Skip to content

fix/deps: bump vulnerable Go modules to patched releases#1305

Merged
keegancsmith merged 2 commits intomainfrom
k/cve
Apr 28, 2026
Merged

fix/deps: bump vulnerable Go modules to patched releases#1305
keegancsmith merged 2 commits intomainfrom
k/cve

Conversation

@keegancsmith
Copy link
Copy Markdown
Member

Raise the indirect go-jose, pgx, and OpenTelemetry module versions to the first fixed releases flagged by Trivy so the CLI no longer resolves known vulnerable dependency versions. Keep the split OpenTelemetry modules aligned at v1.43.0 to avoid mixing versions across that dependency set, and record the corresponding checksum updates from the resolver.

Raise the indirect go-jose, pgx, and OpenTelemetry module versions to
the first fixed releases flagged by Trivy so the CLI no longer resolves
known vulnerable dependency versions. Keep the split OpenTelemetry
modules aligned at v1.43.0 to avoid mixing versions across that
dependency set, and record the corresponding checksum updates from the
resolver.
@keegancsmith keegancsmith requested review from burmudar and evict April 28, 2026 16:29
@keegancsmith keegancsmith enabled auto-merge (squash) April 28, 2026 17:03
@keegancsmith keegancsmith merged commit 36657d0 into main Apr 28, 2026
9 checks passed
@keegancsmith keegancsmith deleted the k/cve branch April 28, 2026 17:12
burmudar pushed a commit that referenced this pull request Apr 30, 2026
Raise the indirect go-jose, pgx, and OpenTelemetry module versions to
the first fixed releases flagged by Trivy so the CLI no longer resolves
known vulnerable dependency versions. Keep the split OpenTelemetry
modules aligned at v1.43.0 to avoid mixing versions across that
dependency set, and record the corresponding checksum updates from the
resolver.
burmudar pushed a commit that referenced this pull request Apr 30, 2026
Raise the indirect go-jose, pgx, and OpenTelemetry module versions to
the first fixed releases flagged by Trivy so the CLI no longer resolves
known vulnerable dependency versions. Keep the split OpenTelemetry
modules aligned at v1.43.0 to avoid mixing versions across that
dependency set, and record the corresponding checksum updates from the
resolver.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants