Skip to content

Comments

fix(migrations): upgrade atlas base image to v1.1.3#2763

Merged
migmartri merged 3 commits intochainloop-dev:mainfrom
migmartri:migmartri/upgrading-golang-skill
Feb 20, 2026
Merged

fix(migrations): upgrade atlas base image to v1.1.3#2763
migmartri merged 3 commits intochainloop-dev:mainfrom
migmartri:migmartri/upgrading-golang-skill

Conversation

@migmartri
Copy link
Member

Upgrades arigaio/atlas from v1.1.0 to v1.1.3 to address:

  • CVE-2025-68121 (Critical) - crypto/tls session resumption issue in stdlib go1.25.6
  • CVE-2025-61732 (High) - cgo code smuggling via Go/C comment parsing in stdlib go1.25.6

Both CVEs are fixed in Go 1.25.7, which atlas v1.1.3 is built with.

Upgrades arigaio/atlas from v1.1.0 to v1.1.3 to address:
- CVE-2025-68121 (Critical) - crypto/tls session resumption issue in stdlib go1.25.6
- CVE-2025-61732 (High) - cgo code smuggling via Go/C comment parsing in stdlib go1.25.6

Both CVEs are fixed in Go 1.25.7, which atlas v1.1.3 is built with.

Signed-off-by: Miguel Martinez <miguel@chainloop.dev>
Signed-off-by: Miguel Martinez <miguel@chainloop.dev>
Signed-off-by: Miguel Martinez <miguel@chainloop.dev>
@migmartri migmartri merged commit 4a18e52 into chainloop-dev:main Feb 20, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants