Skip to content

chore: Bump vulnerable dependencies [CVE-2026-56864, CVE-2026-56865, GO-2026-5932] - #2914

Merged
fseldow merged 2 commits into
release-1.4from
security/cve-bump-release-1.4
Aug 15, 2026
Merged

chore: Bump vulnerable dependencies [CVE-2026-56864, CVE-2026-56865, GO-2026-5932]#2914
fseldow merged 2 commits into
release-1.4from
security/cve-bump-release-1.4

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Security: Auto-bump vulnerable dependencies

govulncheck and trivy detected vulnerabilities on the release-1.4 branch.
This PR updates the affected dependencies to their latest versions.

⚠️ Please review the changes and ensure CI passes before merging.

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
fseldow
fseldow previously approved these changes Aug 15, 2026
@codecov

codecov Bot commented Aug 15, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 74.75%. Comparing base (5d6d6c6) to head (0edd39d).

Additional details and impacted files
@@             Coverage Diff              @@
##           release-1.4    #2914   +/-   ##
============================================
  Coverage        74.75%   74.75%           
============================================
  Files              138      138           
  Lines             6913     6913           
============================================
  Hits              5168     5168           
  Misses            1371     1371           
  Partials           374      374           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Signed-off-by: xinhl <xinhl@microsoft.com>
@fseldow
fseldow merged commit 2106cef into release-1.4 Aug 15, 2026
34 of 35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant