Bump github.com/containerd/containerd from 1.7.33 to 1.7.35 - #515
LouisLotter merged 3 commits into
Conversation
7d6cb8c to
5d02d81
Compare
|
Independent review at All three exact-head workflows still fail; empty registry credentials block prerequisites. Restore the authorized CI credential path and reconcile the held writer claim before source work, then obtain green checks, architecture-specific artifact evidence and independent review of the changed head. Reviewer and exact tidy diff; coordination. Critical curl work and #511's human disposition remain separate. |
|
Recovery checkpoint 2026-09-15: signed head Full repository Bazel sync/tidy is running; focused validation and production artifact evidence remain pending. Python 3.12 DDA setup succeeds; pinned golangci-lint installation is underway. New PR runs: lint Coordination: https://github.com/StackVista/cve-reporter/issues/29. Curl/Python/#511 remain deferred. Final independent review remains required. |
|
Source correction complete at signed head Validation completed: repository Bazel mod tidy → Go work sync → all-module tidy → Bazel mod tidy → Gazelle; all 186 workspace modules subsequently pass Final-head automatic runs are terminal cancelled: lint Coordination: https://github.com/StackVista/cve-reporter/issues/29. Final independent review remains required; curl/Python/#511 and delivery scan are unchanged/outside scope. |
|
Local amd64 production agent build succeeded from signed head Agent binary SHA-256: |
|
Bounded correction complete at signed head Passed: full repository Bazel sync/tidy/Gazelle; subsequent tidy-diff checks for all 186 workspace modules; containerd package tests; OTel workspace and standalone tests; all four upstream cancellation regression cases; amd64/arm64 workspace and standalone graphs selecting containerd 1.7.35. Focused lint fails on the unchanged unused Local artifacts from this head:
The stripped agent extracted from the DEB has SHA-256 Remaining blockers: image export failed twice on Docker's same content-writer lock ( Final-head runs are terminal cancelled, zero artifacts: lint Specific next action: independent review of this exact head, plus an approved native amd64/arm64 validation environment. Existing Coordination: https://github.com/StackVista/cve-reporter/issues/29; prior body update verified. Supervisor handoff: source progress is pushed; remaining environment/publication-boundary decisions warrant To triage, not In review. Curl/Python/#511 remain held; verified scan identity and unavailable Elasticsearch coverage gap are unchanged. No merge, publication, deployment, new scan, or exception decision occurred. No readiness or closure claim. |
Bumps [github.com/containerd/containerd](https://github.com/containerd/containerd) from 1.7.33 to 1.7.35. - [Release notes](https://github.com/containerd/containerd/releases) - [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md) - [Commits](containerd/containerd@v1.7.33...v1.7.35) --- updated-dependencies: - dependency-name: github.com/containerd/containerd dependency-version: 1.7.35 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Full Bazel sync/tidy/Gazelle completed; all 186 workspace modules pass tidy -diff. Restore OTel graph requirements and remove unused checksums. Keep containerd release dependencies, remove unrelated E2E dependency increases that propagated through the workspace. Production artifact validation remains pending.
d3ee212 to
0ef66af
Compare
There was a problem hiding this comment.
🔵 Needs a closer look
The security dependency update affects cross-platform container integrations and still requires fresh CI validation on the rebased head.
Pull request overview
Updates containerd to 1.7.35 to address CVE-2026-53495 and synchronizes Go/Bazel dependency metadata.
Changes:
- Upgrades containerd and its API module.
- Reconciles transitive Go dependencies and checksums.
- Exposes the Prometheus repository to Bazel.
File summaries
| File | Description |
|---|---|
go.mod |
Updates containerd and reconciles transitive versions. |
go.sum |
Updates dependency checksums. |
deps/go.MODULE.bazel |
Adds the required Prometheus Bazel repository. |
Review details
- Files reviewed: 2/3 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
LouisParkin
left a comment
There was a problem hiding this comment.
Reviewed 0ef66af48b6793c640dfc0af56d98a2f453c9279 against stackstate-7.78.2: no blocking findings. The earlier OTel tidy and CI blockers are resolved on this head.
Checked the upstream security fix, dependency graph, Go/Bazel reconciliation, and the agent’s containerd consumers. The additional dependency changes reconcile existing workspace/test requirements; the compatibility replacements for cgroups/runtime-spec remain intact.
Validation:
- Local containerd utility, container check, and workload metadata collector tests pass with Go 1.26.6. Standalone OTel status
go mod tidy -diffpasses. Workspace and standalone resolution select containerd 1.7.35/API 1.9.0 for both architectures. - All three current-head PR workflows pass, including module tidiness, branded/unbranded tests, native binaries, DEBs, branding checks, and image smoke tests.
- Independently inspected both DEBs from run 34949251810: both agent binaries embed containerd 1.7.35/API 1.9.0 and identify merge commit
c50e919bd7, whose parents are this PR head and basec0bda9dbc8.
Image vulnerability scans are report-only; this is not a clean-image or deployment claim. Signing/publication correctly remain skipped on PR runs. This library update does not upgrade the monitored nodes’ containerd daemon.
Update containerd to 1.7.35 for CVE-2026-53495 and reconcile the Go/Bazel dependency manifests. Unrelated E2E upgrades are excluded.
Rebased onto the current
stackstate-7.78.2base, preserving all three signed commits. The dependency changes are unchanged; the updated base includes integrations 7.78.2-6. Prior-head independent source review found no reproducible source blocker, and all three manual CI workflows passed, including amd64/arm64 binaries, DEBs and image validation. Fresh PR checks are required on the rebased head before merge.Tracking: https://github.com/StackVista/cve-reporter/issues/29