[High] Patch prometheus-adapter for CVE-2026-33186 - #18382
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
Patch Analysis: Backports upstream grpc/grpc-go@72186f1 to the vendored grpc-go v1.60.1 in prometheus-adapter 0.12.0. Fix: the server previously accepted requests whose Only Adapted to v1.60.1 API (upstream targets v1.79.3):
|
|
Buddy Build has passed and patch applies cleanly.
|
jslobodzian
left a comment
There was a problem hiding this comment.
Spec review clean (patches referenced + applied, changelog version/release match). PR-check build succeeded with pTests passing on AMD64 and ARM64. Approved.
|
Auto cherry-pick results:
Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1182731&view=results |
|
Auto cherry-pick results:
Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1182731&view=results |

Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
Patch prometheus-adapter for CVE-2026-33186
Change Log
Does this affect the toolchain?
NO
Associated issues
Links to CVEs
Test Methodology