Skip to content

fix(deps): bump grpc-go and golang.org/x/mod to resolve HIGH CVEs - #79

Merged
mridulgain merged 1 commit into
private/master/mg/fix-kubernetes-inclusterconfig-ipv4-bracketfrom
mg/fix-trivy-high-cves
Sep 2, 2026
Merged

fix(deps): bump grpc-go and golang.org/x/mod to resolve HIGH CVEs#79
mridulgain merged 1 commit into
private/master/mg/fix-kubernetes-inclusterconfig-ipv4-bracketfrom
mg/fix-trivy-high-cves

Conversation

@mridulgain

Copy link
Copy Markdown

Summary

Stacked on #78 — this branch is based on private/master/mg/fix-kubernetes-inclusterconfig-ipv4-bracket and should be merged after (or into) that PR.

Test plan

  • go build ./... passes for root, api/v2, and examples modules
  • go test ./storage/... passes
  • CI Trivy Security Scan is green

🤖 Generated with Claude Code

google.golang.org/grpc v1.83.0 has CVE-2026-84304, and
golang.org/x/mod v0.38.0 has CVE-2026-56864/CVE-2026-56865 (a GOSUMDB
transparency-log verification bypass). Bump both across all three
modules (root, api/v2, examples) as flagged by the Trivy Security
Scan on PR #78.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@mridulgain mridulgain self-assigned this Sep 2, 2026
@mridulgain
mridulgain merged commit 0ac9552 into private/master/mg/fix-kubernetes-inclusterconfig-ipv4-bracket Sep 2, 2026
10 of 11 checks passed
@mridulgain
mridulgain deleted the mg/fix-trivy-high-cves branch September 2, 2026 14:41
@mridulgain
mridulgain restored the mg/fix-trivy-high-cves branch September 2, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant