From 5ec6e644760c8b7833222dedb6d112e8744f8dea Mon Sep 17 00:00:00 2001 From: ydiakov Date: Fri, 25 Sep 2026 14:06:58 +0800 Subject: [PATCH] ROSAENG-66312: raise Go floor to 1.26.6 for stdlib CVE remediation The shipped image's binary was built with go1.26.5, which leaves 8 Important Go stdlib CVEs open (CVE-2026-56860, -33818, -46600, -56858, -56862, -56853, -56859, -39821), all fixed in Go 1.26.6. Raise the go directive to 1.26.6 so a builder below the CVE floor fails the build instead of silently producing a vulnerable binary. The go directive is what enforces this: the Konflux builder sets GOTOOLCHAIN=local, under which the toolchain directive is ignored entirely and only the go directive is checked. go mod tidy drops the now-redundant toolchain line. Also switch the BASE_IMAGE default to the floating ubi9/go-toolset:1.26 tag so local `make build-image` tracks Red Hat's z-stream updates rather than drifting behind, which is how the previous 1.26.3 pin fell four z-streams below CI. Konflux overrides BASE_IMAGE via build-args and already resolves to go1.26.7. Co-Authored-By: Claude Opus 5 --- build/Dockerfile | 2 +- go.mod | 4 +--- 2 files changed, 2 insertions(+), 4 deletions(-) diff --git a/build/Dockerfile b/build/Dockerfile index aa7640aa..74e647ad 100644 --- a/build/Dockerfile +++ b/build/Dockerfile @@ -1,4 +1,4 @@ -ARG BASE_IMAGE=registry.access.redhat.com/ubi9/go-toolset:1.26.3-1780490420 +ARG BASE_IMAGE=registry.access.redhat.com/ubi9/go-toolset:1.26 FROM ${BASE_IMAGE} AS builder WORKDIR /opt/app-root/src diff --git a/go.mod b/go.mod index dd6af140..03ad755b 100644 --- a/go.mod +++ b/go.mod @@ -1,8 +1,6 @@ module github.com/openshift/managed-cluster-validating-webhooks -go 1.26.0 - -toolchain go1.26.5 +go 1.26.6 require ( github.com/evanphx/json-patch v5.9.11+incompatible