[release-ocm-2.13] ACM-34225: CVE-2026-34986 Bump github.com/go-jose/go-jose/v4 to v4.1.4 using replace directive (api module)#10345
Conversation
…4 using replace directive
|
@shay23bra: This pull request references ACM-34225 which is a valid jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: openshift/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: shay23bra The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release-ocm-2.13 #10345 +/- ##
====================================================
- Coverage 42.78% 42.77% -0.01%
====================================================
Files 346 346
Lines 65935 65935
====================================================
- Hits 28207 28205 -2
- Misses 35194 35195 +1
- Partials 2534 2535 +1 🚀 New features to boost your workflow:
|
Bump
github.com/go-jose/go-jose/v4tov4.1.4to fixCVE-2026-34986using a replace directiveStrategy Selection
Strategies Not Applicable
Direct dependency version bump
Not applicable: dependency is indirect. Direct version bumps only work for explicitly required modules.
Direct dependency major version upgrade
Not applicable: dependency is indirect. Major version upgrades only apply to direct dependencies.
Indirect dependency fix via parent update
github.com/openshift/assisted-serviceIndirect to direct dependency conversion
Attempted to pin github.com/go-jose/go-jose/v4 to a fixed version, but Go reverted it to indirect at v4.0.5. No other module requires this version directly, so the explicit requirement was automatically removed by Go's module resolution.
✓ Successful Strategy: Replace directive workaround
Added replace directive to override module resolution. Used as last resort when standard updates fail.
https://redhat.atlassian.net/browse/ACM-34225
https://redhat.atlassian.net/browse/ACM-34226
This PR was automatically generated by the CVE Automation tool.
For questions or issues, reach out in #cve-automation.