Skip to content

[v1.13] Backport CVE-2025-13888: fix CVE namespace-isolation break (#897) - #1141

Open
vulgraph wants to merge 1 commit into
redhat-developer:v1.13from
vulgraph:backport/CVE-2025-13888-v1.13
Open

[v1.13] Backport CVE-2025-13888: fix CVE namespace-isolation break (#897)#1141
vulgraph wants to merge 1 commit into
redhat-developer:v1.13from
vulgraph:backport/CVE-2025-13888-v1.13

Conversation

@vulgraph

@vulgraph vulgraph commented May 4, 2026

Copy link
Copy Markdown

Backport of upstream fix for CVE-2025-13888 to v1.13.

Apply was clean against the current tip of the target branch. No code changes on top of the upstream fix.

What type of PR is this?

Uncomment only one /kind line, and delete the rest.
For example, > /kind bug would simply become: /kind bug

/kind bug
/kind cleanup
/kind failing-test
/kind enhancement
/kind documentation
/kind code-refactoring

What does this PR do / why we need it:

Have you updated the necessary documentation?

  • Documentation update is required by this PR.
  • Documentation has been updated.

Which issue(s) this PR fixes:

Fixes #?

Test acceptance criteria:

  • Unit Test
  • E2E Test

How to test changes / Special notes to the reviewer:

argocd adds cluster monitoring label if the ns contains openshift- prefix

Signed-off-by: Anand Kumar Singh <anandrkskd@gmail.com>
(cherry picked from commit bc6ac3e)
@openshift-ci
openshift-ci Bot requested a review from keithchong May 4, 2026 07:23
@openshift-ci

openshift-ci Bot commented May 4, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign rnapoles-rh for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci
openshift-ci Bot requested a review from svghadi May 4, 2026 07:23
@openshift-ci

openshift-ci Bot commented May 4, 2026

Copy link
Copy Markdown

Hi @vulgraph. Thanks for your PR.

I'm waiting for a redhat-developer member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants