Skip to content

fix(security): remediate CVE vulnerabilities for release-0.4 - #51

Merged
ulucinar merged 1 commit into
release-0.4from
fix/cve-remediation-release-0.4-20260915-163727
Sep 15, 2026
Merged

ulucinar merged 1 commit into
release-0.4from
fix/cve-remediation-release-0.4-20260915-163727

Conversation

@upbound-bot

Copy link
Copy Markdown

Summary

This PR fixes CVE vulnerabilities identified by security scanning.

Vulnerabilities Fixed

CVE/GHSA Severity Package Fixed Version
GHSA-vp52-pcj8-j9qc High google.golang.org/grpc v1.83.2
GHSA-qc2q-p7wx-3px3 Medium google.golang.org/grpc v1.83.2
GHSA-2v4p-qf9q-27wj High google.golang.org/grpc v1.83.2
GO-2026-6355 High golang.org/x/crypto v0.56.0
GO-2026-6303 High golang.org/x/crypto v0.56.0
GO-2026-6354 High golang.org/x/crypto v0.56.0

Changes Made

  • Updated google.golang.org/grpc from v1.82.1 to v1.83.2
  • Updated golang.org/x/crypto from v0.53.0 to v0.56.0
  • Updated Go toolchain from 1.25.13 to 1.26.6
  • Updated GO_VERSION in .github/workflows/ci.yml to 1.26.6
  • Ran go mod tidy to update dependencies

References

Verification

  • Rescanned with cve-scan skill after fixes
  • All listed vulnerabilities resolved

- Update google.golang.org/grpc to v1.83.2 (fixes GHSA-vp52-pcj8-j9qc, GHSA-qc2q-p7wx-3px3, GHSA-2v4p-qf9q-27wj)
- Update golang.org/x/crypto to v0.56.0 (fixes GO-2026-6355, GO-2026-6303, GO-2026-6354)
- Update Go version to 1.26.6
- Update CI workflow Go version to 1.26.6

Signed-off-by: Alper Rifat Ulucinar <ulucinar@users.noreply.github.com>
@ulucinar
ulucinar merged commit b9cc1cb into release-0.4 Sep 15, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants