Skip to content

Conversation

@TomerShor
Copy link
Member

📝 Description

Bump Go to 1.25.5 to address vulnerability fixes:

Vulnerability #1: GO-2025-4175
Vulnerability #2: GO-2025-4155

Additionally, bump other go packages:

  • golang.org/x/sync v0.19.0
  • google.golang.org/protobuf v1.36.10
  • k8s.io/api v0.34.3
  • k8s.io/apimachinery v0.34.3
  • k8s.io/client-go v0.34.3

✅ Checklist

  • I updated the documentation (if applicable)
  • I have tested the changes in this PR
  • I confirmed whether my changes are covered by system tests
    • If yes, I ran all relevant system tests and ensured they passed before submitting this PR
    • I updated existing system tests and/or added new ones if needed to cover my changes
  • If I introduced a deprecation:

🧪 Testing


🔗 References

  • Ticket link:
  • Design docs links:
  • External links:

🚨 Breaking Changes?

  • Yes (explain below)
  • No

🔍️ Additional Notes

@TomerShor TomerShor requested a review from a team as a code owner December 10, 2025 10:04
@liranbg liranbg merged commit 431dd2e into mlrun:development Dec 10, 2025
16 checks passed
@TomerShor TomerShor deleted the go-bump branch December 10, 2025 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants