Skip to content

Backport of chore: Update dependencies for cve into release/0.21.x - #6769

Merged
moduli merged 2 commits into
release/0.21.xfrom
backport/moduli-cve-updates/immensely-one-cougar
Jul 30, 2026
Merged

Backport of chore: Update dependencies for cve into release/0.21.x#6769
moduli merged 2 commits into
release/0.21.xfrom
backport/moduli-cve-updates/immensely-one-cougar

Conversation

@hc-github-team-secure-boundary

Copy link
Copy Markdown
Collaborator

Backport

This PR is auto-generated from #6768 to be assessed for backporting due to the inclusion of the label backport/0.21.x.

🚨

Warning automatic cherry-pick of commits failed. If the first commit failed,
you will see a blank no-op commit below. If at least one commit succeeded, you
will see the cherry-picked commits up to, not including, the commit where
the merge conflict occurred.

The person who merged in the original PR is:
@moduli
This person should resolve the merge-conflict(s) by either:

  • Manually completing the cherry picks into this branch
  • Creating a new branch and manually cherry-picking all commits being backported

merge conflict error: POST https://api.github.com/repos/hashicorp/boundary/merges: 409 Merge conflict []

The below text is copied from the body of the original PR.


Description

This PR updates dependencies to resolve the following CVEs

⚠︎ found NVD reported vulnerability CVE-2026-39822 in cpe:2.3:a:golang:go:1.26.4:*:*:*:*:*:*:*
        to-scan.6eb8/boundary:1:1
    ⚠︎ found NVD reported vulnerability CVE-2026-42505 in cpe:2.3:a:golang:go:1.26.4:*:*:*:*:*:*:*
        to-scan.6eb8/boundary:1:1
    ⚠︎ found NVD reported vulnerability CVE-2026-39822 in cpe:2.3:a:golang:go:1.26.4:*:*:*:*:*:*:*
        to-scan.6eb8/boundary:1:1
    ⚠︎ found NVD reported vulnerability CVE-2026-42505 in cpe:2.3:a:golang:go:1.26.4:*:*:*:*:*:*:*
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5023 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5029 in golang.org/x/net@v0.53.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5018 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-rm3j-f69w-wqmq in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-w879-237q-wc7r in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-jppx-rxg9-jmrx in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-6061 in google.golang.org/grpc@v1.79.3
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5006 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5027 in golang.org/x/net@v0.53.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-5cv4-jp36-h3mw in golang.org/x/net@v0.53.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-q4h4-gmj2-qvw2 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-9m57-25v3-79x9 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5025 in golang.org/x/net@v0.53.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5019 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5021 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5761 in github.com/opencontainers/runc@v1.2.8
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-qpw4-5x99-6vjp in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5016 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5158 in go.opentelemetry.io/otel@v1.41.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5015 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5014 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-89gr-r52h-f8rx in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5033 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5024 in golang.org/x/sys@v0.43.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5932 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-x527-x647-q7gg in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5026 in golang.org/x/net@v0.53.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5970 in golang.org/x/text@v0.36.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-vgwf-h737-ff37 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5942 in golang.org/x/net@v0.53.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-45gg-vh54-h5m9 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-f5wc-c3c7-36mc in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5030 in golang.org/x/net@v0.53.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-5cgq-3rg8-m6cv in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5013 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5028 in golang.org/x/net@v0.53.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-hrxh-6v49-42gf in google.golang.org/grpc@v1.79.3
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5020 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5005 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-78mq-xcr3-xm33 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GO-2026-5017 in golang.org/x/crypto@v0.50.0
        to-scan.6eb8/boundary:1:1
    ⚠︎ found OSV reported vulnerability GHSA-xjvp-4fhw-gc47 in github.com/opencontainers/runc@v1.2.8
        to-scan.6eb8/boundary:1:1

PCI review checklist

  • I have documented a clear reason for, and description of, the change I am making.
  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.
  • If applicable, I've documented the impact of any changes to security controls.
    Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.

Overview of commits

@hashicorp-cla-app

hashicorp-cla-app Bot commented Jul 30, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

* chore: Update dependencies for cve

* chore: Suppress GO-2026-5932

(cherry picked from commit 6891267)

# Conflicts:
#	api/go.mod
#	api/go.sum
#	go.mod
#	go.sum
#	plugins/boundary/mains/aws/go.mod
#	plugins/boundary/mains/aws/go.sum
#	plugins/boundary/mains/azure/go.mod
#	plugins/boundary/mains/azure/go.sum
#	plugins/boundary/mains/gcp/go.mod
#	plugins/boundary/mains/gcp/go.sum
#	plugins/boundary/mains/minio/go.mod
#	plugins/boundary/mains/minio/go.sum
#	plugins/kms/mains/alicloudkms/go.mod
#	plugins/kms/mains/alicloudkms/go.sum
#	plugins/kms/mains/awskms/go.mod
#	plugins/kms/mains/awskms/go.sum
#	plugins/kms/mains/azurekeyvault/go.mod
#	plugins/kms/mains/azurekeyvault/go.sum
#	plugins/kms/mains/gcpckms/go.mod
#	plugins/kms/mains/gcpckms/go.sum
#	plugins/kms/mains/ibmkp/go.mod
#	plugins/kms/mains/ibmkp/go.sum
#	plugins/kms/mains/ocikms/go.mod
#	plugins/kms/mains/ocikms/go.sum
#	plugins/kms/mains/transit/go.mod
#	plugins/kms/mains/transit/go.sum
#	sdk/go.mod
#	sdk/go.sum
@moduli
moduli force-pushed the backport/moduli-cve-updates/immensely-one-cougar branch from c044efb to 6eb20c3 Compare July 30, 2026 14:54
@github-actions github-actions Bot added the api label Jul 30, 2026
@moduli moduli added the pr/no-milestone Ignores the Milestone Check label Jul 30, 2026
@moduli
moduli marked this pull request as ready for review July 30, 2026 15:28
@moduli
moduli requested a review from a team as a code owner July 30, 2026 15:28
@moduli
moduli requested a review from a team July 30, 2026 15:28
@moduli
moduli merged commit 58fbb18 into release/0.21.x Jul 30, 2026
53 of 56 checks passed
@moduli
moduli deleted the backport/moduli-cve-updates/immensely-one-cougar branch July 30, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants