OADP-7565: Go 1.25.8 toolchain + golang.org/x/* CVE bumps#159
OADP-7565: Go 1.25.8 toolchain + golang.org/x/* CVE bumps#159
Conversation
- Add toolchain go1.25.8 (fixes GO-2026-4337, GO-2026-4340, GO-2026-4341, GO-2026-4342, CVE-2026-25679, CVE-2026-27137) - golang.org/x/net v0.38.0 → v0.52.0 (fixes GHSA-vvgc-356p-c3xw) - golang.org/x/sys v0.35.0 → v0.42.0 - golang.org/x/text v0.23.0 → v0.35.0 - golang.org/x/term v0.30.0 → v0.41.0 - golang.org/x/mod v0.22.0 → v0.33.0 Generated with [Claude Code](https://claude.ai/code) via [Happy](https://happy.engineering) Co-Authored-By: Claude <noreply@anthropic.com> Co-Authored-By: Happy <yesreply@happy.engineering>
|
@kaovilai: This pull request references OADP-7565 which is a valid jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
There was a problem hiding this comment.
Pull request overview
Updates the module’s Go toolchain configuration and refreshes several golang.org/x/* indirect dependencies to newer versions.
Changes:
- Add a
toolchain go1.25.8directive togo.mod. - Bump indirect
golang.org/x/mod,x/net,x/sys,x/term,x/textversions ingo.mod. - Update
go.sumchecksums to match the upgraded dependencies.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| go.mod | Pins the Go toolchain and updates indirect golang.org/x/* dependency versions. |
| go.sum | Updates dependency checksums to align with the module version bumps. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: kaovilai, mpryc The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Summary
toolchain go1.25.8directive to fix Go stdlib CVEs:golang.org/x/netv0.38.0 → v0.52.0 (fixes GHSA-vvgc-356p-c3xw, XSS in HTML tokenizer)x/sys→ v0.42.0,x/text→ v0.35.0,x/term→ v0.41.0,x/mod→ v0.33.0Note
golang.org/x/cryptois not in this module's dependency graph — those CVEs do not apply here.Test plan
go build ./...passesNote
Responses generated with Claude