Skip to content

fix(security): remediate CVE vulnerabilities in release-0.11#560

Merged
ulucinar merged 1 commit intorelease-0.11from
fix/cve-remediation-release-0.11-20260323-214158
Mar 23, 2026
Merged

fix(security): remediate CVE vulnerabilities in release-0.11#560
ulucinar merged 1 commit intorelease-0.11from
fix/cve-remediation-release-0.11-20260323-214158

Conversation

@upbound-bot
Copy link
Copy Markdown

Summary

This PR fixes CVE vulnerabilities identified by security scanning.

Vulnerabilities Fixed

CVE/GHSA Severity Package Fixed Version
GHSA-p77j-4mvh-x3m3 Critical google.golang.org/grpc v1.79.3

Changes Made

  • Updated google.golang.org/grpc from v1.67.0 to v1.79.3 in go.mod
  • Ran go mod tidy to update go.sum and transitive dependencies

References

Verification

  • Rescanned with cve-scan skill after fixes
  • All listed vulnerabilities resolved

- Update google.golang.org/grpc to v1.79.3 (fixes GHSA-p77j-4mvh-x3m3)

Signed-off-by: Alper Rifat Ulucinar <ulucinar@users.noreply.github.com>
@ulucinar ulucinar merged commit d84be2d into release-0.11 Mar 23, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants