$ the-wire · showcase
kops adopts patched containerd, grpc unpinned across Kubernetes repos
By RepoJournal · Filed · About Kubernetes · Composed from the cited sources · methodology
Two security-driven dependency moves define the day: kops defaults to containerd 2.3.6 for its CVE fixes, and the gRPC pin keeping Kubernetes and externaljwt on a vulnerable version is lifted to v1.84.0.
containerd: default to 2.3.6 / runc 1.5.1 kubernetes/kops
kops now defaults to containerd 2.3.6, the latest patch of the 2.3 LTS line, which the commit says includes fixes for CVE-2026-53495, GHSA-rp3h-jf77-q9p4 and CVE-2026-53493. Because containerd 2.3.5 and newer pin runc 1.5.1 in script/setup/runc-version, runc moves with it.
Bump google.golang.org/grpc to v1.84.0 and lift its pin kubernetes/kubernetes
google.golang.org/grpc moves to v1.84.0 because v1.82.2 lacked the CVE-2026-84304 fix, which landed in v1.83.1+. The four modules v1.83+ pulls in through cloud.google.com/go/auth are graph-only and recorded in status.unwantedReferences rather than vendored.
kube-proxy: drop the dead cgroup walker from pkg/util/oom kubernetes/kubernetes
ApplyOOMScoreAdjContainer has had no caller since 2017, and its pkg/kubelet/cm/util import dragged opencontainers/cgroups, go-systemd/dbus and godbus into kube-proxy for a single write of /proc/self/oom_score_adj. Removing it also cuts the etcd client, admission and the generic apiserver out of kube-proxy's import graph alongside the pkg/cluster/ports and responsewriters changes.
KEP-5972: Dynamic Containers kubernetes/enhancements
A new KEP proposes Dynamic Containers, described as making containers mutable, and carries an /label api-review tag. It lands under sig node with dchen1107 and haircommander assigned, so the shape of any future container-mutation API will go through that review.
chore(hack): stop generating hashes for unsupported Kubernetes versions kubernetes/kops
generate-asset-hashes.sh was still regenerating k8s-1.25.yaml through k8s-1.31.yaml files that had been deleted when support for those versions was removed, so every run recreated them; the script now stops at the oldest supported version, 1.32. Related assetdata cleanup dropped 14 bogus SHA512 entries whose sha256 value was literally "Hash:", and the dead verify-hashes target is gone.
Action items
- → Rebuild kops clusters on containerd 2.3.6, which carries the CVE-2026-53495, GHSA-rp3h-jf77-q9p4 and CVE-2026-53493 f... kubernetes/kops [immediate]
- → Bump google.golang.org/grpc to v1.84.0 in Go modules pinned at v1.82.2, which lacks the CVE-2026-84304 fix kubernetes/kubernetes [immediate]