Skip to content

Patch docker-tools: bump Go 1.26.0, Trivy 0.69.1, pip 26.x to fix CVEs#4778

Merged
vizhur merged 2 commits intomainfrom
vizhur/patch-docker-tools-vulns-20260212
Feb 12, 2026
Merged

Patch docker-tools: bump Go 1.26.0, Trivy 0.69.1, pip 26.x to fix CVEs#4778
vizhur merged 2 commits intomainfrom
vizhur/patch-docker-tools-vulns-20260212

Conversation

@vizhur
Copy link
Contributor

@vizhur vizhur commented Feb 12, 2026

Summary

Bumps dependency versions in the docker-tools system environment to resolve 17 vulnerabilities (1 CRITICAL, 6 HIGH, 10 MEDIUM).

Changes

Component Before After Reason
Go 1.25.5 1.26.0 Fixes stdlib CVEs affecting oras binary (CVE-2025-68121 CRITICAL, GO-2026-4340/4341/4342, GO-2025-4007/4155/4175)
Trivy 0.67.2 0.69.1 Fixes Go stdlib, containerd, sigstore, golang.org/x/crypto CVEs in trivy binary
pip 25.* 26.* Fixes CVE-2026-1703 (GHSA-6vgw-5pg2-w6jp)

Resolves 17 vulnerabilities (1 CRITICAL, 6 HIGH, 10 MEDIUM):
- Go stdlib: CVE-2025-68121 (CRITICAL), GO-2026-4340/4341/4342, GO-2025-4007/4155/4175
- containerd: CVE-2024-25621
- golang.org/x/crypto: CVE-2025-58181, CVE-2025-47914
- sigstore components: cosign, rekor, sigstore, timestamp-authority
- pip: CVE-2026-1703

Verified with vcm build+scan: 0 vulnerabilities on 20260212.v2
@github-actions
Copy link

github-actions bot commented Feb 12, 2026

Test Results for assets-test

0 tests   0 ✅  0s ⏱️
0 suites  0 💤
0 files    0 ❌

Results for commit 62b6b3d.

♻️ This comment has been updated with latest results.

@vizhur vizhur merged commit 5840f61 into main Feb 12, 2026
36 checks passed
@vizhur vizhur deleted the vizhur/patch-docker-tools-vulns-20260212 branch February 12, 2026 20:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants