Skip to content

chore: Bump Go to 1.25.8 and update dependencies#51

Merged
MykolaMarusenko merged 1 commit into
mainfrom
bump-versions
Mar 26, 2026
Merged

chore: Bump Go to 1.25.8 and update dependencies#51
MykolaMarusenko merged 1 commit into
mainfrom
bump-versions

Conversation

@SergK

@SergK SergK commented Mar 26, 2026

Copy link
Copy Markdown
Member
  • Upgrade Go version from 1.24.0 to 1.25.8
  • Bump tektoncd/pipeline from 1.6.0 to 1.10.2 (fixes critical path traversal CVE)
  • Bump google.golang.org/grpc to 1.79.3 (fixes critical authorization bypass CVE)
  • Update Operator SDK from 1.41.1 to 1.42.2
  • Update GitHub Actions to latest stable versions:
    • azure/setup-helm: v3 → v4
    • actions/setup-python: v4 → v6
    • helm/chart-testing-action: v2.6.0 → v2.8.0
    • hadolint/hadolint-action: v1.5.0 → v3

@SergK SergK requested a review from a team as a code owner March 26, 2026 15:23
@SergK SergK force-pushed the bump-versions branch 2 times, most recently from 7ffa6aa to 02a34fd Compare March 26, 2026 16:17
  - Upgrade Go version from 1.24.0 to 1.25.8
  - Bump tektoncd/pipeline from 1.6.0 to 1.10.2 (fixes critical
    path traversal CVE)
  - Bump google.golang.org/grpc to 1.79.3 (fixes critical
    authorization bypass CVE)
  - Update Operator SDK from 1.41.1 to 1.42.2
  - Update GitHub Actions to latest stable versions:
    - azure/setup-helm: v3 → v4
    - actions/setup-python: v4 → v6
    - helm/chart-testing-action: v2.6.0 → v2.8.0
    - hadolint/hadolint-action: v1.5.0 → v3

Signed-off-by: Sergiy Kulanov <sergiy_kulanov@epam.com>
@MykolaMarusenko MykolaMarusenko merged commit 5d0b4f1 into main Mar 26, 2026
9 checks passed
@MykolaMarusenko MykolaMarusenko deleted the bump-versions branch March 26, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants