SREP-3402 - fix(CVE): Update jose2go to v1.7.0 to fix CVE-2025-63811#895
Conversation
|
Important Review skippedAuto reviews are limited based on label configuration. 🚫 Review skipped — only excluded labels are configured. (1)
Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the Use the checkbox below for a quick retry:
WalkthroughThe pull request updates the Go toolchain version from 1.25.3 to 1.25.7 in both the Dockerfile and go.mod file. Additionally, a dependency on Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
0a40058 to
9a649ad
Compare
Updates github.com/dvsekhvalnov/jose2go from v1.6.0 to v1.7.0. Fixes: - CVE-2025-63811 (High) - GHSA-9mj6-hxhv-w67j SREP-3402
9a649ad to
a1628a5
Compare
|
@MitaliBhalla: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #895 +/- ##
=======================================
Coverage 53.04% 53.04%
=======================================
Files 86 86
Lines 6538 6538
=======================================
Hits 3468 3468
Misses 2609 2609
Partials 461 461 🚀 New features to boost your workflow:
|
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: feichashao, MitaliBhalla The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
What type of PR is this?
bug
What this PR does / Why we need it?
Updates
github.com/dvsekhvalnov/jose2gofrom v1.6.0 to v1.7.0 to fix CVE-2025-63811 (GHSA-9mj6-hxhv-w67j), a High severity vulnerability.Which Jira/Github issue(s) does this PR fix?
SREP-3402
Pre-checks