From 597ee95e7359587168e4d3c10e4e3d5d305b01f0 Mon Sep 17 00:00:00 2001 From: Divyanshu Agrawal Date: Fri, 3 Jul 2026 08:00:25 +0000 Subject: [PATCH] fix(cve): CVE-2026-33811, CVE-2026-39833 - update Go stdlib and x/crypto - Update Go stdlib from 1.25.9 to 1.25.11 Addresses CVE-2026-33811 (DoS via long CNAME response in net.LookupCNAME) - Update golang.org/x/crypto from v0.46.0 to v0.52.0 Addresses CVE-2026-39833 (security bypass in ssh/agent key confirmation) - Also upgrades transitive deps: x/net, x/sync, x/sys, x/term, x/text Resolves: SRVKP-12558, SRVKP-12570 Co-Assisted-By: Claude Sonnet 4.6 Signed-off-by: Divyanshu Agrawal --- go.mod | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/go.mod b/go.mod index 3bdcc500eb..2f717c1ce9 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module github.com/tektoncd/cli -go 1.25.10 +go 1.25.11 require ( github.com/AlecAivazis/survey/v2 v2.3.7