| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: kubernetes1.36-proxy | Distribution: openSUSE Tumbleweed |
| Version: 1.36.3 | Vendor: openSUSE |
| Release: 1.1 | Build date: Mon Jul 27 08:16:44 2026 |
| Group: System/Management | Build host: reproducible |
| Size: 49167470 | Source RPM: kubernetes1.36-1.36.3-1.1.src.rpm |
| Packager: https://bugs.opensuse.org | |
| Url: https://kubernetes.io/ | |
| Summary: Kubernetes proxy for container image | |
This subpackage contains the kube-proxy binary for Kubic images
Apache-2.0
* Mon Jul 27 2026 Priyanka Saggu <priyanka.saggu@suse.com>
- CVE-2020-8561: kubernetes: Webhook redirect in kube-apiserver, bsc#1190099
* TL;DR: Please refer to the official blogpost by the upstream Kubernetes project for details on mitigating the CVE: https://kubernetes.io/blog/2026/05/26/reconciling-unfixed-kubernetes-cves/#cve-2020-8561-webhook-redirect-in-kube-apiserver
* ***Important note to users and administrators****
The Issue: The kube-apiserver follows HTTP redirects when communicating with admission webhooks. An actor capable of configuring an AdmissionWebhookConfiguration can redirect API server requests to internal, private networks.
Why it remains unfixed: Restricting this behavior would require breaking the standard HTTP client behavior that many legitimate integrations rely on.
Mitigation: Set the API server log level to less than 10 (to prevent logging response bodies) and disable dynamic profiling (--profiling=false) to prevent unauthorized log-level changes.
* Mon Jul 27 2026 Priyanka Saggu <priyanka.saggu@suse.com>
- Update to version 1.36.3:
* DRA: roll back reserved state in allocateDevice
* Bump images and versions to golang 1.26.5 and update distroless-iptables
* stop logging missing optional container annotations
* Add e2e test for setting maps and slices to null via SSA
* Bump sigs.k8s.io/structured-merge-diff/v6 to v6.3.3
* kubelet startPodSync: reuse the previous context to fix memory leak regression
* Make utf8 replacement char test pass on Go 1.27
* Restore string JSON encoding of cri-api KeyValue
* kubeadm: treat already promoted learner as successful
* kubeadm: use KubernetesAPICallTimeout for mandatory kubeadm-config fetch
* Align DeviceTaintRule informer API version with handlers
* Fix job controller reporting active=0 during pod creation backoff
* flowcontrol: cover Required rule for spec.type and limitResponse.type
* flowcontrol: emit Required when spec.type or limitResponse.type is empty
* test/compatibility_lifecycle: resolve feature names from variables
* kubeadm: skip promote call when etcd member is already a voting member
- Update .spec file to bump go version build requirements:
* `BuildRequires: go >= 1.26.5`
* ref: https://github.com/kubernetes/kubernetes/blob/v1.36.3/.go-version
* Wed Jul 01 2026 Priyanka Saggu <priyanka.saggu@suse.com>
- Update to version 1.36.2:
* Bump images and versions to go 1.26.4 and distroless iptables
* DRA E2E: simplify kind.yaml
* kubeadm: fix dry-run CA copy paths in init certs
* Fix DRA scoring bug with mixed allocated and unallocated claims
* batch/job: Fix scheduling directives mutation for not-yet-started suspended Jobs
* fix(endpoint): avoid panic on services with empty IPFamilies
* fix(csi): preserve mount dir on NodePublish error during remount
* feat(volume): add IsRemount to MounterArgs
* DRA: account for shared devices when rebuilding counters
* Restore ability to plumb binary data through envvar values
* Only emit non-dupicated values as metrics
* Optimize how deletions are handled
* Improve performance characteristic of selinux metric emission
* DRA: fix AllocationModeAll with consumed counters
* Wed May 13 2026 Priyanka Saggu <priyanka.saggu@suse.com>
- Update to version 1.36.1:
* kubeadm: use dedicated ClusterRole for apiserver kubelet client
* KEP-5304: DecodeMetadataFromStream only skips metadata entries with unknown API versions
* DRA: merge same request metadata across drivers
* kubeadm: skip LocalAPIEndpoint defaulting on worker join
* kubeadm: use the localAPIEndpoint for all API calls in 'init'
* kube-proxy: don't do full periodic syncs on large cluster mode
* Delete remote endpoint if it has same ip as local endpoint in the system.
* Delete remote endpoint if it has same ip as local endpoint in the system.
* hack/update-vendor.sh
* register zfs cadvisor plugin
* Add a (*Client) addEndpoint method
* Evaluate etcd cluster health using quorum
* test/localupcluster: stop all components before starting replacements
* localupcluster: set readiness polling interval to 1 second
* localupcluster: properly query /readyz and /healthz
* Escape path inside the container
* Thu Apr 23 2026 Priyanka Saggu <priyanka.saggu@suse.com>
- drop kubeadm-opensuse-flexvolume.patch:
* Patch is no longer needed as upstream kubeadm removed built-in flex volume support entirely in v1.36.
The patch was originally added to align kubeadm's flex volume plugin path with the SUSE kubelet path (/var/lib/kubelet/volume-plugin) on immutable/transactional filesystems (bsc#1084766).
Ref: https://github.com/kubernetes/kubernetes/commit/c7b4a6593bf87e9eb85a366735567c1e72d317a0
* Thu Apr 23 2026 Priyanka Saggu <priyanka.saggu@suse.com>
- initial package for kubernetes v1.36.0
* Full changelog - https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360
/usr/bin/kube-proxy /usr/share/doc/packages/kubernetes1.36-proxy /usr/share/doc/packages/kubernetes1.36-proxy/CONTRIBUTING.md /usr/share/doc/packages/kubernetes1.36-proxy/README.md /usr/share/licenses/kubernetes1.36-proxy /usr/share/licenses/kubernetes1.36-proxy/LICENSE /usr/share/man/man1/kube-proxy.1.gz
Generated by rpm2html 1.8.1
Fabrice Bellet, Mon Aug 3 00:14:01 2026