[Project Darkstar] ROSAENG-63319: Remediate 4 CVEs in splunk-forwarder-operator - #468
Conversation
…25.12 + bump UBI base image Addresses CVE-2026-39822, CVE-2026-42505 (Go stdlib) and CVE-2026-54369, CVE-2026-5435 (RPM-level via UBI base image update). UBI 9.8-1784705586 → 9.8-1785777232. Ref: ROSAENG-63319 Project Darkstar — automated CVE remediation (contact: Kevin Seiter)
|
@kseiter-rh: This pull request references ROSAENG-63319 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the vulnerability to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Skipping CI for Draft Pull Request. |
|
PR needs rebase. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (1)
WalkthroughThe module configuration adds a Go ChangesGo toolchain configuration
Estimated code review effort: 1 (Trivial) | ~2 minutes Possibly related PRs
Suggested reviewers: Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error)
✅ Passed checks (14 passed)
✨ Finishing Touches 💡 2⚔️ Resolve merge conflicts 💡
🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 golangci-lint (2.12.2)Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: kseiter-rh The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
[Project Darkstar] ROSAENG-63319: Remediate CVEs in splunk-forwarder-operator
Changes
toolchain go1.25.12to go.mod (fixes Go stdlib CVEs)9.8-1784705586→9.8-17857772329.8-1784705586→9.8-1785777232Fixed — Go stdlib (2 CVEs)
Fixed — Base Image (2 CVEs)
Not In This PR
No Fix Available
About Project Darkstar
Summary by CodeRabbit