Security update for vexctl
This update for vexctl fixes the following issues: - CVE-2024-45337: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (bsc#1234486). - CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239186). - CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239323). - CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238683). - CVE-2025-27144: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of Service (bsc#1237611). - CVE-2025-30204: github.com/golang-jwt/jwt/v4: jwt-go allows excessive memory allocation during header parsing (bsc#1240444). - CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253802). - CVE-2026-22772: github.com/sigstore/fulcio: bypass MetaIssuer URL validation bypass can trigger SSRF to arbitrary internal services (bsc#1256535). - CVE-2026-24137: github.com/sigstore/sigstore/pkg/tuf: legacy TUF client allows for arbitrary file writes with target cache path traversal (bsc#1257138). Changes for vexctl: - Update to version 0.4.4+git20.5d61136: * build(deps): Bump github.com/sigstore/cosign/v2 * build(deps): Bump actions/setup-go from 6.5.0 to 7.0.0 * build(deps): Bump the all group across 1 directory with 5 updates * build(deps): Bump github.com/sigstore/rekor in the all group * build(deps): Bump the all group with 4 updates * build(deps): Bump github.com/google/go-containerregistry * build(deps): Bump actions/setup-go from 6.4.0 to 6.5.0 in the all group * build(deps): Bump the all group across 1 directory with 2 updates * build(deps): Bump actions/checkout from 6.0.3 to 7.0.0 * build(deps): Bump chainguard-dev/actions in the all group - Update to version 0.4.4: * fix signature duplication * fix lints * housekeeping - deps update and ci cleanup * build(deps): Bump the all group with 2 updates * build(deps): Bump github.com/sigstore/sigstore in the all group * build(deps): Bump golangci/golangci-lint-action in the all group - Update to version 0.4.1+git147.b7e6ef0: * build(deps): Bump goreleaser/goreleaser-action in the all group * Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 in the all group * Bump chainguard-dev/actions from 1.6.17 to 1.6.19 in the all group * Bump chainguard-dev/actions from 1.6.16 to 1.6.17 in the all group * Bump github.com/package-url/packageurl-go in the all group * Bump the all group with 2 updates - Update to version 0.4.1+git133.efecaf7: * Bump github.com/secure-systems-lab/go-securesystemslib - Update to version 0.4.1+git129.c7f3066: * Bump github.com/google/go-containerregistry in the all group * Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 * Bump softprops/action-gh-release from 2.6.1 to 3.0.0 * Bump chainguard-dev/actions from 1.6.13 to 1.6.14 in the all group * Bump actions/upload-artifact from 7.0.0 to 7.0.1 in the all group * Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 in the all group * Bump kubernetes-sigs/release-actions in the all group * Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.10.0 * Bump the all group across 1 directory with 2 updates * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 * fix(add): allow add without --product flag * Use gomod version, bump linter * Port vexctl to intoto/attestation * Bump the all group across 1 directory with 5 updates * Bump google.golang.org/grpc from 1.78.0 to 1.79.3 - Update to version 0.4.1+git96.558125d: * Bump the all group across 1 directory with 3 updates * Bump chainguard-dev/actions from 1.6.5 to 1.6.6 in the all group * Bump github.com/google/go-containerregistry from 0.20.7 to 0.21.0 * Bump actions/upload-artifact from 6.0.0 to 7.0.0 * Bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0 * Bump chainguard-dev/actions from 1.6.2 to 1.6.4 in the all group - Update to version 0.4.1+git78.f951e3a: * Bump chainguard-dev/actions from 1.6.1 to 1.6.2 in the all group - Update to version 0.4.1+git76.10d7a2e: * Bump chainguard-dev/actions from 1.6.0 to 1.6.1 in the all group * Bump chainguard-dev/actions from 1.5.16 to 1.6.0 in the all group * Bump chainguard-dev/actions from 1.5.14 to 1.5.16 in the all group * Bump chainguard-dev/actions from 1.5.13 to 1.5.14 in the all group * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.4.1 * Bump actions/setup-go from 6.1.0 to 6.2.0 in the all group * Bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5 * Bump github.com/sigstore/cosign/v2 from 2.6.1 to 2.6.2 in the all group * Bump chainguard-dev/actions from 1.5.10 to 1.5.11 in the all group * Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.3 * Bump github.com/sigstore/sigstore * Bump actions/upload-artifact from 5.0.0 to 6.0.0 * bump golangci-lint * update gorelease sing to works with cosign 3.0+ * Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 in the all group * Bump golangci/golangci-lint-action from 9.1.0 to 9.2.0 in the all group * Bump actions/checkout from 6.0.0 to 6.0.1 in the all group * Bump softprops/action-gh-release from 2.4.2 to 2.5.0 in the all group * Bump chainguard-dev/actions from 1.5.9 to 1.5.10 in the all group * Bump golangci/golangci-lint-action from 8.0.0 to 9.1.0 * Bump actions/checkout from 5.0.1 to 6.0.0 * Bump actions/setup-go from 6.0.0 to 6.1.0 in the all group * Bump golang.org/x/crypto from 0.43.0 to 0.45.0 * Bump github.com/sigstore/rekor from 1.4.2 to 1.4.3 in the all group * Bump actions/upload-artifact from 4.6.2 to 5.0.0 * Bump chainguard-dev/actions from 1.5.6 to 1.5.7 in the all group * Bump sigstore/cosign-installer from 3.10.0 to 4.0.0 * Bump chainguard-dev/actions from 1.5.4 to 1.5.6 in the all group * Bump softprops/action-gh-release from 2.3.4 to 2.4.0 in the all group * Bump github.com/sigstore/cosign/v2 from 2.6.0 to 2.6.1 in the all group - Update to version 0.4.1: * Reverse platform+os naming scheme - Update to version 0.4.0: * update go, goreleaser and update/clean ci * Bump sigs.k8s.io/release-utils from 0.12.1 to 0.12.2 in the all group - Packaging improvements: * Update to BuildRequires: golang(API) >= 1.25 matching go.mod - Update to version 0.3.0+git181.33bac59: * Bump sigstore/cosign-installer from 3.9.2 to 3.10.0 in the all group * Fix break w/cosign 2.6.0 * Bump cosign & go-vex * Fix 2.4 linter nits * Bump softprops/action-gh-release from 2.3.2 to 2.3.3 in the all group * Bump github.com/spf13/cobra from 1.9.1 to 1.10.1 * Bump actions/setup-go from 5.5.0 to 6.0.0 * Bump github.com/stretchr/testify from 1.11.0 to 1.11.1 in the all group * Bump github.com/stretchr/testify from 1.10.0 to 1.11.0 * Bump github.com/go-viper/mapstructure/v2 in the go_modules group * Bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0 in the all group * update release-utils and fix pkg name * Bump actions/checkout from 4.2.2 to 5.0.0 * Bump github.com/secure-systems-lab/go-securesystemslib in the all group * Bump github.com/sigstore/rekor from 1.3.10 to 1.4.0 * Bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0 * Bump sigstore/cosign-installer from 3.9.1 to 3.9.2 in the all group * Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.5.3 in the all group * Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 in the all group * Bump github.com/sigstore/cosign/v2 from 2.5.1 to 2.5.2 in the all group * Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 in the all group * migrate config to v2 * Bump golangci/golangci-lint-action from 6.5.2 to 8.0.0 - Update to version 0.3.0+git133.ff97560: * Bump softprops/action-gh-release from 2.3.0 to 2.3.2 in the all group * Bump github.com/cloudflare/circl in the go_modules group * Bump softprops/action-gh-release from 2.2.2 to 2.3.0 in the all group * Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group * Bump github.com/sigstore/sigstore from 1.9.3 to 1.9.4 in the all group * Bump sigstore/cosign-installer from 3.8.1 to 3.8.2 in the all group * Bump softprops/action-gh-release from 2.2.1 to 2.2.2 in the all group * Bump ko-build/setup-ko from 0.8 to 0.9 in the all group * Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0 * Bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 in the all group * Bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 in the all group * Bump github.com/golang-jwt/jwt/v4 in the go_modules group * Bump golangci/golangci-lint-action from 6.5.1 to 6.5.2 in the all group * Bump github.com/sigstore/sigstore from 1.8.15 to 1.9.1 * Bump golang.org/x/net from 0.35.0 to 0.36.0 in the go_modules group * Bump golangci/golangci-lint-action from 6.5.0 to 6.5.1 in the all group * Bump github.com/go-jose/go-jose/v3 in the go_modules group * Bump github.com/go-jose/go-jose/v4 in the go_modules group * Bump actions/upload-artifact from 4.6.0 to 4.6.1 in the all group * Bump sigstore/cosign-installer from 3.8.0 to 3.8.1 in the all group * use go1.24 and update golangci-lint * Bump golangci/golangci-lint-action from 6.3.3 to 6.5.0 in the all group * Bump github.com/spf13/cobra from 1.8.1 to 1.9.1 * Bump github.com/sigstore/sigstore from 1.8.12 to 1.8.14 in the all group * Bump golangci/golangci-lint-action from 6.3.2 to 6.3.3 in the all group * Bump goreleaser/goreleaser-action from 6.1.0 to 6.2.1 in the all group * Bump golangci/golangci-lint-action from 6.3.0 to 6.3.2 in the all group * Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 in the all group * Bump golangci/golangci-lint-action from 6.2.0 to 6.3.0 in the all group * Bump sigs.k8s.io/release-utils from 0.9.0 to 0.10.0 * Bump github.com/sigstore/rekor from 1.3.8 to 1.3.9 in the all group * Bump actions/setup-go from 5.2.0 to 5.3.0 in the all group * Bump golangci/golangci-lint-action from 6.1.1 to 6.2.0 in the all group * Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0 * Bump go dependencies manually * Bump ko-build/setup-ko from 0.7 to 0.8 in the all group * Bump actions/upload-artifact from 4.5.0 to 4.6.0 in the all group * Bump softprops/action-gh-release from 2.2.0 to 2.2.1 in the all group * Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the all group * Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in the go_modules group * Bump softprops/action-gh-release from 2.0.9 to 2.1.0 in the all group * Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 in the all group * Bump softprops/action-gh-release from 2.0.8 to 2.0.9 in the all group * Update verify.yaml * Update release.yaml * Update ci-build-test.yaml * Bump actions/setup-go from 5.0.2 to 5.1.0 in the all group * Bump actions/checkout from 4.2.1 to 4.2.2 in the all group * Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 in the all group * Bump actions/upload-artifact from 4.4.2 to 4.4.3 in the all group * Bump actions/upload-artifact from 4.4.1 to 4.4.2 in the all group * Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 in the all group * Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 in the all group * Bump github.com/sigstore/cosign/v2 from 2.4.0 to 2.4.1 in the all group * Bump actions/checkout from 4.1.7 to 4.2.0 in the all group * Bump sigs.k8s.io/release-utils from 0.8.4 to 0.8.5 in the all group * upgrade to go1.23
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for vexctl fixes the following issues: - CVE-2024-45337: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (bsc#1234486). - CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239186). - CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239323). - CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238683). - CVE-2025-27144: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of Service (bsc#1237611). - CVE-2025-30204: github.com/golang-jwt/jwt/v4: jwt-go allows excessive memory allocation during header parsing (bsc#1240444). - CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253802). - CVE-2026-22772: github.com/sigstore/fulcio: bypass MetaIssuer URL validation bypass can trigger SSRF to arbitrary internal services (bsc#1256535). - CVE-2026-24137: github.com/sigstore/sigstore/pkg/tuf: legacy TUF client allows for arbitrary file writes with target cache path traversal (bsc#1257138). Changes for vexctl: - Update to version 0.4.4+git20.5d61136: * build(deps): Bump github.com/sigstore/cosign/v2 * build(deps): Bump actions/setup-go from 6.5.0 to 7.0.0 * build(deps): Bump the all group across 1 directory with 5 updates * build(deps): Bump github.com/sigstore/rekor in the all group * build(deps): Bump the all group with 4 updates * build(deps): Bump github.com/google/go-containerregistry * build(deps): Bump actions/setup-go from 6.4.0 to 6.5.0 in the all group * build(deps): Bump the all group across 1 directory with 2 updates * build(deps): Bump actions/checkout from 6.0.3 to 7.0.0 * build(deps): Bump chainguard-dev/actions in the all group - Update to version 0.4.4: * fix signature duplication * fix lints * housekeeping - deps update and ci cleanup * build(deps): Bump the all group with 2 updates * build(deps): Bump github.com/sigstore/sigstore in the all group * build(deps): Bump golangci/golangci-lint-action in the all group - Update to version 0.4.1+git147.b7e6ef0: * build(deps): Bump goreleaser/goreleaser-action in the all group * Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 in the all group * Bump chainguard-dev/actions from 1.6.17 to 1.6.19 in the all group * Bump chainguard-dev/actions from 1.6.16 to 1.6.17 in the all group * Bump github.com/package-url/packageurl-go in the all group * Bump the all group with 2 updates - Update to version 0.4.1+git133.efecaf7: * Bump github.com/secure-systems-lab/go-securesystemslib - Update to version 0.4.1+git129.c7f3066: * Bump github.com/google/go-containerregistry in the all group * Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 * Bump softprops/action-gh-release from 2.6.1 to 3.0.0 * Bump chainguard-dev/actions from 1.6.13 to 1.6.14 in the all group * Bump actions/upload-artifact from 7.0.0 to 7.0.1 in the all group * Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 in the all group * Bump kubernetes-sigs/release-actions in the all group * Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.10.0 * Bump the all group across 1 directory with 2 updates * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 * fix(add): allow add without --product flag * Use gomod version, bump linter * Port vexctl to intoto/attestation * Bump the all group across 1 directory with 5 updates * Bump google.golang.org/grpc from 1.78.0 to 1.79.3 - Update to version 0.4.1+git96.558125d: * Bump the all group across 1 directory with 3 updates * Bump chainguard-dev/actions from 1.6.5 to 1.6.6 in the all group * Bump github.com/google/go-containerregistry from 0.20.7 to 0.21.0 * Bump actions/upload-artifact from 6.0.0 to 7.0.0 * Bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0 * Bump chainguard-dev/actions from 1.6.2 to 1.6.4 in the all group - Update to version 0.4.1+git78.f951e3a: * Bump chainguard-dev/actions from 1.6.1 to 1.6.2 in the all group - Update to version 0.4.1+git76.10d7a2e: * Bump chainguard-dev/actions from 1.6.0 to 1.6.1 in the all group * Bump chainguard-dev/actions from 1.5.16 to 1.6.0 in the all group * Bump chainguard-dev/actions from 1.5.14 to 1.5.16 in the all group * Bump chainguard-dev/actions from 1.5.13 to 1.5.14 in the all group * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.4.1 * Bump actions/setup-go from 6.1.0 to 6.2.0 in the all group * Bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5 * Bump github.com/sigstore/cosign/v2 from 2.6.1 to 2.6.2 in the all group * Bump chainguard-dev/actions from 1.5.10 to 1.5.11 in the all group * Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.3 * Bump github.com/sigstore/sigstore * Bump actions/upload-artifact from 5.0.0 to 6.0.0 * bump golangci-lint * update gorelease sing to works with cosign 3.0+ * Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 in the all group * Bump golangci/golangci-lint-action from 9.1.0 to 9.2.0 in the all group * Bump actions/checkout from 6.0.0 to 6.0.1 in the all group * Bump softprops/action-gh-release from 2.4.2 to 2.5.0 in the all group * Bump chainguard-dev/actions from 1.5.9 to 1.5.10 in the all group * Bump golangci/golangci-lint-action from 8.0.0 to 9.1.0 * Bump actions/checkout from 5.0.1 to 6.0.0 * Bump actions/setup-go from 6.0.0 to 6.1.0 in the all group * Bump golang.org/x/crypto from 0.43.0 to 0.45.0 * Bump github.com/sigstore/rekor from 1.4.2 to 1.4.3 in the all group * Bump actions/upload-artifact from 4.6.2 to 5.0.0 * Bump chainguard-dev/actions from 1.5.6 to 1.5.7 in the all group * Bump sigstore/cosign-installer from 3.10.0 to 4.0.0 * Bump chainguard-dev/actions from 1.5.4 to 1.5.6 in the all group * Bump softprops/action-gh-release from 2.3.4 to 2.4.0 in the all group * Bump github.com/sigstore/cosign/v2 from 2.6.0 to 2.6.1 in the all group - Update to version 0.4.1: * Reverse platform+os naming scheme - Update to version 0.4.0: * update go, goreleaser and update/clean ci * Bump sigs.k8s.io/release-utils from 0.12.1 to 0.12.2 in the all group - Packaging improvements: * Update to BuildRequires: golang(API) >= 1.25 matching go.mod - Update to version 0.3.0+git181.33bac59: * Bump sigstore/cosign-installer from 3.9.2 to 3.10.0 in the all group * Fix break w/cosign 2.6.0 * Bump cosign & go-vex * Fix 2.4 linter nits * Bump softprops/action-gh-release from 2.3.2 to 2.3.3 in the all group * Bump github.com/spf13/cobra from 1.9.1 to 1.10.1 * Bump actions/setup-go from 5.5.0 to 6.0.0 * Bump github.com/stretchr/testify from 1.11.0 to 1.11.1 in the all group * Bump github.com/stretchr/testify from 1.10.0 to 1.11.0 * Bump github.com/go-viper/mapstructure/v2 in the go_modules group * Bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0 in the all group * update release-utils and fix pkg name * Bump actions/checkout from 4.2.2 to 5.0.0 * Bump github.com/secure-systems-lab/go-securesystemslib in the all group * Bump github.com/sigstore/rekor from 1.3.10 to 1.4.0 * Bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0 * Bump sigstore/cosign-installer from 3.9.1 to 3.9.2 in the all group * Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.5.3 in the all group * Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 in the all group * Bump github.com/sigstore/cosign/v2 from 2.5.1 to 2.5.2 in the all group * Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 in the all group * migrate config to v2 * Bump golangci/golangci-lint-action from 6.5.2 to 8.0.0 - Update to version 0.3.0+git133.ff97560: * Bump softprops/action-gh-release from 2.3.0 to 2.3.2 in the all group * Bump github.com/cloudflare/circl in the go_modules group * Bump softprops/action-gh-release from 2.2.2 to 2.3.0 in the all group * Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group * Bump github.com/sigstore/sigstore from 1.9.3 to 1.9.4 in the all group * Bump sigstore/cosign-installer from 3.8.1 to 3.8.2 in the all group * Bump softprops/action-gh-release from 2.2.1 to 2.2.2 in the all group * Bump ko-build/setup-ko from 0.8 to 0.9 in the all group * Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0 * Bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 in the all group * Bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 in the all group * Bump github.com/golang-jwt/jwt/v4 in the go_modules group * Bump golangci/golangci-lint-action from 6.5.1 to 6.5.2 in the all group * Bump github.com/sigstore/sigstore from 1.8.15 to 1.9.1 * Bump golang.org/x/net from 0.35.0 to 0.36.0 in the go_modules group * Bump golangci/golangci-lint-action from 6.5.0 to 6.5.1 in the all group * Bump github.com/go-jose/go-jose/v3 in the go_modules group * Bump github.com/go-jose/go-jose/v4 in the go_modules group * Bump actions/upload-artifact from 4.6.0 to 4.6.1 in the all group * Bump sigstore/cosign-installer from 3.8.0 to 3.8.1 in the all group * use go1.24 and update golangci-lint * Bump golangci/golangci-lint-action from 6.3.3 to 6.5.0 in the all group * Bump github.com/spf13/cobra from 1.8.1 to 1.9.1 * Bump github.com/sigstore/sigstore from 1.8.12 to 1.8.14 in the all group * Bump golangci/golangci-lint-action from 6.3.2 to 6.3.3 in the all group * Bump goreleaser/goreleaser-action from 6.1.0 to 6.2.1 in the all group * Bump golangci/golangci-lint-action from 6.3.0 to 6.3.2 in the all group * Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 in the all group * Bump golangci/golangci-lint-action from 6.2.0 to 6.3.0 in the all group * Bump sigs.k8s.io/release-utils from 0.9.0 to 0.10.0 * Bump github.com/sigstore/rekor from 1.3.8 to 1.3.9 in the all group * Bump actions/setup-go from 5.2.0 to 5.3.0 in the all group * Bump golangci/golangci-lint-action from 6.1.1 to 6.2.0 in the all group * Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0 * Bump go dependencies manually * Bump ko-build/setup-ko from 0.7 to 0.8 in the all group * Bump actions/upload-artifact from 4.5.0 to 4.6.0 in the all group * Bump softprops/action-gh-release from 2.2.0 to 2.2.1 in the all group * Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the all group * Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in the go_modules group * Bump softprops/action-gh-release from 2.0.9 to 2.1.0 in the all group * Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 in the all group * Bump softprops/action-gh-release from 2.0.8 to 2.0.9 in the all group * Update verify.yaml * Update release.yaml * Update ci-build-test.yaml * Bump actions/setup-go from 5.0.2 to 5.1.0 in the all group * Bump actions/checkout from 4.2.1 to 4.2.2 in the all group * Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 in the all group * Bump actions/upload-artifact from 4.4.2 to 4.4.3 in the all group * Bump actions/upload-artifact from 4.4.1 to 4.4.2 in the all group * Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 in the all group * Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 in the all group * Bump github.com/sigstore/cosign/v2 from 2.4.0 to 2.4.1 in the all group * Bump actions/checkout from 4.1.7 to 4.2.0 in the all group * Bump sigs.k8s.io/release-utils from 0.8.4 to 0.8.5 in the all group * upgrade to go1.23
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1234486
- https://bugzilla.suse.com/1237611
- https://bugzilla.suse.com/1238683
- https://bugzilla.suse.com/1239186
- https://bugzilla.suse.com/1239323
- https://bugzilla.suse.com/1240444
- https://bugzilla.suse.com/1253802
- https://bugzilla.suse.com/1256535
- https://bugzilla.suse.com/1257138
- https://www.suse.com/security/cve/CVE-2024-45337
- https://www.suse.com/security/cve/CVE-2025-22868
- https://www.suse.com/security/cve/CVE-2025-22869
- https://www.suse.com/security/cve/CVE-2025-22870
- https://www.suse.com/security/cve/CVE-2025-27144
- https://www.suse.com/security/cve/CVE-2025-30204
- https://www.suse.com/security/cve/CVE-2025-58181
- https://www.suse.com/security/cve/CVE-2026-22772
- https://www.suse.com/security/cve/CVE-2026-24137