Skip to content

fix: fix main vulnerabilities - #1944

Merged
bernot-dev merged 1 commit into
mainfrom
bwplotka/main-gmpctl-vulnfix
Jun 3, 2026
Merged

fix: fix main vulnerabilities#1944
bernot-dev merged 1 commit into
mainfrom
bwplotka/main-gmpctl-vulnfix

Conversation

@bwplotka

@bwplotka bwplotka commented Jun 3, 2026

Copy link
Copy Markdown
Collaborator

Updating Go and image vulnerabilities using

./gmpctl.sh vulnfix

@bwplotka
bwplotka requested a review from bernot-dev June 3, 2026 13:34

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Go base image version from 1.26.3 to 1.26.4 across several Dockerfiles, bumps the golang.org/x/crypto dependency to v0.52.0, and updates the bash image tag in the Helm values. Feedback was given to wrap the new bash image tag in double quotes to prevent it from being parsed as a number, adhering to the configuration file's explicit instructions.

Comment thread charts/values.global.yaml
@bwplotka

bwplotka commented Jun 3, 2026

Copy link
Copy Markdown
Collaborator Author

govulncheck seems to fail because Go action has an old Go version (actions/setup-go@v5.0.0)

Signed-off-by: bwplotka <bwplotka@gmail.com>

push CI
@bernot-dev
bernot-dev force-pushed the bwplotka/main-gmpctl-vulnfix branch from 0b6ab73 to ea361e1 Compare June 3, 2026 22:03
@bernot-dev
bernot-dev enabled auto-merge (rebase) June 3, 2026 22:15
@bernot-dev
bernot-dev merged commit f18f4b8 into main Jun 3, 2026
43 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants