Skip to content

Comments

[release-1.33] Do Not Merge - revert crypto bump and use OCP crypto branch#6694

Open
TomSweeneyRedHat wants to merge 2 commits intocontainers:release-1.33from
TomSweeneyRedHat:dev/tsweeney/ocp_revert
Open

[release-1.33] Do Not Merge - revert crypto bump and use OCP crypto branch#6694
TomSweeneyRedHat wants to merge 2 commits intocontainers:release-1.33from
TomSweeneyRedHat:dev/tsweeney/ocp_revert

Conversation

@TomSweeneyRedHat
Copy link
Member

This reverts 65707d0 from the release-1.33 branch and replaces golang.org/x/crypto with one that the OCP team has worked up to address CVE-2025-47913. This will keep Go at v1.22 in this branch, which is important to the OCP Builder team.

What type of PR is this?

/kind api-change
/kind bug
/kind cleanup
/kind deprecation
/kind design
/kind documentation
/kind failing-test
/kind feature
/kind flake
/kind other

What this PR does / why we need it:

How to verify it

Which issue(s) this PR fixes:

Special notes for your reviewer:

Does this PR introduce a user-facing change?

None

@TomSweeneyRedHat TomSweeneyRedHat added do-not-merge/work-in-progress No New Tests Allow PR to proceed without adding regression tests labels Feb 19, 2026
@dosubot dosubot bot added the size:M This PR changes 30-99 lines, ignoring generated files. label Feb 19, 2026
This reverts commit 2b88f58.

Signed-off-by: Tom Sweeney <tsweeney@redhat.com>
Use the golang.org/x/crypto library from the OCP team located at:
github.com/openshift/golang-crypto v0.33.1-0.20260212164730-3e9ce6e0b8f5

To try and keep Go at a version that is usable by the OCP team.

Signed-off-by: Tom Sweeney <tsweeney@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do-not-merge/work-in-progress No New Tests Allow PR to proceed without adding regression tests size:M This PR changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant