Skip to content

cve fix gameday#1310

Open
yangspirit wants to merge 5 commits into
GoogleCloudPlatform:release-1.17from
yangspirit:release-1.17.9-gke
Open

cve fix gameday#1310
yangspirit wants to merge 5 commits into
GoogleCloudPlatform:release-1.17from
yangspirit:release-1.17.9-gke

Conversation

@yangspirit
Copy link
Copy Markdown
Member

What type of PR is this?

Uncomment only one /kind <> line, hit enter to put that in a new line, and remove leading whitespaces from that line:

/kind api-change
/kind bug
/kind cleanup
/kind design
/kind documentation
/kind failing-test
/kind feature
/kind flake

What this PR does / why we need it:

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

Does this PR introduce a user-facing change?:


Automation Bot and others added 5 commits February 20, 2026 04:16
Image group: oss-golang
- Image: google-go.pkg.dev/golang
  Status: updated
  Before: 1.24.3
  After: 1.24.13@sha256:2ea380febc64f22355a66fd6141eb6575276b3ec45c97c1594f657bc47b60e60
  - cmd/csi_driver/Dockerfile
  - cmd/metadata_prefetch/Dockerfile
  - cmd/sidecar_mounter/Dockerfile
  - cmd/webhook/Dockerfile

Image group: debian-base
- Image: gcr.io/gke-release/debian-base
  Status: updated
  Before: bookworm-v1.0.2-gke.2
  After: bookworm-v1.0.7-gke.2@sha256:1c204d6571a2add77c003188a8e72efd4e1c9e0d73dd1045eeef30b3a81adddc
  - cmd/csi_driver/Dockerfile
  - cmd/metadata_prefetch/Dockerfile


Target Images: gcs-fuse-csi-driver-webhook; gcs-fuse-csi-driver-sidecar-mounter; gcs-fuse-csi-driver

RELEASE_NOTE=None
VMW_RELEASE_NOTE=None
BM_RELEASE_NOTE=None

This CL is managed by Auto-VC and will be updated automatically as newer image versions appear. It is tracked through hashtags; modifying or removing them will disconnect it from the automation and result in Auto-VC creating a new CL.
Visit go/auto-vc to learn more about Auto-VC.

NoBug: image bump by auto-vc

Change-Id: Id0a1a0b5cce530dcbb942cde8995de4aed825159
- Bump "go.opentelemetry.io/otel/sdk" from "v1.36.0" to "v1.40.0" to fix "GO-2026-4394"
- Bump "golang.org/x/crypto" from "v0.38.0" to "v0.45.0" to fix "GO-2025-4134"
- Bump "golang.org/x/net" from "v0.40.0" to "v0.45.0" to fix "GO-2026-4440"
Target Images: gcs-fuse-csi-driver-webhook; gcs-fuse-csi-driver-sidecar-mounter; gcs-fuse-csi-driver

RELEASE_NOTE=None
VMW_RELEASE_NOTE=None
BM_RELEASE_NOTE=None

This CL is managed by Auto-VC and will be updated automatically as newer image versions appear. It is tracked through hashtags; modifying or removing them will disconnect it from the automation and result in Auto-VC creating a new CL.
Visit go/auto-vc to learn more about Auto-VC.

NoBug: image bump by auto-vc

Change-Id: I6a5c12ae672425703cca6d0000db98ec107b4bc2
- Bump "google.golang.org/grpc" from "v1.72.1" to "v1.79.3" to fix "GO-2026-4762"
Target Images: gcs-fuse-csi-driver-webhook; gcs-fuse-csi-driver-sidecar-mounter; gcs-fuse-csi-driver

RELEASE_NOTE=None
VMW_RELEASE_NOTE=None
BM_RELEASE_NOTE=None

This CL is managed by Auto-VC and will be updated automatically as newer image versions appear. It is tracked through hashtags; modifying or removing them will disconnect it from the automation and result in Auto-VC creating a new CL.
Visit go/auto-vc to learn more about Auto-VC.

NoBug: image bump by auto-vc

Change-Id: Id8a34d938a9c0aa2a36c185e30baa7661ed4ae77
@google-cla
Copy link
Copy Markdown

google-cla Bot commented Apr 15, 2026

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@google-oss-prow
Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: yangspirit

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@gemini-code-assist
Copy link
Copy Markdown

Note

The number of changes in this pull request is too large for Gemini Code Assist to generate a review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants