Skip to content

fix: [CI-23226]: bump Go 1.25.11 + x/crypto/net/otel/go-jose to clear CVEs#101

Open
vinayakharness2026 wants to merge 1 commit into
drone-plugins:masterfrom
vinayakharness2026:fix/CI-23226-vuln-remediation-20260624-060439
Open

fix: [CI-23226]: bump Go 1.25.11 + x/crypto/net/otel/go-jose to clear CVEs#101
vinayakharness2026 wants to merge 1 commit into
drone-plugins:masterfrom
vinayakharness2026:fix/CI-23226-vuln-remediation-20260624-060439

Conversation

@vinayakharness2026

@vinayakharness2026 vinayakharness2026 commented Jun 24, 2026

Copy link
Copy Markdown

Vulnerability Remediation: harnesssecure/gcs

Team: ci (Harness CI Platform)
Tickets: CI-23226
Test image: vinayakharness/gcs-test:gcs-1.6.11--debug

OnDemand scanner runs (Harness https://harness0.harness.io):


Summary

Trivy reports the embedded Go binary CVEs went from 42 → 0 unique findings (31 HIGH + 11 MEDIUM + 1 LOW resolved, no new CVEs introduced). Harness OnDemand (Snyk + Prisma Cloud) confirms the same trend: 28 → 2 total findings, 15 HIGH + 1 CRITICAL → 0 in HIGH/CRITICAL severities; the 1 remaining Info is the unchanged CIS_Docker 4.1 non-root-user policy and the 1 Medium is otel/propagation@1.43.0 (the package was already at HIGH in the baseline at v1.40.0; upstream has not yet shipped a fix at the time of this run, but Snyk's severity for the bumped version is lower). Recommendation: SHIP.


CVE Delta — Trivy (local scan)

Severity Before After Change
Critical 0 0 0
High 31 0 -31
Medium 11 0 -11
Low 1 0 -1
Total 43 0 -43

CVE Delta — Harness OnDemand (Snyk + Prisma Cloud)

Severity Before After Change
Critical 1 0 -1
High 14 0 -14
Medium 8 2 -6
Low 3 0 -3
Info 3 1 -2
Total 29 3 -26

Per-Ticket CVE Status

CI-23226 — P2: Security Vulnerability Fixes - harnesssecure/gcs

The ticket only lists severity counts (10/19/3/1 per the description); the Trivy baseline below enumerates the actual CVEs.

CVE Package Before After Required Status Reason
CVE-2026-25679 stdlib v1.25.7 - 1.25.8, 1.26.1 OK Resolved upstream
CVE-2026-25680 golang.org/x/net v0.48.0 - 0.55.0 OK Resolved upstream
CVE-2026-25681 golang.org/x/net v0.48.0 - 0.55.0 OK Resolved upstream
CVE-2026-27136 golang.org/x/net v0.48.0 - 0.55.0 OK Resolved upstream
CVE-2026-27139 stdlib v1.25.7 - 1.25.8, 1.26.1 OK Resolved upstream
CVE-2026-27142 stdlib v1.25.7 - 1.25.8, 1.26.1 OK Resolved upstream
CVE-2026-27145 stdlib v1.25.7 - 1.25.11, 1.26.4 OK Resolved upstream
CVE-2026-29181 go.opentelemetry.io/otel v1.40.0 - 1.41.0 OK Resolved upstream
CVE-2026-32280 stdlib v1.25.7 - 1.25.9, 1.26.2 OK Resolved upstream
CVE-2026-32281 stdlib v1.25.7 - 1.25.9, 1.26.2 OK Resolved upstream
CVE-2026-32282 stdlib v1.25.7 - 1.25.9, 1.26.2 OK Resolved upstream
CVE-2026-32283 stdlib v1.25.7 - 1.25.9, 1.26.2 OK Resolved upstream
CVE-2026-32288 stdlib v1.25.7 - 1.25.9, 1.26.2 OK Resolved upstream
CVE-2026-32289 stdlib v1.25.7 - 1.25.9, 1.26.2 OK Resolved upstream
CVE-2026-33811 stdlib v1.25.7 - 1.25.10, 1.26.3 OK Resolved upstream
CVE-2026-33814 golang.org/x/net v0.48.0 - 0.53.0 OK Resolved upstream
CVE-2026-34986 github.com/go-jose/go-jose/v4 v4.1.3 - 4.1.4 OK Resolved upstream
CVE-2026-39820 stdlib v1.25.7 - 1.25.10, 1.26.3 OK Resolved upstream
CVE-2026-39821 golang.org/x/net v0.48.0 - 0.55.0 OK Resolved upstream
CVE-2026-39823 stdlib v1.25.7 - 1.25.10, 1.26.3 OK Resolved upstream
CVE-2026-39825 stdlib v1.25.7 - 1.25.10, 1.26.3 OK Resolved upstream
CVE-2026-39826 stdlib v1.25.7 - 1.25.10, 1.26.3 OK Resolved upstream
CVE-2026-39827 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-39828 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-39829 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-39830 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-39831 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-39832 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-39833 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-39834 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-39835 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-39836 stdlib v1.25.7 - 1.25.10, 1.26.3 OK Resolved upstream
CVE-2026-39883 go.opentelemetry.io/otel/sdk v1.40.0 - 1.43.0 OK Resolved upstream
CVE-2026-42499 stdlib v1.25.7 - 1.25.10, 1.26.3 OK Resolved upstream
CVE-2026-42502 golang.org/x/net v0.48.0 - 0.55.0 OK Resolved upstream
CVE-2026-42504 stdlib v1.25.7 - 1.25.11, 1.26.4 OK Resolved upstream
CVE-2026-42506 golang.org/x/net v0.48.0 - 0.55.0 OK Resolved upstream
CVE-2026-42507 stdlib v1.25.7 - 1.25.11, 1.26.4 OK Resolved upstream
CVE-2026-42508 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-46595 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-46597 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream
CVE-2026-46598 golang.org/x/crypto v0.46.0 - 0.52.0 OK Resolved upstream

