Skip to content

fix: resolve 21 govulncheck vulnerabilities via dependency and toolchain upgrades#112

Open
bagelface wants to merge 1 commit into
Layr-Labs:masterfrom
BreadchainCoop:patch-vulnerabilities
Open

fix: resolve 21 govulncheck vulnerabilities via dependency and toolchain upgrades#112
bagelface wants to merge 1 commit into
Layr-Labs:masterfrom
BreadchainCoop:patch-vulnerabilities

Conversation

@bagelface

Copy link
Copy Markdown

Summary

Ran govulncheck and resolved all 21 reported vulnerabilities by upgrading dependencies and pinning the Go toolchain.

Dependency upgrades:

  • google.golang.org/grpc v1.67.1v1.80.0 — fixes "GO-2026-4762"
  • testcontainers/testcontainers-go v0.34.0v0.42.0 — migrates off "docker/docker" to "moby/moby/client"
  • docker/docker v27.2.0v28.5.2 — fixes "GO-2026-4887", "GO-2026-4883" (AuthZ plugin bypass)

Toolchain:

  • Pinned toolchain go1.25.9 in "go.mod" — fixes 13 standard library vulnerabilities across "crypto/tls", "crypto/x509", "archive/tar", "html/template", "net/url", "os", and "encoding/asn1"

govulncheck ./... now reports 0 vulnerabilities. All existing tests pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant