Skip to content

[master] MGMT-23665: CVE-2026-33186 Bump google.golang.org/grpc to v1.79.3 using replace directive (api module)#10081

Open
cve-automation[bot] wants to merge 1 commit intomasterfrom
cve-CVE-2026-33186-ba0784a9-9ba83d
Open

[master] MGMT-23665: CVE-2026-33186 Bump google.golang.org/grpc to v1.79.3 using replace directive (api module)#10081
cve-automation[bot] wants to merge 1 commit intomasterfrom
cve-CVE-2026-33186-ba0784a9-9ba83d

Conversation

@cve-automation
Copy link
Copy Markdown

Bump google.golang.org/grpc to v1.79.3 to fix CVE-2026-33186 using a replace directive

Strategy Selection

Strategies Not Applicable

  • Direct dependency version bump
    Not applicable: dependency is indirect. Direct version bumps only work for explicitly required modules.

  • Direct dependency major version upgrade
    Not applicable: dependency is indirect. Major version upgrades only apply to direct dependencies.

  • Indirect dependency fix via parent update

    • No suitable versions found for introducers:
      • github.com/openshift/custom-resource-status
      • github.com/openshift/hive/apis
  • Indirect to direct dependency conversion
    Attempted to pin google.golang.org/grpc to a fixed version, but Go reverted it to indirect at v1.27.0. No other module requires this version directly, so the explicit requirement was automatically removed by Go's module resolution.

✓ Successful Strategy: Replace directive workaround

Added replace directive to override module resolution. Used as last resort when standard updates fail.

https://redhat.atlassian.net/browse/MGMT-23665
https://redhat.atlassian.net/browse/MGMT-23664


This PR was automatically generated by the CVE Automation tool.
For questions or issues, reach out in #cve-automation.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Mar 27, 2026
@openshift-ci-robot
Copy link
Copy Markdown

openshift-ci-robot commented Mar 27, 2026

@cve-automation[bot]: This pull request references MGMT-23665 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the vulnerability to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Bump google.golang.org/grpc to v1.79.3 to fix CVE-2026-33186 using a replace directive

Strategy Selection

Strategies Not Applicable

  • Direct dependency version bump
    Not applicable: dependency is indirect. Direct version bumps only work for explicitly required modules.

  • Direct dependency major version upgrade
    Not applicable: dependency is indirect. Major version upgrades only apply to direct dependencies.

  • Indirect dependency fix via parent update

  • No suitable versions found for introducers:

    • github.com/openshift/custom-resource-status
    • github.com/openshift/hive/apis
  • Indirect to direct dependency conversion
    Attempted to pin google.golang.org/grpc to a fixed version, but Go reverted it to indirect at v1.27.0. No other module requires this version directly, so the explicit requirement was automatically removed by Go's module resolution.

✓ Successful Strategy: Replace directive workaround

Added replace directive to override module resolution. Used as last resort when standard updates fail.

https://redhat.atlassian.net/browse/MGMT-23665
https://redhat.atlassian.net/browse/MGMT-23664


This PR was automatically generated by the CVE Automation tool.
For questions or issues, reach out in #cve-automation.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci bot added the size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. label Mar 27, 2026
@openshift-ci openshift-ci bot requested review from mlorenzofr and yoavsc0302 March 27, 2026 14:25
@openshift-ci openshift-ci bot added the api-review Categorizes an issue or PR as actively needing an API review. label Mar 27, 2026
@coderabbitai
Copy link
Copy Markdown

coderabbitai bot commented Mar 27, 2026

Important

Review skipped

Auto reviews are limited based on label configuration.

🚫 Review skipped — only excluded labels are configured. (1)
  • do-not-merge/work-in-progress

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 133e3ca3-9835-428c-b629-0878e6160b1e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cve-CVE-2026-33186-ba0784a9-9ba83d

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented Mar 27, 2026

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: cve-automation[bot]
Once this PR has been reviewed and has the lgtm label, please assign linoyaslan for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@omer-vishlitzky
Copy link
Copy Markdown
Contributor

/retest

@codecov
Copy link
Copy Markdown

codecov bot commented Mar 27, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 44.17%. Comparing base (acc8646) to head (09006c7).
⚠️ Report is 2 commits behind head on master.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##           master   #10081   +/-   ##
=======================================
  Coverage   44.17%   44.17%           
=======================================
  Files         416      416           
  Lines       72404    72404           
=======================================
  Hits        31985    31985           
  Misses      37522    37522           
  Partials     2897     2897           

see 2 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@gamli75
Copy link
Copy Markdown
Contributor

gamli75 commented Mar 29, 2026

/test verify-deps

@gamli75
Copy link
Copy Markdown
Contributor

gamli75 commented Mar 29, 2026

/override ci/prow/e2e-agent-compact-ipv4

@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented Mar 29, 2026

@gamli75: Overrode contexts on behalf of gamli75: ci/prow/e2e-agent-compact-ipv4

Details

In response to this:

/override ci/prow/e2e-agent-compact-ipv4

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented Mar 29, 2026

@cve-automation[bot]: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-agent-compact-ipv4-iso-no-registry 09006c7 link false /test e2e-agent-compact-ipv4-iso-no-registry
ci/prow/verify-deps 09006c7 link true /test verify-deps

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api-review Categorizes an issue or PR as actively needing an API review. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants