[Snyk] Security upgrade golang from 1.25.2 to 1.25.5
Snyk has created this PR to fix 5 vulnerabilities in the dockerfile dependencies of this project.
Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.
Snyk changed the following file(s):
-
tool/codegen/Dockerfile
We recommend upgrading to golang:1.25.5, as this image has only 91 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.
Vulnerabilities that will be fixed with an upgrade:
| Issue | Score | |
|---|---|---|
| CVE-2025-9086 SNYK-DEBIAN13-CURL-12613264 |
364 | |
| CVE-2025-10148 SNYK-DEBIAN13-CURL-12613266 |
364 | |
| CVE-2025-9231 SNYK-DEBIAN13-OPENSSL-13174592 |
364 | |
| CVE-2025-9230 SNYK-DEBIAN13-OPENSSL-13174602 |
364 | |
| CVE-2025-9232 SNYK-DEBIAN13-OPENSSL-13174605 |
364 |
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.
Codecov Report
:white_check_mark: All modified and coverable lines are covered by tests.
:white_check_mark: Project coverage is 28.85%. Comparing base (e5bbc7b) to head (41e0752).
Additional details and impacted files
@@ Coverage Diff @@
## master #6372 +/- ##
=======================================
Coverage 28.85% 28.85%
=======================================
Files 560 560
Lines 59993 59993
=======================================
Hits 17313 17313
Misses 41359 41359
Partials 1321 1321
| Flag | Coverage Δ | |
|---|---|---|
| . | 23.27% <ø> (ø) |
|
| .-pkg-app-pipedv1-plugin-analysis | 32.64% <ø> (ø) |
|
| .-pkg-app-pipedv1-plugin-kubernetes | 58.67% <ø> (ø) |
|
| .-pkg-app-pipedv1-plugin-kubernetes_multicluster | 67.63% <ø> (ø) |
|
| .-pkg-app-pipedv1-plugin-scriptrun | 54.83% <ø> (ø) |
|
| .-pkg-app-pipedv1-plugin-terraform | 38.65% <ø> (ø) |
|
| .-pkg-app-pipedv1-plugin-wait | 33.92% <ø> (ø) |
|
| .-pkg-app-pipedv1-plugin-waitapproval | 52.71% <ø> (ø) |
|
| .-pkg-plugin-sdk | 50.34% <ø> (ø) |
|
| .-tool-actions-gh-release | 19.23% <ø> (ø) |
|
| .-tool-actions-plan-preview | 25.51% <ø> (ø) |
|
| .-tool-codegen-protoc-gen-auth | 0.00% <ø> (ø) |
Flags with carried forward coverage won't be shown. Click here to find out more.
:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.
:rocket: New features to boost your workflow:
- :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
- :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.