Kubernetes - Orchestration de containers
Find a file
Davanum Srinivas c825d80bbf Update security-critical authentication and protobuf dependencies
This PR updates security-critical dependencies addressing authentication
and data parsing vulnerabilities.

**Authentication Security:**
- github.com/coreos/go-oidc: v2.3.0 -> v2.5.0
  - Security fix: Now verifies token signature BEFORE validating payload
  - Prevents potential processing of tampered tokens before cryptographic
    verification

- github.com/cyphar/filepath-securejoin: v0.6.0 -> v0.6.1
  - Security fix: Fixed seccomp fallback logic - library now properly falls
    back to safer O_PATH resolver when openat2(2) is denied by seccomp-bpf
  - Fixed file descriptor leak in openat2 wrapper during RESOLVE_IN_ROOT

- cyphar.com/go-pathrs: v0.2.1 -> v0.2.2
  - Companion update to filepath-securejoin

**Protobuf Security:**
- google.golang.org/protobuf: v1.36.8 -> v1.36.11
  - Security fix: Added recursion limit check in lazy decoding validation
  - Prevents potential stack exhaustion attacks via maliciously crafted
    protobuf messages
  - Also adds support for URL chars in type URLs in text-format

These updates are critical for:
- OIDC authentication in kube-apiserver
- Container filesystem path resolution (used by container runtimes)
- Protobuf message parsing throughout the codebase

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2026-01-13 16:56:16 -05:00
.github update pr template issue links section 2025-06-06 10:40:00 -04:00
api define endpointslice.endpoints as optional 2026-01-08 17:12:25 +00:00
build Merge pull request #135687 from yashsingh74/cni-bump 2026-01-10 04:57:41 +05:30
CHANGELOG CHANGELOG: Update directory for v1.35.0 release 2025-12-17 13:01:55 +00:00
cluster upgrade containerd version to v2.1+ 2026-01-13 18:13:52 +08:00
cmd Merge pull request #136127 from carlory/fix-3279 2026-01-12 15:24:10 +05:30
docs Make root approval non-recursive 2022-10-10 08:26:53 -04:00
e2e_dra testing: partial revert of E2E + DRA upgrade/downgrade 2026-01-11 09:55:17 +01:00
hack Merge pull request #135432 from pohly/apimachinery-featuregate-contextual-logging 2026-01-14 01:11:35 +05:30
LICENSES Update to github.com/google/cadvisor v0.55.1 2025-12-21 08:13:06 -05:00
logo logo: better alignment of layers 2022-10-19 12:17:25 -07:00
pkg Merge pull request #136077 from kannon92/sync-mutable-pod-mutable-scheduling-suspend-check 2026-01-14 01:11:42 +05:30
plugin locked the feature-gate VolumeAttributesClass to default (true) and switch storage version from v1beta1 to v1 2025-12-18 15:59:33 +08:00
staging Update security-critical authentication and protobuf dependencies 2026-01-13 16:56:16 -05:00
test Merge pull request #136086 from richabanker/graduate-watch_list_duration_seconds-BETA 2026-01-13 15:29:37 +05:30
third_party build: remove deprecated '// +build' tag 2025-12-18 12:16:21 +01:00
vendor Update security-critical authentication and protobuf dependencies 2026-01-13 16:56:16 -05:00
.generated_files remove clearly unnecessary lingering BUILD file references 2022-10-04 16:47:25 -07:00
.gitattributes Mark api/openapi-spec/**/*.json as generated files 2024-10-28 13:33:50 -07:00
.gitignore Generate go.work files 2024-02-29 00:22:06 -08:00
.go-version Bump images and versions to go 1.25.5 and distroless iptables 2025-12-05 10:40:45 +01:00
CHANGELOG.md Revert "Add link to to file" 2023-01-05 15:53:04 +08:00
code-of-conduct.md
CONTRIBUTING.md Remove stale analytics links from docs 2020-11-18 07:04:48 -06:00
go.mod Update security-critical authentication and protobuf dependencies 2026-01-13 16:56:16 -05:00
go.sum Update security-critical authentication and protobuf dependencies 2026-01-13 16:56:16 -05:00
go.work bump go language version to 1.25 2025-09-17 14:56:07 -07:00
go.work.sum Update golang.org/x dependencies to latest versions 2026-01-11 16:26:07 -05:00
LICENSE
Makefile
OWNERS add go.work.sum to dep-approvers file list 2025-09-17 14:12:48 -07:00
OWNERS_ALIASES Merge pull request #135156 from elmiko/update-cloud-provider-owners 2025-12-20 14:06:38 -08:00
README.md Fix Borg pub link in README 2024-12-23 00:15:17 +03:30
SECURITY_CONTACTS Update SECURITY_CONTACTS 2023-10-10 14:45:43 +00:00
SUPPORT.md Update SUPPORT.md 2022-06-27 16:58:44 +02:00

Kubernetes (K8s)

CII Best Practices Go Report Card GitHub release (latest SemVer)


Kubernetes, also known as K8s, is an open source system for managing containerized applications across multiple hosts. It provides basic mechanisms for the deployment, maintenance, and scaling of applications.

Kubernetes builds upon a decade and a half of experience at Google running production workloads at scale using a system called Borg, combined with best-of-breed ideas and practices from the community.

Kubernetes is hosted by the Cloud Native Computing Foundation (CNCF). If your company wants to help shape the evolution of technologies that are container-packaged, dynamically scheduled, and microservices-oriented, consider joining the CNCF. For details about who's involved and how Kubernetes plays a role, read the CNCF announcement.


To start using K8s

See our documentation on kubernetes.io.

Take a free course on Scalable Microservices with Kubernetes.

To use Kubernetes code as a library in other applications, see the list of published components. Use of the k8s.io/kubernetes module or k8s.io/kubernetes/... packages as libraries is not supported.

To start developing K8s

The community repository hosts all information about building Kubernetes from source, how to contribute code and documentation, who to contact about what, etc.

If you want to build Kubernetes right away there are two options:

You have a working Go environment.
git clone https://github.com/kubernetes/kubernetes
cd kubernetes
make
You have a working Docker environment.
git clone https://github.com/kubernetes/kubernetes
cd kubernetes
make quick-release

For the full story, head over to the developer's documentation.

Support

If you need support, start with the troubleshooting guide, and work your way through the process that we've outlined.

That said, if you have questions, reach out to us one way or another.

Community Meetings

The Calendar has the list of all the meetings in the Kubernetes community in a single location.

Adopters

The User Case Studies website has real-world use cases of organizations across industries that are deploying/migrating to Kubernetes.

Governance

Kubernetes project is governed by a framework of principles, values, policies and processes to help our community and constituents towards our shared goals.

The Kubernetes Community is the launching point for learning about how we organize ourselves.

The Kubernetes Steering community repo is used by the Kubernetes Steering Committee, which oversees governance of the Kubernetes project.

Roadmap

The Kubernetes Enhancements repo provides information about Kubernetes releases, as well as feature tracking and backlogs.