OCPBUGS-94907: Bump golang.org/x/net to openshift-sustaining/net v0.50.0-sec.2 - #2350
OCPBUGS-94907: Bump golang.org/x/net to openshift-sustaining/net v0.50.0-sec.2#2350MrSanketkumar wants to merge 1 commit into
Conversation
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
|
@MrSanketkumar: This pull request references Jira Issue OCPBUGS-94907, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
WalkthroughChangesGo dependency updates
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 inconclusive)
✅ Passed checks (14 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: MrSanketkumar The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@go.mod`:
- Around line 205-206: Document an approved exception for the golang.org/x/net
replacement with github.com/openshift-sustaining/net v0.50.0-sec.2, covering
license compatibility, CVE status, SBOM/provenance, artifact signing, and vendor
resolution. Retain the replace directive because the upstream v0.55.0
requirement is incompatible with this module’s Go 1.24 version.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: cbd6036a-9a11-439a-87c6-3fa2c59801f3
⛔ Files ignored due to path filters (138)
go.sumis excluded by!**/*.sumvendor/golang.org/x/crypto/openpgp/s2k/s2k.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/salsa20/salsa/hsalsa20.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/scrypt/scrypt.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/doc.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/hashes.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/hashes_noasm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/keccakf_amd64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/keccakf_amd64.sis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/legacy_hash.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/legacy_keccakf.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/sha3_s390x.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/sha3_s390x.sis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/shake.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/sha3/shake_noasm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/context/context.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/escape.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/node.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/nodetype_string.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/parse.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/render.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go126.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go127.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/config.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/config_go124.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/config_go125.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/config_go126.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/config_pre_go124.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/frame.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/gotrack.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/http2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/timer.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc7540.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc9218.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_roundrobin.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/idna10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpcommon/request.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpsfv/httpsfv.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/socks/socks.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/websocket/hybi.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/errgroup/errgroup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_arm64.sis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_other_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_windows_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_x86.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/plan9/pwd_go15_plan9.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/plan9/pwd_plan9.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/affinity_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/fdset.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ifreq_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_signed.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_unsigned.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/mkall.shis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/mkerrors.shis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_darwin.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_netbsd.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_solaris.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_unix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_386.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_amd64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_loong64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mips.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mips64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mips64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mipsle.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_ppc.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_ppc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_ppc64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_riscv64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_s390x.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_sparc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsyscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsyscall_solaris_amd64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_386.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_amd64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_loong64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_mips.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_mips64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_mips64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_mipsle.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_ppc.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_ppc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_ppc64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_riscv64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_s390x.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_sparc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_386.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_amd64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_loong64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mips.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mips64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mips64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mipsle.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_ppc.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_ppc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_ppc64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_riscv64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_s390x.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_sparc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_netbsd_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/syscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/types_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/zsyscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/term/term_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/term/terminal.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/encoding/unicode/unicode.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/secure/bidirule/bidirule.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/secure/bidirule/bidirule10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/secure/bidirule/bidirule9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/core.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables11.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables15.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables17.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/forminfo.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables11.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables15.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables17.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/modules.txtis excluded by!**/vendor/**,!vendor/**
📒 Files selected for processing (1)
go.mod
|
|
||
| replace golang.org/x/net => github.com/openshift-sustaining/net v0.50.0-sec.2 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- go.mod replacement context ---'
sed -n '185,215p' go.mod
printf '%s\n' '--- vendor and dependency references ---'
if [ -d vendor ]; then
find vendor -maxdepth 3 -type f -path '*openshift-sustaining*' -o -path 'vendor/modules.txt' | sort
sed -n '/github.com\/openshift-sustaining\/net/,+8p' vendor/modules.txt 2>/dev/null || true
else
echo 'vendor directory: absent'
fi
printf '%s\n' '--- relevant repository references ---'
rg -n --hidden -g '!/.git' -g '!vendor/**' 'openshift-sustaining/net|v0\.50\.0-sec\.2|GO-2026-5029|pre-release|provenance|SBOM|cosign' .
printf '%s\n' '--- module metadata in go.mod ---'
sed -n '1,30p' go.modRepository: openshift/oc
Length of output: 3376
🌐 Web query:
golang.org/x/net v0.50.0-sec.2 github.com/openshift-sustaining/net security fork GO-2026-5029 v0.55.0
💡 Result:
The entity "github.com/openshift-sustaining/net" appears to be a reference to internal or community-maintained network-related repositories under the OpenShift ecosystem, rather than a single standardized security fork of the upstream golang.org/x/net library [1][2][3]. Regarding the specific identifiers mentioned: GO-2026-5029 is a documented security vulnerability (also tracked as CVE-2026-25681) affecting the golang.org/x/net/html package [4][5]. The vulnerability involves incorrect handling of character references in DOCTYPE nodes, which can lead to XSS attacks when parsed HTML is subsequently rendered [4][6][7]. This vulnerability was addressed in the upstream golang.org/x/net package in version v0.55.0 [4][8]. The version string v0.50.0-sec.2 is not a standard release from the official Go Project [9][10]. It is likely a downstream, project-specific, or organization-internal patch version (possibly used within OpenShift-related repositories) applied to address specific vulnerabilities, such as those identified in the v0.50.0 release cycle [11]. Users are generally advised to upgrade to the latest upstream version (v0.55.0 or higher) to ensure all known security vulnerabilities are patched [4][8][7].
Citations:
- 1: https://github.com/openshift-sustaining/openshift--cluster-network-operator
- 2: https://github.com/openshift-sustaining/openshift--multus-networkpolicy
- 3: https://github.com/openshift-sustaining/openshift--multus-cni
- 4: https://pkg.go.dev/vuln/GO-2026-5029
- 5: https://nvd.nist.gov/vuln/detail/CVE-2026-25681
- 6: https://osv.dev/vulnerability/GO-2026-5029
- 7: https://www.sentinelone.com/vulnerability-database/cve-2026-25681/
- 8: https://deps.dev/advisory/osv/GO-2026-5029
- 9: https://pkg.go.dev/golang.org/x/net@v0.50.0
- 10: https://go.googlesource.com/net/+/refs/tags/v0.50.0
- 11: https://deps.dev/go/golang.org%2Fx%2Fnet/v0.50.0
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- go.mod replacement context ---'
sed -n '185,215p' go.mod
printf '%s\n' '--- vendor and dependency references ---'
if [ -d vendor ]; then
find vendor -maxdepth 3 -type f \( -path '*openshift-sustaining*' -o -path 'vendor/modules.txt' \) | sort
sed -n '/github.com\/openshift-sustaining\/net/,+8p' vendor/modules.txt 2>/dev/null || true
else
echo 'vendor directory: absent'
fi
printf '%s\n' '--- relevant repository references ---'
rg -n --hidden -g '!/.git' -g '!vendor/**' 'openshift-sustaining/net|v0\.50\.0-sec\.2|GO-2026-5029|pre-release|provenance|SBOM|cosign' .
printf '%s\n' '--- module metadata in go.mod ---'
sed -n '1,30p' go.modRepository: openshift/oc
Length of output: 3376
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- fork module metadata ---'
curl -fsSL https://proxy.golang.org/github.com/openshift-sustaining/net/@v/v0.50.0-sec.2.mod
printf '%s\n' '--- fork version metadata ---'
curl -fsSL https://proxy.golang.org/github.com/openshift-sustaining/net/@v/v0.50.0-sec.2.info
printf '%s\n' '--- upstream fixed module metadata ---'
curl -fsSL https://proxy.golang.org/golang.org/x/net/@v/v0.55.0.mod
printf '%s\n' '--- vendored parser symbols related to DOCTYPE and character references ---'
rg -n -C 5 'doctype|DOCTYPE|char.?ref|character reference|parseDoctype' vendor/golang.org/x/net/html vendor/github.com/openshift-sustaining/net 2>/dev/null || true
printf '%s\n' '--- module version ordering ---'
python3 - <<'PY'
import re
for v in ("v0.50.0-sec.2", "v0.50.0", "v0.55.0"):
print(v, re.fullmatch(r"v\d+\.\d+\.\d+(?:-([0-9A-Za-z.-]+))?", v).groups())
PYRepository: openshift/oc
Length of output: 13281
🌐 Web query:
site:github.com/openshift-sustaining/net "v0.50.0-sec.2"
💡 Result:
No GitHub results were found for:
site:github.com/openshift-sustaining/net "v0.50.0-sec.2"
🌐 Web query:
GO-2026-5029 github.com/openshift-sustaining/net v0.50.0-sec.2 fixed fork
💡 Result:
GO-2026-5029 is a Go vulnerability (also identified as CVE-2026-25681) that affects the golang.org/x/net package, specifically related to the improper handling of character references in DOCTYPE nodes [1][2][3]. This vulnerability can be exploited to generate an unexpected HTML tree, potentially enabling Cross-Site Scripting (XSS) attacks in applications that sanitize input HTML before rendering it [1][4]. The issue was addressed in the upstream golang.org/x/net library in version 0.55.0 [1][4]. Regarding the reference to a github.com/openshift-sustaining/net v0.50.0-sec.2 fork, there is no public evidence of a specific repository named openshift-sustaining/net. OpenShift's engineering teams frequently utilize an organization called openshift-sustaining to host patched versions of dependencies (such as grpc-go) to address security vulnerabilities while maintaining compatibility with specific Go toolchain versions or release branches [5][6][7]. It is highly probable that the requested reference is an internal or project-specific identifier for a backported security fix to golang.org/x/net within an OpenShift component, similar to the practices documented for other security patches in the OpenShift ecosystem [5][7]. Users are advised to rely on the upstream fix (upgrading golang.org/x/net to v0.55.0 or later) whenever possible [1][4]. If working within an environment that requires specific version constraints, ensure you are tracking official Red Hat or OpenShift security advisories for guidance on approved patches.
Citations:
- 1: https://pkg.go.dev/vuln/GO-2026-5029
- 2: https://osv.dev/vulnerability/GO-2026-5029
- 3: https://nvd.nist.gov/vuln/detail/CVE-2026-25681
- 4: https://deps.dev/advisory/osv/GO-2026-5029
- 5: OCPBUGS-80434: Replace google.golang.org/grpc with github.com/openshift-sustaining/grpc-go v1.75.1-sec.1 to avoid go version bump and fix CVE-2026-33186 csi-driver-nfs#178
- 6: openshift/cluster-capi-operator@17abd1d
- 7: [Release-4.19] OCPBUGS-80485,OCPBUGS-80484: Update grpc to v1.75.1-sec.1 to fix CVE-2026-33186 operator-framework-operator-controller#731
🏁 Script executed:
#!/bin/bash
set -eu
tmp="$(mktemp -d)"
trap 'rm -rf "$tmp"' EXIT
mkdir -p "$tmp/fork" "$tmp/upstream"
curl -fsSL https://proxy.golang.org/github.com/openshift-sustaining/net/@v/v0.50.0-sec.2.zip -o "$tmp/fork.zip"
curl -fsSL https://proxy.golang.org/golang.org/x/net/@v/v0.55.0.zip -o "$tmp/upstream.zip"
unzip -q "$tmp/fork.zip" -d "$tmp/fork"
unzip -q "$tmp/upstream.zip" -d "$tmp/upstream"
fork_root="$(find "$tmp/fork" -mindepth 1 -maxdepth 1 -type d | head -n1)"
upstream_root="$(find "$tmp/upstream" -mindepth 1 -maxdepth 1 -type d | head -n1)"
printf '%s\n' '--- targeted html source differences ---'
diff -u "$upstream_root/html/doctype.go" "$fork_root/html/doctype.go" || true
diff -u "$upstream_root/html/token.go" "$fork_root/html/token.go" | sed -n '1,240p' || true
printf '%s\n' '--- fork security-related commits and tag ---'
curl -fsSL 'https://api.github.com/repos/openshift-sustaining/net/commits/249934248a04f1b87cce33d0f46fd8b7bb596480' \
| jq '{sha:.sha, message:.commit.message, date:.commit.author.date}'
printf '%s\n' '--- upstream v0.55.0 commit ---'
curl -fsSL 'https://api.github.com/repos/golang/net/git/ref/tags/v0.55.0' \
| jq '{type:.object.type, sha:.object.sha}'Repository: openshift/oc
Length of output: 711
🏁 Script executed:
#!/bin/bash
set -eu
tmp="$(mktemp -d)"
trap 'rm -rf "$tmp"' EXIT
curl -fsSL https://proxy.golang.org/github.com/openshift-sustaining/net/@v/v0.50.0-sec.2.zip -o "$tmp/fork.zip"
curl -fsSL https://proxy.golang.org/golang.org/x/net/@v/v0.55.0.zip -o "$tmp/upstream.zip"
printf '%s\n' '--- archive paths ---'
unzip -Z1 "$tmp/fork.zip" | rg '/html/(doctype|token|parse)\.go$'
unzip -Z1 "$tmp/upstream.zip" | rg '/html/(doctype|token|parse)\.go$'
fork_doctype="$(unzip -Z1 "$tmp/fork.zip" | rg '/html/doctype\.go$' | head -n1)"
upstream_doctype="$(unzip -Z1 "$tmp/upstream.zip" | rg '/html/doctype\.go$' | head -n1)"
fork_token="$(unzip -Z1 "$tmp/fork.zip" | rg '/html/token\.go$' | head -n1)"
upstream_token="$(unzip -Z1 "$tmp/upstream.zip" | rg '/html/token\.go$' | head -n1)"
unzip -p "$tmp/fork.zip" "$fork_doctype" > "$tmp/fork-doctype.go"
unzip -p "$tmp/upstream.zip" "$upstream_doctype" > "$tmp/upstream-doctype.go"
unzip -p "$tmp/fork.zip" "$fork_token" > "$tmp/fork-token.go"
unzip -p "$tmp/upstream.zip" "$upstream_token" > "$tmp/upstream-token.go"
printf '%s\n' '--- doctype.go differences ---'
diff -u "$tmp/upstream-doctype.go" "$tmp/fork-doctype.go" || true
printf '%s\n' '--- token.go differences near doctype handling ---'
diff -u "$tmp/upstream-token.go" "$tmp/fork-token.go" | rg -n -C 8 'doctype|DOCTYPE|character|reference|^@@' || trueRepository: openshift/oc
Length of output: 2318
Security Misconfiguration (CWE-16)
Exploitability: Theoretical
Document the approved exception for the downstream security fork.
v0.50.0-sec.2 is a pre-release version. Keep it only if the project records an exception covering license compatibility, CVE status, SBOM/provenance, artifact signing, and vendor resolution. Upstream v0.55.0 requires Go 1.25, while this module uses Go 1.24.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@go.mod` around lines 205 - 206, Document an approved exception for the
golang.org/x/net replacement with github.com/openshift-sustaining/net
v0.50.0-sec.2, covering license compatibility, CVE status, SBOM/provenance,
artifact signing, and vendor resolution. Retain the replace directive because
the upstream v0.55.0 requirement is incompatible with this module’s Go 1.24
version.
Source: Path instructions
|
Closing this PR as a fix PR has already been raised by @germanparente (#2342). I will link the existing tracker to that PR instead. |
|
@MrSanketkumar: This pull request references Jira Issue OCPBUGS-94907. The bug has been updated to no longer refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@MrSanketkumar: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Summary
golang.org/x/netwithgithub.com/openshift-sustaining/net@v0.50.0-sec.2to fix CVE-2026-25681 and CVE-2026-39821Test plan
go build ./cmd/oc/)Summary by CodeRabbit