What would you like to be added?
After releasing 3.6.13 (#22016), we didn't bump golang.org/x/net in the release-3.6 branch, which has CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-42502 (HIGH), CVE-2026-25680 and CVE-2026-42506 (MEDIUM).
Why is this needed?
To keep our images without reported CVEs.
What would you like to be added?
After releasing 3.6.13 (#22016), we didn't bump
golang.org/x/netin the release-3.6 branch, which has CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-42502 (HIGH), CVE-2026-25680 and CVE-2026-42506 (MEDIUM).Why is this needed?
To keep our images without reported CVEs.