Skip to content

Upgrade google.golang.org/grpc version to 1.79.3#258

Merged
rishiy15 merged 2 commits intomainfrom
bump-grpc-version
Mar 19, 2026
Merged

Upgrade google.golang.org/grpc version to 1.79.3#258
rishiy15 merged 2 commits intomainfrom
bump-grpc-version

Conversation

@rishiy15
Copy link
Contributor

@rishiy15 rishiy15 commented Mar 19, 2026

✨ Summary

Bumping the grpc version to 1.79.3 to address the authorization bypass security vulnerability mentioned here https://github.com/1Password/onepassword-operator/security/dependabot/20.

Also bumping go.opentelemetry.io/otel/sdk to 1.40.0 to address https://github.com/1Password/onepassword-operator/security/dependabot/19

Ran go mod tidy

🔗 Resolves:

✅ Checklist

  • 🖊️ Commits are signed
  • 🧪 Tests added/updated: (See the Testing Guide for when to use each type and how to run them)
    • 🔹 Unit
    • 🔸 Integration
    • 🌐 E2E (Connect)
    • 🔑 E2E (Service Account)
  • 📚 Docs updated (if behavior changed)

🕵️ Review Notes & ⚠️ Risks

@rishiy15 rishiy15 changed the title Upgrade grpc version to 1.79.3 Upgrade google.golang.org/grpc version to 1.79.3 Mar 19, 2026
@rishiy15 rishiy15 requested review from JillRegan and bertrmz March 19, 2026 18:25
@rishiy15 rishiy15 merged commit a69eee6 into main Mar 19, 2026
7 checks passed
@rishiy15 rishiy15 deleted the bump-grpc-version branch March 19, 2026 22:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants