[release-3.6] bump dependencies with vulnerabilities - #22365
Conversation
Addresses CVE-2026-56852 / GO-2026-5970. Signed-off-by: Ivan Valdes <ivan@vald.es>
Addresses GHSA-w67g-5rqw-f597 / GO-2026-6278. Signed-off-by: Ivan Valdes <ivan@vald.es>
baa2dfc to
24c5b69
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted filessee 175 files with indirect coverage changes @@ Coverage Diff @@
## release-3.6 #22365 +/- ##
================================================
+ Coverage 56.07% 68.70% +12.63%
================================================
Files 402 417 +15
Lines 34555 35765 +1210
================================================
+ Hits 19376 24573 +5197
+ Misses 13570 9729 -3841
+ Partials 1609 1463 -146 Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
|
/retest |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: fuweid, ivanvc The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
The
govulncheckCI job is failing forrelease-3.6. Refer to: #22356 / https://prow.k8s.io/view/gs/kubernetes-ci-logs/pr-logs/pull/etcd-io_etcd/22356/pull-etcd-govulncheck/2094502728762920960I bumped:
golang.org/x/netto v0.56.0golang.org/x/textto v0.39.0github.com/gorilla/websocketto v1.5.3