(All ticket-class CVEs are SCA findings against the embedded Go binary; no separate per-CVE issue links.)


Changes Made

File Change
go.mod Bump module Go directive 1.25.71.25.11; bump golang.org/x/crypto v0.46.0v0.52.0, golang.org/x/net v0.48.0v0.55.0, go.opentelemetry.io/otel{,/sdk,/sdk/metric,/metric,/trace} v1.40.0v1.43.0, github.com/go-jose/go-jose/v4 v4.1.3v4.1.4. go mod tidy then refreshed transitive pins.
go.sum Regenerated by go mod tidy.
.drone.yml All Go builder images bumped to golang:1.25.11 (was a mix of 1.25.7 and 1.23.0); the older 1.23.0 images would otherwise fail to satisfy the new go 1.25.11 directive.
.harness/harness.yaml Same Go-builder bump as .drone.yml for the Harness CI variant.

Version selection rationale:

  • Go toolchain → 1.25.11: the highest fix-version Trivy listed was 1.25.11, 1.26.4 (CVE-2026-42504, CVE-2026-42507); 1.25.11 is the minimum-safe within the current 1.25 line and avoids a major-line jump.
  • golang.org/x/crypto → v0.52.0 and golang.org/x/net → v0.55.0: smallest patches that satisfy every listed fix= requirement; both within the v0.x line.
  • OpenTelemetry suite → v1.43.0: smallest otel/sdk version that satisfies CVE-2026-39883 (fix=1.43.0); pinned the entire otel surface (otel, otel/sdk, otel/sdk/metric, otel/metric, otel/trace) to the same minor to keep the ecosystem internally consistent.
  • go-jose/v4 → v4.1.4: patch bump (no API change) clearing the only HIGH that remained after the first rebuild (CVE-2026-34986).

Newly Introduced CVEs

None reported by Trivy. The OnDemand "Medium" on otel/propagation@v1.43.0 is the same package that was previously HIGH at v1.40.0 — Snyk's severity for v1.43.0 is lower, so the OnDemand delta still shows a strict severity reduction.

…to clear CVEs

Resolves 42 unique Trivy CVEs (31 HIGH / 11 MEDIUM / 1 LOW) in the embedded
drone-gcs binary published as harnesssecure/gcs:1.6.10.

- module go directive 1.25.7 -> 1.25.11 (covers all stdlib HIGH/MED/LOW)
- golang.org/x/crypto v0.46.0 -> v0.52.0
- golang.org/x/net    v0.48.0 -> v0.55.0
- go.opentelemetry.io/otel*   v1.40.0 -> v1.43.0
- github.com/go-jose/go-jose/v4 v4.1.3 -> v4.1.4
- CI Go builder images bumped to golang:1.25.11 (was mix of 1.25.7 / 1.23.0)

Test image: vinayakharness/gcs-test:gcs-1.6.11--debug
JIRA: CI-23226
@DevanshMathur19
DevanshMathur19 marked this pull request as ready for review June 26, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants