Skip to content

[cloud-provider-yandex] Fix CVE - #32

Merged
pabateman merged 1 commit into
masterfrom
fix/cve-yandex-csi
Jul 20, 2026
Merged

pabateman merged 1 commit into
masterfrom
fix/cve-yandex-csi

Conversation

@ptrvsrg

@ptrvsrg ptrvsrg commented Jun 22, 2026 •

Copy link
Copy Markdown
Member

Description

Updated Go dependencies for the Yandex CSI driver to remediate CVEs, including google.golang.org/grpc.

Also updated the build and CI toolchain:

  • builder image to golang:1.25.12-alpine3.24 with digest pinning;
  • runtime image to alpine:3.24 with digest pinning;
  • GitHub Actions Go version to 1.25.12;
  • golangci-lint to v2.8.0.

This affects the Yandex CSI driver image. During delivery in Deckhouse, CSI controller/node pods using the updated image are expected to roll out; no storage migration is intended.

Why do we need it, and what problem does it solve?

The Yandex CSI driver used vulnerable Go dependencies reported by CVE scanning.

The old Dockerfile and CI Go versions were also incompatible with the updated dependency stack. The change updates the dependency stack and aligns the build/CI toolchain with Go 1.25.12 and Alpine 3.24.

Why do we need it in the patch release (if we do)?

Not necessarily

Checklist

  • The code is covered by unit tests.
  • e2e tests passed.
  • Documentation updated according to the changes.
  • Changes were tested in the Kubernetes cluster manually.

Changelog entries

section: cloud-provider-yandex
type: fix
summary: Updated Yandex CSI driver dependencies and build toolchain to remediate CVEs.
impact_level: default

@ptrvsrg ptrvsrg self-assigned this Jun 22, 2026
@ptrvsrg
ptrvsrg requested review from aleksey-su and pabateman July 14, 2026 12:09
Signed-off-by: Sergey Petrov <sergey.petrov@flant.com>
@ptrvsrg
ptrvsrg force-pushed the fix/cve-yandex-csi branch from 4ad8f11 to b198008 Compare July 15, 2026 10:58
@ptrvsrg
ptrvsrg marked this pull request as ready for review July 16, 2026 07:46
@pabateman
pabateman merged commit 72b0be0 into master Jul 20, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants