Skip to content

security: upgrade golang to 1.25.7 to fix CVE-2025-61732#750

Merged
liamfallon merged 2 commits intokptdev:mainfrom
Nordix:bump-go
Feb 18, 2026
Merged

security: upgrade golang to 1.25.7 to fix CVE-2025-61732#750
liamfallon merged 2 commits intokptdev:mainfrom
Nordix:bump-go

Conversation

@liamfallon
Copy link
Contributor

@liamfallon liamfallon commented Feb 16, 2026

This PR upgrades the kptdev SDK and base images to version 1.25.7 to fix CVE-2025-61732

Signed-off-by: liamfallon <liam.fallon@est.tech>
Copilot AI review requested due to automatic review settings February 16, 2026 09:56
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR attempts to upgrade Go to version 1.25.7 across the kptdev SDK and base images to address CVE-2025-61732 (referenced via GHSA-8jvr-vh7g-f8gx). However, there is a critical issue: Go version 1.25.7 does not exist. As of January 2025, the Go language has only released versions up to the 1.23.x series.

Changes:

  • Updated Go version directive from 1.25.6 to 1.25.7 in multiple go.mod files
  • Updated Dockerfile base image from golang:1.25-alpine3.23 to golang:1.25.7-alpine3.23
  • Updated various transitive dependencies in go.sum files as a result of the version change

Reviewed changes

Copilot reviewed 6 out of 10 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
go/kfn/go.mod Updates Go version to non-existent 1.25.7
go/kfn/commands/embed/Dockerfile Updates base image to non-existent golang:1.25.7-alpine3.23
go/get-started/go.sum Updates transitive dependency checksums
go/get-started/go.mod Updates Go version to non-existent 1.25.7 and updates indirect dependencies
go/fn/internal/test/go.sum Updates transitive dependency checksums
go/fn/internal/test/go.mod Updates Go version to non-existent 1.25.7 and updates indirect dependencies
go/fn/go.sum Updates transitive dependency checksums
go/fn/go.mod Updates Go version to non-existent 1.25.7 and updates direct/indirect dependencies
go/fn/examples/go.sum Updates transitive dependency checksums
go/fn/examples/go.mod Updates Go version to non-existent 1.25.7 and updates indirect dependencies

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Signed-off-by: liamfallon <liam.fallon@est.tech>
@liamfallon liamfallon merged commit b371169 into kptdev:main Feb 18, 2026
6 checks passed
@liamfallon liamfallon deleted the bump-go branch February 18, 2026 08:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants