Overview
Important
This is a recommended release for all op-proposer operators. It contains dependency and container base image updates that clear reported CVEs, with no behaviour changes.
What's Changed
Security
golang.org/x/cryptoupdated to 0.56.0, clearingCVE-2026-56855andCVE-2026-78662. Both are denial-of-service issues ingolang.org/x/crypto/ssh, which op-proposer does not link — the upgrade clears the reported findings rather than closing a reachable path (#22750)- The container image now ships zlib 1.3.2-r7, clearing
CVE-2026-85091
Full Changelog: op-proposer/v1.16.4...op-proposer/v1.16.5
🚢 Docker Image: