RATATOSKRATATOSK
ログイン

Crossplane

v2.2.6Orchestration & Management
2026年9月15日

ACTION 3OTHER 1

依存関係の更新で上流の CVE 修正を取り込む、セキュリティ重視のメンテナンスリリースです。パッケージリビジョンの引き継ぎも修正され、置き換え対象のリビジョンから所有権を引き継ぐ処理が手動介入なしで完了します。

要対応 (3)

  • securityhighgoogle.golang.org/grpc の更新

    google.golang.org/grpcv1.83.2 に更新し、gRPC の勧告 GHSA-2v4p-qf9q-27wj を含む上流の CVE 修正を取り込みます。

    GHSA-2v4p-qf9q-27wj

  • securityGo toolchain の更新

    Go toolchain を 1.26.7 に更新し、上流の CVE 修正を取り込みます。ロックファイルも更新されます。

    GHSA-2v4p-qf9q-27wj

  • securitygolang.org/x/crypto の更新

    golang.org/x/cryptov0.56.0 に更新し、上流の CVE 修正を取り込みます。

    GHSA-2v4p-qf9q-27wj

その他の記録済み変更 1 件すべてfixes 1

fixes (1)

  • * **Package revisions now take control of established objects from the revision they replace:** An outgoing package revision could fail to relinquish control of the package's CRDs, leaving the incoming revision permanently unhealthy with cannot establish control of object. The provider's pod would never be created, so that provider could do no work without manual intervention by someone either deleting the stale revision or editing the CRD's owner reference by hand. Package revisions now directly take control from the revision they replace, so the hand-off succeeds without any intervention. Backported in #7828, originally fixed in #7733.
Crossplaneをスタックに追加

対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。

スタックに追加