Skip to content

[deckhouse-cli] Bump vulnerable dependencies for the 0.34 line - #503

Merged
yalosev merged 1 commit into
mainfrom
chore/fix-sigstore-cves
Oct 6, 2026
Merged

yalosev merged 1 commit into
mainfrom
chore/fix-sigstore-cves

Conversation

@Glitchy-Sheep

@Glitchy-Sheep Glitchy-Sheep commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Address CVEs reported in the signing dependencies of the bundled d8 binary. The next 0.34.x patch will be pinned in Deckhouse main.

Bumps

  • github.com/go-chi/chi/v5: v5.2.3 -> v5.3.0
  • github.com/sigstore/fulcio: v1.8.4 -> v1.8.6
  • github.com/sigstore/rekor: v1.4.3 -> v1.5.2
  • github.com/sigstore/sigstore: v1.10.3 -> v1.10.8
  • github.com/sigstore/sigstore-go: v1.1.4 -> v1.2.1
  • github.com/sigstore/timestamp-authority/v2: v2.0.3 -> v2.1.2
  • github.com/theupdateframework/go-tuf/v2: v2.3.0 -> v2.4.2-0.20260407074541-7e8f69f906ef

Includes the related dependency updates required by these versions.

Tests

  • task build on macOS arm64

  • task build:dev:linux:amd64:cross with CGO disabled

  • Go tests with dev build tags; color tests rerun with NO_COLOR unset

  • go mod verify and go mod tidy -diff

  • d8 tools cosign version and d8 tools cosign --help

  • CI tests and PR build passed.

  • CI trdl release build passed, including Linux CGO/GOST.

Release publication and final image scans are pending.

Signed-off-by: Roman Berezkin <roman.berezkin@flant.com>
@yalosev
yalosev merged commit 94cd265 into main Oct 6, 2026
10 checks passed
@yalosev
yalosev deleted the chore/fix-sigstore-cves branch October 6, 2026 15:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants