Skip to content

fix(security): bump grpc and CLI tool versions to resolve CVEs#52

Merged
EItanya merged 1 commit intomainfrom
eitanya/cves
Mar 19, 2026
Merged

fix(security): bump grpc and CLI tool versions to resolve CVEs#52
EItanya merged 1 commit intomainfrom
eitanya/cves

Conversation

@EItanya
Copy link
Contributor

@EItanya EItanya commented Mar 19, 2026

Bump google.golang.org/grpc v1.78.0 -> v1.79.3 to fix CRITICAL CVE-2026-33186 (authorization bypass). Bump all bundled CLI tools to latest releases (kubectl 1.35.3, helm 4.1.3, istioctl 1.28.5, argo-rollouts 1.8.4, cilium 0.19.2) to reduce CVE surface area.

Bump google.golang.org/grpc v1.78.0 -> v1.79.3 to fix CRITICAL
CVE-2026-33186 (authorization bypass). Bump all bundled CLI tools
to latest releases (kubectl 1.35.3, helm 4.1.3, istioctl 1.28.5,
argo-rollouts 1.8.4, cilium 0.19.2) to reduce CVE surface area.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
@EItanya EItanya requested a review from dimetron as a code owner March 19, 2026 12:03
@EItanya EItanya merged commit 9125aee into main Mar 19, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant