Security updates
- Updated
github.com/getkin/kin-openapito v0.144.0, addressing GHSA-r277-6w6q-xmqw (#5416). - Updated
google.golang.org/grpcto v1.82.1, addressing GHSA-hrxh-6v49-42gf (#5392, #5393). - Updated
golang.org/x/textto v0.39.0, addressing CVE-2026-56852 (#5383, #5385). - Updated
golang.org/x/netto v0.56.0, addressing CVE-2026-46600 (#5382, #5384). - Updated
github.com/klauspost/compressto v1.18.7 (#5429). - UI: bumped
tar,js-yaml, andbrace-expansion, addressing CVE-2026-59871, CVE-2026-59873, CVE-2026-59874, and CVE-2026-59869 (#5413, #5424). - UI: bumped
brace-expansionto 1.1.18 and 5.0.9, addressing CVE-2026-14257 and CVE-2026-69152 (#5466, #5471). - UI: refreshed the Yarn lockfile, removing the vulnerable
ip-addresspackage (CVE-2026-69192) and updatingpostcss(GHSA-r28c-9q8g-f849) (#5419).
Changelog
- d8461d6 build: remove go workspace and reduce Renovate to security-only updates (#5397) (#5403)
- 496c887 chore(deps): lock file maintenance (#5419)
- a3b2460 docs: add v2.2 release notes (#5399) (#5401)
- df3c039 docs: add v2.2.1 release notes (#5468) (#5473)
- 400510a docs: document Python memory profiling (#5406) (#5411)
- 852c39b fix(deps): bump brace-expansion in /ui [security] (#5466) (#5471)
- 0252239 fix(deps): bump tar, js-yaml, brace-expansion in /ui [security] (#5413) (#5424)
- 4504545 fix(security/critical/): update module github.com/getkin/kin-openapi to v0.144.0 [security] (#5416)
- c7fdec8 fix(security/high/): update module google.golang.org/grpc to v1.82.1 [security] (#5392)
- 097528e fix(security/high/api): update module google.golang.org/grpc to v1.82.1 [security] (#5393)
- dc8c13f fix(security/unknown/): update module github.com/klauspost/compress to v1.18.7 [security] (#5429)
- 1f4a845 fix(security/unknown/): update module golang.org/x/net to v0.56.0 [security] (#5382)
- 0e02e48 fix(security/unknown/): update module golang.org/x/text to v0.39.0 [security] (#5383)
- 290d232 fix(security/unknown/api): update module golang.org/x/net to v0.56.0 [security] (#5384)
- 32e1863 fix(security/unknown/api): update module golang.org/x/text to v0.39.0 [security] (#5385)
- aafe99d fix(ui): adapt to prettier 3.9 and eslint-plugin-react-hooks 7.1 (#5438) (#5440)
As always, feedback is more than welcome, feel free to open issues/discussions.
You can reach out to the team using:
Docker Images
docker pull grafana/pyroscope:2.2.1