Skip to content

[TT-16932] CVE fixes for release-5.12#8091

Merged
buger merged 1 commit intorelease-5.12from
fix/cve-fixes-5.12
Apr 17, 2026
Merged

[TT-16932] CVE fixes for release-5.12#8091
buger merged 1 commit intorelease-5.12from
fix/cve-fixes-5.12

Conversation

@buger
Copy link
Copy Markdown
Member

@buger buger commented Apr 17, 2026

Summary

Fix HIGH CVEs on release-5.12:

  • CVE-2026-34986: go-jose/v3 v3.0.4 → v3.0.5
  • CVE-2026-34986: go-jose/v4 v4.0.5 → v4.1.4
  • Note: pgproto3/v2 is a transitive dependency and cannot be removed via go mod tidy

Test plan

  • CI passes
  • trivy shows no HIGH go-jose CVEs

🤖 Generated with Claude Code

- CVE-2026-34986: bump go-jose/v3 v3.0.4 → v3.0.5
- CVE-2026-34986: bump go-jose/v4 v4.0.5 → v4.1.4
- CVE-2026-32286: pgproto3/v2 retained (transitive dep, cannot be removed via tidy)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@buger buger merged commit 33c7751 into release-5.12 Apr 17, 2026
18 of 27 checks passed
@buger buger deleted the fix/cve-fixes-5.12 branch April 17, 2026 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant