—
GO-2026-5630
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
Quick fix
GO-2026-5630 — github.com/tektoncd/pipeline: upgrade to the fixed version with the command below.
go get github.com/tektoncd/pipeline@v1.0.2Details
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/tektoncd/pipeline
Introduced in:
0.43.0Fixed in: 1.0.2Fix
go get github.com/tektoncd/pipeline@v1.0.2References
- https://github.com/tektoncd/pipeline/security/advisories/GHSA-rmx9-2pp3-xhcr[ADVISORY]
- https://github.com/tektoncd/pipeline/commit/2c398711e6e9e232180508f0648425a8ea34dc9e[FIX]
- https://github.com/tektoncd/pipeline/commit/b8905600322aa86327baae0a7c04d6cf1207362a[FIX]
- https://github.com/tektoncd/pipeline/releases/tag/v1.11.0[WEB]