Skip to content

[TT-16932] [Critical Fix 5.12.1 / 5.8.13] CVE fixes#8024

Merged
buger merged 2 commits intorelease-5.8.13from
TT-16932-5.8.13
Apr 17, 2026
Merged

[TT-16932] [Critical Fix 5.12.1 / 5.8.13] CVE fixes#8024
buger merged 2 commits intorelease-5.8.13from
TT-16932-5.8.13

Conversation

@MFCaballero
Copy link
Copy Markdown
Contributor

@MFCaballero MFCaballero commented Apr 15, 2026

Description

This PR addresses the following CVEs for release-5.8.13:

[CVE-2026-34986] go-jose/v3 -> Updated to v3.0.5 ✅
[CVE-2026-34986] go-jose/v4 -> Updated to v4.1.4 ✅
[CVE-2026-39883] otel/sdk -> Updated to v1.43.0 (via TykTechnologies/opentelemetry v0.0.25) ✅

Note: go directive bumped 1.24.6 -> 1.25.0 to match the base branch (release-5.8.13 is already on go 1.25).

Related Issue

TT-16932

Test Plan

  • go build ./... passes
  • CI passes

@github-actions
Copy link
Copy Markdown
Contributor

Failed to generate code suggestions for PR

@github-actions
Copy link
Copy Markdown
Contributor

API Changes

no api changes detected

@MFCaballero MFCaballero changed the title fix cves [TT-16932] [Critical Fix 5.12.1 / 5.8.13] CVE fixes Apr 15, 2026
@sonarqubecloud
Copy link
Copy Markdown

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@MFCaballero MFCaballero added the deps-reviewed Dependency changes reviewed and approved for CI execution label Apr 16, 2026
buger added a commit that referenced this pull request Apr 17, 2026
- CVE-2026-34986: bump go-jose/v4 v4.0.5 -> v4.1.4
- CVE-2026-39883: bump otel/sdk v1.40.0 -> v1.43.0 (via TykTechnologies/opentelemetry v0.0.25)
- Also bumps go directive 1.24.6 -> 1.25.0 (matching base branch release-5.8.13)

Consolidating all CVE fixes into single PR #8024.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
MFCaballero and others added 2 commits April 17, 2026 18:54
- CVE-2026-34986: bump go-jose/v4 v4.0.5 -> v4.1.4
- CVE-2026-39883: bump otel/sdk v1.40.0 -> v1.43.0 (via TykTechnologies/opentelemetry v0.0.25)
- Also bumps go directive 1.24.6 -> 1.25.0 (matching base branch release-5.8.13)

Consolidating all CVE fixes into single PR #8024.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@buger buger force-pushed the TT-16932-5.8.13 branch from e060855 to 712020f Compare April 17, 2026 15:55
@github-actions
Copy link
Copy Markdown
Contributor

🚨 Jira Linter Failed

Commit: 712020f
Failed at: 2026-04-17 15:56:08 UTC

The Jira linter failed to validate your PR. Please check the error details below:

🔍 Click to view error details
failed to get Jira issue: failed to fetch Jira issue TT-16932: Issue does not exist or you do not have permission to see it.: request failed. Please analyze the request body for more details. Status code: 404

Next Steps

  • Ensure your branch name contains a valid Jira ticket ID (e.g., ABC-123)
  • Verify your PR title matches the branch's Jira ticket ID
  • Check that the Jira ticket exists and is accessible

This comment will be automatically deleted once the linter passes.

@buger buger merged commit a3d2e83 into release-5.8.13 Apr 17, 2026
5 of 7 checks passed
@buger buger deleted the TT-16932-5.8.13 branch April 17, 2026 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deps-reviewed Dependency changes reviewed and approved for CI execution

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants