k8s.io/csi-translation-lib=k8s.io/csi-translation-lib@v0.33.3
53-
tidy: false
54-
5546
- uses: go/build
5647
with:
5748
packages: ./cmd/cloud-controller-manager
5849
output: cloud-controller-manager
5950
ldflags: |
6051
-X k8s.io/component-base/version.gitVersion=v${{package.version}}
52+
go-package: go-1.26
6153

6254
subpackages:
6355
- name: ${{package.name}}-compat
@@ -101,4 +93,4 @@ test:
10193
environment:
10294
contents:
10395
packages:
104-
- go-1.25
96+
- go-1.26

0 commit comments

Comments
 (0)