Skip to content

[cherry-pick v20260330] fix(security): bump Go to 1.25.10 and golang.org/x/net to v0.55.0#8575

Open
djsly wants to merge 1 commit into
official/v20260330from
djsly/icm-796913379-cve-go-1.25.10-v20260330
Open

[cherry-pick v20260330] fix(security): bump Go to 1.25.10 and golang.org/x/net to v0.55.0#8575
djsly wants to merge 1 commit into
official/v20260330from
djsly/icm-796913379-cve-go-1.25.10-v20260330

Conversation

@djsly
Copy link
Copy Markdown
Collaborator

@djsly djsly commented May 22, 2026

Summary

Cherry-pick of #8551 to official/vv20260330.

Bumps the Go toolchain and golang.org/x/net to address upstream CVEs:

Vulnerability CVE Component Fixed by
net/mail DoS via crafted addresses CVE-2026-39820 net/mail (stdlib) Go 1.25.10
cmd/go pack subcommand directory traversal CVE-2026-39817 cmd/go (stdlib) Go 1.25.10
HTTP/2 + IPv6 host parsing fixes (various, see x/net release notes) golang.org/x/net v0.55.0

Why bump to Go 1.25 (and not a 1.24.x patch)

Go 1.24 reached EOL in February 2026 and does NOT receive security backports. go1.25.10 is the only release stream that contains these fixes.

golang.org/x/net v0.51.0+ also requires go 1.25.0 in its own go.mod, so the Go bump is required regardless.

Verification

  • go mod tidy succeeds for every module in the branch.
  • go build ./... clean across every module.
  • PR CI must pull go 1.25 runners.

Release plan

Once merged, two tags are pushed off the resulting commit:

  • v0.v20260330.<N+1> (AgentBaker module)
  • aks-node-controller/v0.v20260330.<N+1> (aks-node-controller submodule)

🤖 Generated with GitHub Copilot CLI

IcM 796913379

Backport of #8551 to official/v20260330.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions
Copy link
Copy Markdown
Contributor

Changes cached containers or packages on windows VHDs

Please get a Windows SIG member to approve.

The following dif file shows any additions or deletions from what will be cached on windows VHDs organised by VHD type.

  • Additions are new things cached.
  • Deletions are things no longer cached.
diff --git a/vhd_files/2022-containerd-gen2.txt b/vhd_files/2022-containerd-gen2.txt
index 88166c3..cfac7fb 100644
--- a/vhd_files/2022-containerd-gen2.txt
+++ b/vhd_files/2022-containerd-gen2.txt
@@ -4 +4 @@ c:\akse-cache\: https://packages.aks.azure.com/ccgakvplugin/v1.1.5/binaries/wind
-c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.1.2/windows-amd64.zip
+c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.0.2/windows-amd64.zip
@@ -28,2 +28,3 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.32.12/windo
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.10/windowszip/v1.33.10-1int.zip
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.11/windowszip/v1.33.11-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.7/windowszip/v1.33.7-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.8/windowszip/v1.33.8-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.3/windowszip/v1.34.3-1int.zip
@@ -31 +31,0 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.4/window
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.7/windowszip/v1.34.7-1int.zip
@@ -44 +43,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\14
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1491587726=1
@@ -69 +67,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\36
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\3658215055=1
@@ -76 +73,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\41
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\4173449358=1
@@ -106,3 +103,3 @@ mcr.microsoft.com/containernetworking/azure-cni:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cni:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.7.15-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.8.1-0
@@ -110,3 +107,9 @@ mcr.microsoft.com/containernetworking/azure-cns:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cns:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.7.15-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.8.1-0
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.9-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.8-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.3-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc
@@ -115,8 +118,5 @@ mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.7.2
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.3-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.10-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.5-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.6-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.2-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.3-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.2-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.4-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.1-windows-hp
@@ -128,3 +128,6 @@ mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.4
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.11-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.8-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.30.15-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.1-windows-hpc-1
@@ -133,2 +136,2 @@ mcr.microsoft.com/windows/nanoserver:ltsc2022
-mcr.microsoft.com/windows/servercore:10.0.20348.5020
-mcr.microsoft.com/windows/servercore:10.0.20348.5139
+mcr.microsoft.com/windows/servercore:10.0.20348.4773
+mcr.microsoft.com/windows/servercore:10.0.20348.4893
@@ -140 +143 @@ Windows 2022-containerd-gen2 base image sku: 2022-datacenter-core-smalldisk-g2
-Windows 2022-containerd-gen2 base version: 20348.5139.260507
+Windows 2022-containerd-gen2 base version: 20348.4893.260303
diff --git a/vhd_files/2022-containerd.txt b/vhd_files/2022-containerd.txt
index b3f76e6..f57c982 100644
--- a/vhd_files/2022-containerd.txt
+++ b/vhd_files/2022-containerd.txt
@@ -4 +4 @@ c:\akse-cache\: https://packages.aks.azure.com/ccgakvplugin/v1.1.5/binaries/wind
-c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.1.2/windows-amd64.zip
+c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.0.2/windows-amd64.zip
@@ -28,2 +28,3 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.32.12/windo
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.10/windowszip/v1.33.10-1int.zip
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.11/windowszip/v1.33.11-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.7/windowszip/v1.33.7-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.8/windowszip/v1.33.8-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.3/windowszip/v1.34.3-1int.zip
@@ -31 +31,0 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.4/window
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.7/windowszip/v1.34.7-1int.zip
@@ -44 +43,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\14
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1491587726=1
@@ -69 +67,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\36
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\3658215055=1
@@ -76 +73,0 @@ HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\41
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\4173449358=1
@@ -106,3 +103,3 @@ mcr.microsoft.com/containernetworking/azure-cni:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cni:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.7.15-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.8.1-0
@@ -110,3 +107,9 @@ mcr.microsoft.com/containernetworking/azure-cns:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cns:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.7.15-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.8.1-0
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.9-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.8-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.3-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc
@@ -115,8 +118,5 @@ mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.7.2
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.3-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.10-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.5-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.6-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.2-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.3-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.2-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.4-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.1-windows-hp
@@ -128,3 +128,6 @@ mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.4
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.11-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.8-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.30.15-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.1-windows-hpc-1
@@ -133,2 +136,2 @@ mcr.microsoft.com/windows/nanoserver:ltsc2022
-mcr.microsoft.com/windows/servercore:10.0.20348.5020
-mcr.microsoft.com/windows/servercore:10.0.20348.5139
+mcr.microsoft.com/windows/servercore:10.0.20348.4773
+mcr.microsoft.com/windows/servercore:10.0.20348.4893
@@ -140 +143 @@ Windows 2022-containerd base image sku: 2022-Datacenter-Core-smalldisk
-Windows 2022-containerd base version: 20348.5139.260507
+Windows 2022-containerd base version: 20348.4893.260303
diff --git a/vhd_files/2025-gen2.txt b/vhd_files/2025-gen2.txt
index 7baa7a5..d31b59b 100644
--- a/vhd_files/2025-gen2.txt
+++ b/vhd_files/2025-gen2.txt
@@ -4 +4 @@ c:\akse-cache\: https://packages.aks.azure.com/ccgakvplugin/v1.1.5/binaries/wind
-c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.1.2/windows-amd64.zip
+c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.0.2/windows-amd64.zip
@@ -15 +14,0 @@ c:\akse-cache\csi-proxy\: https://packages.aks.azure.com/csi-proxy/v1.1.2-hotfix
-c:\akse-cache\wcn\: mcr.microsoft.com/wcn/package:1.7.0-cpu-arch
@@ -26,2 +25,3 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.32.12/windo
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.10/windowszip/v1.33.10-1int.zip
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.11/windowszip/v1.33.11-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.7/windowszip/v1.33.7-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.8/windowszip/v1.33.8-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.3/windowszip/v1.34.3-1int.zip
@@ -29 +28,0 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.4/window
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.7/windowszip/v1.34.7-1int.zip
@@ -32,2 +30,0 @@ c:\akse-cache\win-vnet-cni\: https://packages.aks.azure.com/azure-cni/v1.6.21/bi
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1451608719=1
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1861198479=1
@@ -36,3 +33,3 @@ mcr.microsoft.com/containernetworking/azure-cni:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cni:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.7.15-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.8.1-0
@@ -40,3 +37,9 @@ mcr.microsoft.com/containernetworking/azure-cns:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cns:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.7.15-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.8.1-0
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.9-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.8-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.3-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc
@@ -45,8 +48,5 @@ mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.7.2
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.3-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.10-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.5-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.6-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.2-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.3-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.2-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.4-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.1-windows-hp
@@ -58,3 +58,6 @@ mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.4
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.11-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.8-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.30.15-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.1-windows-hpc-1
@@ -64,4 +67,4 @@ mcr.microsoft.com/windows/nanoserver:ltsc2025
-mcr.microsoft.com/windows/servercore:10.0.20348.5020
-mcr.microsoft.com/windows/servercore:10.0.20348.5139
-mcr.microsoft.com/windows/servercore:10.0.26100.32690
-mcr.microsoft.com/windows/servercore:10.0.26100.32860
+mcr.microsoft.com/windows/servercore:10.0.20348.4773
+mcr.microsoft.com/windows/servercore:10.0.20348.4893
+mcr.microsoft.com/windows/servercore:10.0.26100.32370
+mcr.microsoft.com/windows/servercore:10.0.26100.32522
@@ -71,2 +73,0 @@ mcr.microsoft.com/windows/servercore/iis:windowsservercore-ltsc2025
-Windows 2025-gen2 base image offer: WindowsServer
-Windows 2025-gen2 base image publisher: MicrosoftWindowsServer
@@ -74 +75 @@ Windows 2025-gen2 base image sku: 2025-datacenter-core-smalldisk-g2
-Windows 2025-gen2 base version: 26100.32860.260510
+Windows 2025-gen2 base version: 26100.32522.260306
diff --git a/vhd_files/2025.txt b/vhd_files/2025.txt
index f747f05..03661ca 100644
--- a/vhd_files/2025.txt
+++ b/vhd_files/2025.txt
@@ -4 +4 @@ c:\akse-cache\: https://packages.aks.azure.com/ccgakvplugin/v1.1.5/binaries/wind
-c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.1.2/windows-amd64.zip
+c:\akse-cache\aks-secure-tls-bootstrap-client\: https://github.com/Azure/aks-secure-tls-bootstrap/releases/download/client/v1.0.2/windows-amd64.zip
@@ -15 +14,0 @@ c:\akse-cache\csi-proxy\: https://packages.aks.azure.com/csi-proxy/v1.1.2-hotfix
-c:\akse-cache\wcn\: mcr.microsoft.com/wcn/package:1.7.0-cpu-arch
@@ -26,2 +25,3 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.32.12/windo
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.10/windowszip/v1.33.10-1int.zip
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.11/windowszip/v1.33.11-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.7/windowszip/v1.33.7-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.33.8/windowszip/v1.33.8-1int.zip
+c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.3/windowszip/v1.34.3-1int.zip
@@ -29 +28,0 @@ c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.4/window
-c:\akse-cache\win-k8s\: https://packages.aks.azure.com/kubernetes/v1.34.7/windowszip/v1.34.7-1int.zip
@@ -32,2 +30,0 @@ c:\akse-cache\win-vnet-cni\: https://packages.aks.azure.com/azure-cni/v1.6.21/bi
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1451608719=1
-HKLM:\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\1861198479=1
@@ -36,3 +33,3 @@ mcr.microsoft.com/containernetworking/azure-cni:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cni:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cni:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.7.15-0
+mcr.microsoft.com/containernetworking/azure-cni:v1.8.1-0
@@ -40,3 +37,9 @@ mcr.microsoft.com/containernetworking/azure-cns:v1.5.50
-mcr.microsoft.com/containernetworking/azure-cns:v1.6.43-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.7.16-0
-mcr.microsoft.com/containernetworking/azure-cns:v1.8.6-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.6.35-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.7.15-0
+mcr.microsoft.com/containernetworking/azure-cns:v1.8.1-0
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.31.9-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.32.8-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.3-windows-hpc
+mcr.microsoft.com/oss/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc
@@ -45,8 +48,5 @@ mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.7.2
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.3-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.10-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.9-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.5-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.6-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.2-windows-hp
-mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.3-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.2-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.33.8-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.4-windows-hp
+mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.1-windows-hp
@@ -58,3 +58,6 @@ mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.4
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.11-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.8-windows-hpc-1
-mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.30.15-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.31.12-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.32.11-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.33.6-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.3-windows-hpc-1
+mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.35.1-windows-hpc-1
@@ -64,4 +67,4 @@ mcr.microsoft.com/windows/nanoserver:ltsc2025
-mcr.microsoft.com/windows/servercore:10.0.20348.5020
-mcr.microsoft.com/windows/servercore:10.0.20348.5139
-mcr.microsoft.com/windows/servercore:10.0.26100.32690
-mcr.microsoft.com/windows/servercore:10.0.26100.32860
+mcr.microsoft.com/windows/servercore:10.0.20348.4773
+mcr.microsoft.com/windows/servercore:10.0.20348.4893
+mcr.microsoft.com/windows/servercore:10.0.26100.32370
+mcr.microsoft.com/windows/servercore:10.0.26100.32522
@@ -71,2 +73,0 @@ mcr.microsoft.com/windows/servercore/iis:windowsservercore-ltsc2025
-Windows 2025 base image offer: WindowsServer
-Windows 2025 base image publisher: MicrosoftWindowsServer
@@ -74 +75 @@ Windows 2025 base image sku: 2025-datacenter-core-smalldisk
-Windows 2025 base version: 26100.32860.260510
+Windows 2025 base version: 26100.32522.260306

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Cherry-picks a security update onto official/vv20260330 to remediate upstream CVEs by bumping the Go toolchain to 1.25.10 and updating golang.org/x/net (and related x/* transitive deps) across all Go modules and CI workflows. This aligns the repo’s build/test environment with supported Go versions and refreshes dependency sums, plus includes a small go vet-driven fix in e2e config code.

Changes:

  • Bump go directive to 1.25.10 across all modules and refresh go.sum files via go mod tidy.
  • Update golang.org/x/net to v0.55.0 (and associated golang.org/x/* versions) where applicable.
  • Update GitHub Actions workflows to run with Go 1.25, and fix an invalid %w usage in fmt.Sprintf in e2e config.

Reviewed changes

Copilot reviewed 15 out of 18 changed files in this pull request and generated no comments.

Show a summary per file
File Description
go.mod Bumps root module Go version; updates x/net/x/sys/x/text; reflects tidy changes in direct vs indirect requires.
go.sum Updates dependency checksums consistent with the module tidying after the version bumps.
e2e/go.mod Bumps Go version; updates x/crypto and x/net (indirect) and related x/* deps.
e2e/go.sum Updates e2e module checksums for updated golang.org/x/* versions.
e2e/config/config.go Fixes incorrect %w formatting verb in fmt.Sprintf to avoid go vet failures.
aks-node-controller/go.mod Bumps Go version and updates golang.org/x/sys (indirect).
aks-node-controller/go.sum Updates checksums for updated golang.org/x/* versions.
hack/tools/go.mod Bumps tools module Go version.
image-fetcher/go.mod Bumps image-fetcher module Go version.
vhdbuilder/lister/go.mod Bumps lister module Go version.
vhdbuilder/prefetch/go.mod Bumps prefetch module Go version.
.github/workflows/check-coverage.yml Updates CI to use Go 1.25 for coverage job.
.github/workflows/copilot-setup-steps.yml Updates Copilot setup workflow to use Go 1.25.
.github/workflows/go-test.yml Updates unit test workflow to use Go 1.25.
.github/workflows/golangci-lint.yml Updates golangci-lint workflow to use Go 1.25.
.github/workflows/shellcheck.yml Updates shellcheck workflow to use Go 1.25.
.github/workflows/shellspec.yaml Updates shellspec workflow to use Go 1.25.
.github/workflows/validate-components.yml Updates component validation workflow to use Go 1.25.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants