Skip to content

bump: golang.org/x/{net,text} + go 1.27.1 for v1.33.8-alauda-20 - #48

Merged
kycheng merged 1 commit into
AlaudaDevops:alauda-v1.33.7from
kycheng:alauda-20
Sep 14, 2026
Merged

kycheng merged 1 commit into
AlaudaDevops:alauda-v1.33.7from
kycheng:alauda-20

Conversation

@kycheng

@kycheng kycheng commented Sep 14, 2026

Copy link
Copy Markdown
Collaborator

Bumps golang.org/x/net → v0.58.0 and golang.org/x/text → v0.41.0 (via hack/pin-dependency.sh) — the two Go modules trivy 2026-09 flags as fixable on the built kubectl binary. Also bumps go directive to 1.27.1 so release CI ships stdlib CVE fixes (CVE-2026-33818 etc).

vendor/ NOT committed — hack/update-vendor.sh timed out on a transitive network fetch (github.com/coreos/go-systemd via GOPROXY, EOF). Please run hack/update-vendor.sh locally on the CI before cutting the alauda-20 tag.

Requesting cut of v1.33.8-alauda-20 after merge + vendor refresh.

🤖 Generated with Claude Code

Bumps the two Go modules that trivy 2026-09 flags as fixable on
the built kubectl binary via k8s's own hack/pin-dependency.sh
mechanism, the go directive so release CI runs Go 1.27.1
(closes stdlib CVE-2026-33818 etc), and vendor/ is refreshed
via hack/update-vendor.sh:

  golang.org/x/net   -> v0.58.0
  golang.org/x/text  -> v0.41.0
  go directive       1.26.4 -> 1.27.1

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@kycheng
kycheng merged commit 3816f28 into AlaudaDevops:alauda-v1.33.7 Sep 14, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants