Skip to content

fix(deps): bump go-jose to v4.1.4 for CVE-2026-34986#35

Merged
svghadi merged 2 commits into
rh-gitops-midstream:v2.43.1from
aali309:fix/cve-2026-34986-go-jose-v2.43.1
May 7, 2026
Merged

fix(deps): bump go-jose to v4.1.4 for CVE-2026-34986#35
svghadi merged 2 commits into
rh-gitops-midstream:v2.43.1from
aali309:fix/cve-2026-34986-go-jose-v2.43.1

Conversation

@aali309
Copy link
Copy Markdown

@aali309 aali309 commented Apr 30, 2026

No description provided.

aali309 added 2 commits April 30, 2026 15:13
Signed-off-by: Atif Ali <atali@redhat.com>
Signed-off-by: Atif Ali <atali@redhat.com>
@aali309 aali309 marked this pull request as ready for review May 1, 2026 22:24
@svghadi
Copy link
Copy Markdown
Collaborator

svghadi commented May 5, 2026

Can you confirm whether this dependency has been updated in upstream Dex? If not, we should consider updating it there as well for the versions supported by upstream.

@anandrkskd
Copy link
Copy Markdown

anandrkskd commented May 5, 2026

Can you confirm whether this dependency has been updated in upstream Dex? If not, we should consider updating it there as well for the versions supported by upstream.

Dependency is not updated in upstream dex.
I have created a PR on upstream dexidp#4776 for de version 2.43.x, will cherry pick it to other branches once approved.

@svghadi
Copy link
Copy Markdown
Collaborator

svghadi commented May 7, 2026

Thanks @aali309 & @anandrkskd

@svghadi svghadi merged commit 564d623 into rh-gitops-midstream:v2.43.1 May 7, 2026
6 of 7 checks passed
@aali309 aali309 deleted the fix/cve-2026-34986-go-jose-v2.43.1 branch May 9, 2026 20:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants