Skip to content

HYPERFLEET-846 - fix: bump google.golang.org/grpc to v1.79.3 for CVE-2026-33186 (#95)#100

Open
86254860 wants to merge 1 commit intoopenshift-hyperfleet:release-0.2from
86254860:cherry-pick-95-to-release-0.2
Open

HYPERFLEET-846 - fix: bump google.golang.org/grpc to v1.79.3 for CVE-2026-33186 (#95)#100
86254860 wants to merge 1 commit intoopenshift-hyperfleet:release-0.2from
86254860:cherry-pick-95-to-release-0.2

Conversation

@86254860
Copy link
Copy Markdown
Contributor

@86254860 86254860 commented Apr 8, 2026

This is an manually cherry-pick of #95

/assign 86254860

…2026-33186 (openshift-hyperfleet#95)

- Bumps `google.golang.org/grpc` from v1.79.2 to v1.79.3 to remediate
CVE-2026-33186 (CVSS 9.1 - authorization bypass via missing leading
slash in `:path`)
- See also: openshift-hyperfleet/hyperfleet-sentinel PR for the same fix

- [x] `go build ./...` passes
- [x] Unit tests pass
- [ ] CI pipeline passes

Relates to:
[HYPERFLEET-846](https://redhat.atlassian.net/browse/HYPERFLEET-846)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

* **Chores**
  * Updated a dependency to the latest version.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented Apr 8, 2026

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign yasun1 for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai
Copy link
Copy Markdown

coderabbitai bot commented Apr 8, 2026

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a4f1ad32-0771-472f-9648-74e4962ac1a7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands and usage tips.

@86254860
Copy link
Copy Markdown
Contributor Author

86254860 commented Apr 8, 2026

/test images-images

@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented Apr 8, 2026

@86254860: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/presubmits-integration 89a895e link true /test presubmits-integration
ci/prow/images-images 89a895e link true /test images-images

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant