—
GO-2026-5630
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
Quick fix
GO-2026-5630 — github.com/tektoncd/pipeline: upgrade to the fixed version with the command below.
go get github.com/tektoncd/pipeline@v1.0.2 Details
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/tektoncd/pipeline
Introduced in:
0.43.0 Fixed in: 1.0.2 Fix
go get github.com/tektoncd/pipeline@v1.0.2 References
- https://github.com/tektoncd/pipeline/security/advisories/GHSA-rmx9-2pp3-xhcr [ADVISORY]
- https://github.com/tektoncd/pipeline/commit/2c398711e6e9e232180508f0648425a8ea34dc9e [FIX]
- https://github.com/tektoncd/pipeline/commit/b8905600322aa86327baae0a7c04d6cf1207362a [FIX]
- https://github.com/tektoncd/pipeline/releases/tag/v1.11.0 [WEB]