Security update for elemental-toolkit, elemental-operator
Details
This update for elemental-toolkit, elemental-operator fixes the following issues:
elemental-operator:
Update to v1.7.4:
Bump github.com/rancher-sandbox/go-tpm and its dependencies
This bump includes few CVE fixes:
* bsc#1241826 (CVE-2025-22872)
* bsc#1241857 (CVE-2025-22872)
* bsc#1251511 (CVE-2025-47911)
* bsc#1251679 (CVE-2025-58190)
Install yip config files in before-install step
Revert "Do not delete ManagedOSVersions by default"
Set default channel variable names consistent with OS version
Do not delete ManagedOSVersions by default
Include -channel suffix to channel names
OS channel: enable baremetal channel by default
elemental-toolkit:
Update to v2.2.7:
Bump toolkit build to go 1.24
Bump golang.org/x/crypto library
This bumg includes few CVE fixes:
* bsc#1241826 (CVE-2025-22872)
* bsc#1241857 (CVE-2025-22872)
* bsc#1251511 (CVE-2025-47911)
* bsc#1251679 (CVE-2025-58190)
* bsc#1253581 (CVE-2025-47913)
* bsc#1253901 (CVE-2025-58181)
* bsc#1254079 (CVE-2025-47914)