trust-manager is the easiest way to manage security-critical TLS trust bundles in Kubernetes and OpenShift clusters.
This release is a patch release, upgrading Go from 1.25.1 to 1.25.3, fixing a range of CVEs: CVE-2025-61724
, CVE-2025-58187
, CVE-2025-47912
, CVE-2025-58183
, CVE-2025-61723
, CVE-2025-58186
, CVE-2025-58185
, CVE-2025-58188
, and CVE-2025-61725
.
Furthermore, additional go dependencies were upgraded where possible.
What's Changed
- [CI] Merge self-upgrade-main into main by @octo-sts[bot] in #775
- fix(deps): update module sigs.k8s.io/controller-runtime to v0.22.3 by @octo-sts[bot] in #773
- Bump trust package suffix, forcing a new go 1.25.3 build by @inteon in #776
Full Changelog: v0.20.1...v0.20.2