Skip to content

Conversation

@Sumynwa
Copy link

@Sumynwa Sumynwa commented Jan 6, 2026

Bump the github.com/sirupsen/logrus version to 1.9.3 across our components where it is back-level to bring us up-to-date and resolve high severity CVE-2025-65637

(cherry picked from commit 9eba559)

Merge Checklist
  • Followed patch format from upstream recommendation: https://github.com/kata-containers/community/blob/main/CONTRIBUTING.md#patch-format
  • Included a single commit in a given PR - at least unless there are related commits and each makes sense as a change on its own.
  • Merged using "create a merge commit" rather than "squash and merge" (or similar)
  • genPolicy only: Builds on Windows
  • genPolicy only: Updated sample YAMLs' policy annotations, if applicable
Summary

Cherry-pick upstream fix for CVE-2025-65637 to bump version of sirupsen/logrus

Associated issues
Links to CVEs

https://nvd.nist.gov/vuln/detail/CVE-2025-65637

Test Methodology

Local Build:
src/tools/csi-kata-directvolume/
src/tools/log-parser

Bump the github.com/sirupsen/logrus version to 1.9.3
across our components where it is back-level to bring us
up-to-date and resolve high severity CVE-2025-65637

Signed-off-by: stevenhorsman <steven@uk.ibm.com>
(cherry picked from commit 9eba559)
@Sumynwa Sumynwa marked this pull request as ready for review January 6, 2026 07:57
@Sumynwa Sumynwa requested review from a team as code owners January 6, 2026 07:57
@Sumynwa Sumynwa merged commit a207f85 into msft-main Jan 9, 2026
82 of 95 checks passed
@Sumynwa Sumynwa deleted the sumsharma/CVE-2025-65637 branch January 9, 2026 05:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants