Skip to content

Conversation

@blewis12
Copy link
Member

Cherry picks #7243 and #7245 to the v0.44 release branch, in order to address some outgoing CVE's

* CVE-2025-52881 => bump selinux to v1.13.0

* CVE-2025-68156 => bump expr-lang/expr to v1.17.7

* CVE-2025-61727 and CVE-2025-61729 => bump Go version to 1.24.11 in build images

Once this is deployed we can update the go version in go.mod and other remaining spots

* Downgrade github.com/stretchr/testify back to v1.10.0 to address failing tests

testify was for some reason bumped with the selinux bump, it seems to be causing test failures

* Downgrade github.com/cyphar/filepath-securejoin back to v0.3.6

The changelog for v0.5.0 seems like there are some more significant changes, so would rather keep this at the previous version if possible
* update go version to 1.24.11

* Update build image version
@blewis12 blewis12 requested a review from jharvey10 January 21, 2026 15:58
Copy link
Contributor

@jharvey10 jharvey10 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@blewis12 blewis12 merged commit 7a76f39 into release-v0.44 Jan 21, 2026
58 checks passed
@blewis12 blewis12 deleted the blewis12/cherry-pick-to-v0.44 branch January 21, 2026 17:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants