chore: secrets-store-provider-azure v1.8.2-5 - #9282
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Updates the cached Azure Secrets Store CSI provider image for Linux VHDs to address vulnerabilities and incorporate upstream fixes.
Changes:
- Updates
v1.7.2→v1.8.2-5. - Applies the multi-architecture image across supported Linux VHD variants.
Package Update Analysis: secrets-store-provider-azure
Version change: v1.7.2 → v1.8.2-5 (minor update)
OS variants affected: Ubuntu, Azure Linux/Mariner, Flatcar, Azure Container Linux
OS variants NOT updated: Windows—not applicable to this entry
| Change | Description | Risk |
|---|---|---|
| Feature | Adds AKS identity-binding support | 🟡 Medium |
| Security | Secures provider socket permissions using umask |
🟢 Low |
| Bug fix | Prevents JSON logger nil panics | 🟢 Low |
| Bug fix | Corrects managed-identity client ID handling | 🟢 Low |
| Bug fix | Corrects UNIX-socket health-check parsing | 🟢 Low |
| Dependencies | Updates Go, Kubernetes, crypto, gRPC, and telemetry dependencies | 🟡 Medium |
No API-breaking changes are documented in the v1.8.1 or v1.8.2 releases. The MCR-specific -5 rebuild has no separate public changelog, so its precise CVE and image-size impact could not be verified.
Overall Risk: 🟡 Medium
Recommendation: Validate image availability, architecture manifests, and VHD caching before merge.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
What this PR does / why we need it:
/kind feature
Which issue(s) this PR fixes:
For CVE fix.