Skip to content

[cherry-pick v20260304] fix(security): bump Go to 1.25.10 and golang.org/x/net to v0.55.0#8560

Open
djsly wants to merge 1 commit into
official/v20260304from
djsly/icm-796913379-cve-go-1.25.10-v20260304
Open

[cherry-pick v20260304] fix(security): bump Go to 1.25.10 and golang.org/x/net to v0.55.0#8560
djsly wants to merge 1 commit into
official/v20260304from
djsly/icm-796913379-cve-go-1.25.10-v20260304

Conversation

@djsly
Copy link
Copy Markdown
Collaborator

@djsly djsly commented May 22, 2026

Summary

Cherry-pick of #8551 to official/vv20260304.

Bumps the Go toolchain and golang.org/x/net to address upstream CVEs:

Vulnerability CVE Component Fixed by
net/mail DoS via crafted addresses CVE-2026-39820 net/mail (stdlib) Go 1.25.10
cmd/go pack subcommand directory traversal CVE-2026-39817 cmd/go (stdlib) Go 1.25.10
HTTP/2 + IPv6 host parsing fixes (various, see x/net release notes) golang.org/x/net v0.55.0

Why bump to Go 1.25 (and not a 1.24.x patch)

Go 1.24 reached EOL in February 2026 and does NOT receive security backports. go1.25.10 is the only release stream that contains these fixes.

golang.org/x/net v0.51.0+ also requires go 1.25.0 in its own go.mod, so the Go bump is required regardless.

Verification

  • go mod tidy succeeds for every module in the branch.
  • go build ./... clean across every module.
  • PR CI must pull go 1.25 runners.

Release plan

Once merged, two tags are pushed off the resulting commit:

  • v0.v20260304.<N+1> (AgentBaker module)
  • aks-node-controller/v0.v20260304.<N+1> (aks-node-controller submodule)

🤖 Generated with GitHub Copilot CLI

Backport Go 1.25.10 and golang.org/x/net v0.55.0 to official/v20260304 for IcM 796913379.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions
Copy link
Copy Markdown
Contributor

Changes cached containers or packages on windows VHDs

Please get a Windows SIG member to approve.

The following dif file shows any additions or deletions from what will be cached on windows VHDs organised by VHD type.

  • Additions are new things cached.
  • Deletions are things no longer cached.
diff --git a/vhd_files/2022-containerd-gen2.txt b/vhd_files/2022-containerd-gen2.txt
index d077754..3af8808 100644
--- a/vhd_files/2022-containerd-gen2.txt
+++ b/vhd_files/2022-containerd-gen2.txt
@@ -4 +4 @@ c:\akse-cache\: https://packages.aks.azure.com/ccgakvplugin/v1.1.5/binaries/wind
-c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.1.2/windows-amd64.zip
+c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.0.2/windows-amd64.zip
@@ -28,2 +28,3 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.32.12/windo
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.10/windowszip/v1.33.10-1int.zip
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.11/windowszip/v1.33.11-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.7/windowszip/v1.33.7-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.8/windowszip/v1.33.8-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.3/windowszip/v1.34.3-1int.zip
@@ -31 +31,0 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.4/window
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.7/windowszip/v1.34.7-1int.zip
@@ -44 +43,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\14
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1491587726=1
@@ -69 +67,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\36
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\3658215055=1
@@ -76 +73,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\41
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\4173449358=1
@@ -106,3 +103,2 @@ mcr.microsoft.com/containernetworking/azure-cni:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cni:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.7.9-0
@@ -110,3 +106,8 @@ mcr.microsoft.com/containernetworking/azure-cns:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cns:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.7.9-0
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.9-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.8-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.3-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc
@@ -115,8 +116,5 @@ mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.7.2
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.3-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.10-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.5-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.6-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.2-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.3-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.2-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.4-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.1-windows-hp
@@ -128,3 +126,3 @@ mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.4
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.11-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.8-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.3-windows-hpc-1
@@ -133,2 +131,2 @@ mcr.microsoft.com/windows/nanoserver:ltsc2022
-mcr.microsoft.com/windows/servercore:10.0.20348.5020
-mcr.microsoft.com/windows/servercore:10.0.20348.5139
+mcr.microsoft.com/windows/servercore:10.0.20348.4648
+mcr.microsoft.com/windows/servercore:10.0.20348.4773
@@ -137 +135 @@ mcr.microsoft.com/windows/servercore/iis:windowsservercore-ltsc2022
-Windows 2022-containerd-gen2 base version: 20348.5139.260507
+Windows 2022-containerd-gen2 base version: 20348.4773.260206
diff --git a/vhd_files/2022-containerd.txt b/vhd_files/2022-containerd.txt
index 9fc5424..bf444f2 100644
--- a/vhd_files/2022-containerd.txt
+++ b/vhd_files/2022-containerd.txt
@@ -4 +4 @@ c:\akse-cache\: https://packages.aks.azure.com/ccgakvplugin/v1.1.5/binaries/wind
-c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.1.2/windows-amd64.zip
+c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.0.2/windows-amd64.zip
@@ -28,2 +28,3 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.32.12/windo
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.10/windowszip/v1.33.10-1int.zip
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.11/windowszip/v1.33.11-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.7/windowszip/v1.33.7-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.8/windowszip/v1.33.8-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.3/windowszip/v1.34.3-1int.zip
@@ -31 +31,0 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.4/window
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.7/windowszip/v1.34.7-1int.zip
@@ -44 +43,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\14
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1491587726=1
@@ -69 +67,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\36
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\3658215055=1
@@ -76 +73,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\41
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\4173449358=1
@@ -106,3 +103,2 @@ mcr.microsoft.com/containernetworking/azure-cni:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cni:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.7.9-0
@@ -110,3 +106,8 @@ mcr.microsoft.com/containernetworking/azure-cns:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cns:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.7.9-0
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.9-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.8-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.3-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc
@@ -115,8 +116,5 @@ mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.7.2
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.3-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.10-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.5-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.6-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.2-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.3-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.2-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.4-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.1-windows-hp
@@ -128,3 +126,3 @@ mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.4
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.11-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.8-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.3-windows-hpc-1
@@ -133,2 +131,2 @@ mcr.microsoft.com/windows/nanoserver:ltsc2022
-mcr.microsoft.com/windows/servercore:10.0.20348.5020
-mcr.microsoft.com/windows/servercore:10.0.20348.5139
+mcr.microsoft.com/windows/servercore:10.0.20348.4648
+mcr.microsoft.com/windows/servercore:10.0.20348.4773
@@ -137 +135 @@ mcr.microsoft.com/windows/servercore/iis:windowsservercore-ltsc2022
-Windows 2022-containerd base version: 20348.5139.260507
+Windows 2022-containerd base version: 20348.4773.260206
diff --git a/vhd_files/2025-gen2.txt b/vhd_files/2025-gen2.txt
index ca4841d..19c0eda 100644
--- a/vhd_files/2025-gen2.txt
+++ b/vhd_files/2025-gen2.txt
@@ -4 +4 @@ c:\akse-cache\: https://packages.aks.azure.com/ccgakvplugin/v1.1.5/binaries/wind
-c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.1.2/windows-amd64.zip
+c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.0.2/windows-amd64.zip
@@ -15 +14,0 @@ c:\akse-cache\csi-proxy\: https://packages.aks.azure.com/csi-proxy/v1.1.2-hotfix
-c:\akse-cache\wcn\: mcr.microsoft.com/wcn/package:1.7.0-cpu-arch
@@ -26,2 +25,3 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.32.12/windo
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.10/windowszip/v1.33.10-1int.zip
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.11/windowszip/v1.33.11-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.7/windowszip/v1.33.7-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.8/windowszip/v1.33.8-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.3/windowszip/v1.34.3-1int.zip
@@ -29 +28,0 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.4/window
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.7/windowszip/v1.34.7-1int.zip
@@ -32,2 +30,0 @@ c:\akse-cache\win-vnet-cni\: https://packages.aks.azure.com/azure-cni/v1.6.21/bi
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1451608719=1
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1861198479=1
@@ -36,3 +33,2 @@ mcr.microsoft.com/containernetworking/azure-cni:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cni:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.7.9-0
@@ -40,3 +36,8 @@ mcr.microsoft.com/containernetworking/azure-cns:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cns:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.7.9-0
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.9-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.8-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.3-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc
@@ -45,8 +46,5 @@ mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.7.2
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.3-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.10-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.5-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.6-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.2-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.3-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.2-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.4-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.1-windows-hp
@@ -58,3 +56,3 @@ mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.4
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.11-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.8-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.3-windows-hpc-1
@@ -64,4 +62,4 @@ mcr.microsoft.com/windows/nanoserver:ltsc2025
-mcr.microsoft.com/windows/servercore:10.0.20348.5020
-mcr.microsoft.com/windows/servercore:10.0.20348.5139
-mcr.microsoft.com/windows/servercore:10.0.26100.32690
-mcr.microsoft.com/windows/servercore:10.0.26100.32860
+mcr.microsoft.com/windows/servercore:10.0.20348.4648
+mcr.microsoft.com/windows/servercore:10.0.20348.4773
+mcr.microsoft.com/windows/servercore:10.0.26100.32230
+mcr.microsoft.com/windows/servercore:10.0.26100.32370
@@ -71 +69 @@ mcr.microsoft.com/windows/servercore/iis:windowsservercore-ltsc2025
-Windows 2025-gen2 base version: 26100.32860.260510
+Windows 2025-gen2 base version: 26100.32370.260206
diff --git a/vhd_files/2025.txt b/vhd_files/2025.txt
index f184f01..8bf836c 100644
--- a/vhd_files/2025.txt
+++ b/vhd_files/2025.txt
@@ -4 +4 @@ c:\akse-cache\: https://packages.aks.azure.com/ccgakvplugin/v1.1.5/binaries/wind
-c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.1.2/windows-amd64.zip
+c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.0.2/windows-amd64.zip
@@ -15 +14,0 @@ c:\akse-cache\csi-proxy\: https://packages.aks.azure.com/csi-proxy/v1.1.2-hotfix
-c:\akse-cache\wcn\: mcr.microsoft.com/wcn/package:1.7.0-cpu-arch
@@ -26,2 +25,3 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.32.12/windo
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.10/windowszip/v1.33.10-1int.zip
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.11/windowszip/v1.33.11-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.7/windowszip/v1.33.7-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.8/windowszip/v1.33.8-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.3/windowszip/v1.34.3-1int.zip
@@ -29 +28,0 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.4/window
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.7/windowszip/v1.34.7-1int.zip
@@ -32,2 +30,0 @@ c:\akse-cache\win-vnet-cni\: https://packages.aks.azure.com/azure-cni/v1.6.21/bi
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1451608719=1
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1861198479=1
@@ -36,3 +33,2 @@ mcr.microsoft.com/containernetworking/azure-cni:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cni:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.7.9-0
@@ -40,3 +36,8 @@ mcr.microsoft.com/containernetworking/azure-cns:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cns:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.7.9-0
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.9-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.8-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.3-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc
@@ -45,8 +46,5 @@ mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.7.2
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.3-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.10-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.5-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.6-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.2-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.3-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.2-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.4-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.1-windows-hp
@@ -58,3 +56,3 @@ mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.4
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.11-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.8-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.3-windows-hpc-1
@@ -64,4 +62,4 @@ mcr.microsoft.com/windows/nanoserver:ltsc2025
-mcr.microsoft.com/windows/servercore:10.0.20348.5020
-mcr.microsoft.com/windows/servercore:10.0.20348.5139
-mcr.microsoft.com/windows/servercore:10.0.26100.32690
-mcr.microsoft.com/windows/servercore:10.0.26100.32860
+mcr.microsoft.com/windows/servercore:10.0.20348.4648
+mcr.microsoft.com/windows/servercore:10.0.20348.4773
+mcr.microsoft.com/windows/servercore:10.0.26100.32230
+mcr.microsoft.com/windows/servercore:10.0.26100.32370
@@ -71 +69 @@ mcr.microsoft.com/windows/servercore/iis:windowsservercore-ltsc2025
-Windows 2025 base version: 26100.32860.260510
+Windows 2025 base version: 26100.32370.260206

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports a security update to the v20260304 branch by upgrading the Go toolchain version across all Go modules in this repo snapshot and updating golang.org/x/net (and related x/* transitive deps) to the patched versions. This aligns CI workflows with the new Go minor version and fixes an e2e formatting issue that stricter vetting can flag.

Changes:

  • Bump all repo Go modules from go 1.24.12 to go 1.25.10.
  • Update golang.org/x/net to v0.55.0 (plus resulting go.sum refreshes in root/e2e/aks-node-controller).
  • Update GitHub Actions workflows to use Go 1.25 and fix fmt.Sprintf("%w", ...) usage in e2e.

Reviewed changes

Copilot reviewed 14 out of 17 changed files in this pull request and generated no comments.

Show a summary per file
File Description
go.mod Bumps Go directive to 1.25.10 and updates indirect golang.org/x/* versions (incl. x/net v0.55.0).
go.sum Refreshes sums to match the updated golang.org/x/* dependency graph.
e2e/go.mod Bumps Go directive and updates golang.org/x/crypto + indirect golang.org/x/* deps.
e2e/go.sum Refreshes sums for the updated e2e dependency set.
e2e/config/config.go Replaces invalid %w in fmt.Sprintf with %v.
aks-node-controller/go.mod Bumps Go directive and updates indirect golang.org/x/sys.
aks-node-controller/go.sum Refreshes sums for updated golang.org/x/* dependencies.
hack/tools/go.mod Bumps Go directive for the tools module.
vhdbuilder/lister/go.mod Bumps Go directive for the lister module.
vhdbuilder/prefetch/go.mod Bumps Go directive for the prefetch module.
.github/workflows/check-coverage.yml Updates CI to run with Go 1.25.
.github/workflows/copilot-setup-steps.yml Updates Copilot setup workflow to use Go 1.25.
.github/workflows/go-test.yml Updates unit test workflow to use Go 1.25.
.github/workflows/golangci-lint.yml Updates golangci-lint workflow to use Go 1.25.
.github/workflows/shellcheck.yml Updates shellcheck workflow to use Go 1.25.
.github/workflows/shellspec.yaml Updates shellspec workflow to use Go 1.25.
.github/workflows/validate-components.yml Updates component validation workflows to use Go 1.25.

@djsly djsly changed the title [cherry-pick v20260304] fix(security): bump Go to 1.25.10 and golang.org/x/net to v0.55.0 [IcM 796913379] [cherry-pick v20260304] fix(security): bump Go to 1.25.10 and golang.org/x/net to v0.55.0 May 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants