chore(deps): bump the go_modules group across 1 directory with 10 updates - #675
chore(deps): bump the go_modules group across 1 directory with 10 updates#675dependabot[bot] wants to merge 1 commit into
Conversation
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
| github.com/antlr4-go/antlr/v4 v4.13.1 // indirect | ||
| github.com/aws/aws-sdk-go v1.55.5 // indirect | ||
| github.com/aws/aws-sdk-go-v2 v1.41.4 // indirect | ||
| github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.7 // indirect |
There was a problem hiding this comment.
The following vulnerability impacts github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream versions <1.7.8: GHSA-xmrv-pmrh-hhx2.
It can be remediated by updating to version 1.7.8 or higher.
| github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.7 // indirect | |
| github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.8 // indirect |
| github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.12 // indirect | ||
| github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.20 // indirect | ||
| github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.20 // indirect | ||
| github.com/aws/aws-sdk-go-v2/service/s3 v1.97.1 // indirect |
There was a problem hiding this comment.
The following vulnerability impacts github.com/aws/aws-sdk-go-v2/service/s3 versions <1.97.3: GHSA-xmrv-pmrh-hhx2.
It can be remediated by updating to version 1.97.3 or higher.
| github.com/aws/aws-sdk-go-v2/service/s3 v1.97.1 // indirect | |
| github.com/aws/aws-sdk-go-v2/service/s3 v1.97.3 // indirect |
| go.yaml.in/yaml/v3 v3.0.4 // indirect | ||
| golang.org/x/arch v0.17.0 // indirect | ||
| golang.org/x/crypto v0.46.0 // indirect | ||
| golang.org/x/crypto v0.49.0 // indirect |
There was a problem hiding this comment.
The following vulnerabilities impact golang.org/x/crypto versions <0.52.0: CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598.
These can be remediated by updating to version 0.52.0 or higher.
| golang.org/x/crypto v0.49.0 // indirect | |
| golang.org/x/crypto v0.52.0 // indirect |
| golang.org/x/oauth2 v0.34.0 // indirect | ||
| golang.org/x/sync v0.19.0 // indirect | ||
| golang.org/x/mod v0.33.0 // indirect | ||
| golang.org/x/net v0.52.0 // indirect |
There was a problem hiding this comment.
The following vulnerabilities impact golang.org/x/net versions <0.55.0: CVE-2026-25680, CVE-2026-39821.
These can be remediated by updating to version 0.55.0 or higher.
| golang.org/x/net v0.52.0 // indirect | |
| golang.org/x/net v0.55.0 // indirect |
…ates Bumps the go_modules group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [filippo.io/edwards25519](https://github.com/FiloSottile/edwards25519) | `1.1.0` | `1.1.1` | | [github.com/containerd/containerd](https://github.com/containerd/containerd) | `1.7.23` | `1.7.33` | | [github.com/docker/cli](https://github.com/docker/cli) | `27.3.1+incompatible` | `29.2.0+incompatible` | | [github.com/go-chi/chi/v5](https://github.com/go-chi/chi) | `5.2.2` | `5.2.4` | | [github.com/hashicorp/go-getter](https://github.com/hashicorp/go-getter) | `1.7.9` | `1.8.6` | | [github.com/opencontainers/runc](https://github.com/opencontainers/runc) | `1.1.14` | `1.3.6` | | [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) | `0.48.1` | `0.59.1` | | [github.com/shamaton/msgpack/v2](https://github.com/shamaton/msgpack) | `2.2.3` | `2.4.1` | Updates `filippo.io/edwards25519` from 1.1.0 to 1.1.1 - [Commits](FiloSottile/edwards25519@v1.1.0...v1.1.1) Updates `github.com/containerd/containerd` from 1.7.23 to 1.7.33 - [Release notes](https://github.com/containerd/containerd/releases) - [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md) - [Commits](containerd/containerd@v1.7.23...v1.7.33) Updates `github.com/docker/cli` from 27.3.1+incompatible to 29.2.0+incompatible - [Commits](docker/cli@v27.3.1...v29.2.0) Updates `github.com/go-chi/chi/v5` from 5.2.2 to 5.2.4 - [Release notes](https://github.com/go-chi/chi/releases) - [Changelog](https://github.com/go-chi/chi/blob/master/CHANGELOG.md) - [Commits](go-chi/chi@v5.2.2...v5.2.4) Updates `github.com/hashicorp/go-getter` from 1.7.9 to 1.8.6 - [Release notes](https://github.com/hashicorp/go-getter/releases) - [Changelog](https://github.com/hashicorp/go-getter/blob/main/CHANGELOG.md) - [Commits](hashicorp/go-getter@v1.7.9...v1.8.6) Updates `github.com/opencontainers/runc` from 1.1.14 to 1.3.6 - [Release notes](https://github.com/opencontainers/runc/releases) - [Changelog](https://github.com/opencontainers/runc/blob/main/CHANGELOG.md) - [Commits](opencontainers/runc@v1.1.14...v1.3.6) Updates `github.com/quic-go/quic-go` from 0.48.1 to 0.59.1 - [Release notes](https://github.com/quic-go/quic-go/releases) - [Commits](quic-go/quic-go@v0.48.1...v0.59.1) Updates `github.com/shamaton/msgpack/v2` from 2.2.3 to 2.4.1 - [Release notes](https://github.com/shamaton/msgpack/releases) - [Changelog](https://github.com/shamaton/msgpack/blob/main/CHANGELOG.md) - [Commits](shamaton/msgpack@v2.2.3...v2.4.1) Updates `golang.org/x/crypto` from 0.46.0 to 0.49.0 - [Commits](golang/crypto@v0.46.0...v0.49.0) Updates `golang.org/x/net` from 0.48.0 to 0.52.0 - [Commits](golang/net@v0.48.0...v0.52.0) --- updated-dependencies: - dependency-name: filippo.io/edwards25519 dependency-version: 1.1.1 dependency-type: indirect - dependency-name: github.com/containerd/containerd dependency-version: 1.7.33 dependency-type: indirect - dependency-name: github.com/docker/cli dependency-version: 29.2.0+incompatible dependency-type: indirect - dependency-name: github.com/go-chi/chi/v5 dependency-version: 5.2.4 dependency-type: indirect - dependency-name: github.com/hashicorp/go-getter dependency-version: 1.8.6 dependency-type: indirect - dependency-name: github.com/opencontainers/runc dependency-version: 1.3.6 dependency-type: indirect - dependency-name: github.com/quic-go/quic-go dependency-version: 0.59.1 dependency-type: indirect - dependency-name: github.com/shamaton/msgpack/v2 dependency-version: 2.4.1 dependency-type: indirect - dependency-name: golang.org/x/crypto dependency-version: 0.49.0 dependency-type: indirect - dependency-name: golang.org/x/net dependency-version: 0.52.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
fffe82d to
6dc3eaf
Compare
|



Bumps the go_modules group with 8 updates in the / directory:
1.1.01.1.11.7.231.7.3327.3.1+incompatible29.2.0+incompatible5.2.25.2.41.7.91.8.61.1.141.3.60.48.10.59.12.2.32.4.1Updates
filippo.io/edwards25519from 1.1.0 to 1.1.1Commits
d1c650aextra: initialize receiver in MultiScalarMultUpdates
github.com/containerd/containerdfrom 1.7.23 to 1.7.33Release notes
Sourced from github.com/containerd/containerd's releases.
... (truncated)
Changelog
Sourced from github.com/containerd/containerd's changelog.
... (truncated)
Commits
e8b1a9bMerge pull request #13631 from samuelkarp/prepare-1.7.337517e67Prepare release notes for v1.7.33ab30651Merge commit from fork0962898Merge pull request #13615 from k8s-infra-cherrypick-robot/cherry-pick-13606-t...74c728cupdate runc binary to v1.3.6d34cdafMerge commit from fork1e9806fMerge commit from fork9ab2b7aBound user-database file reads in openBoundedUserFiled805d96Merge pull request #13579 from akhilerm/1.7-go1.26.4947caa4update go to 1.26.4/1.25.11Updates
github.com/docker/clifrom 27.3.1+incompatible to 29.2.0+incompatibleCommits
0b9d198Merge pull request #6764 from vvoland/update-docker9c9ec73vendor: github.com/moby/moby/client v0.2.2bab3e81vendor: github.com/moby/moby/api v1.53.02e64fc1Merge pull request #6367 from thaJeztah/template_slicejoin1f2ba2aMerge pull request #6760 from thaJeztah/container_create_fix_errore34a342templates: make "join" work with non-string slices and map valuesa86356dMerge pull request #6763 from thaJeztah/bump_mapstructure771660avendor: github.com/go-viper/mapstructure/v2 v2.5.09cff36bMerge pull request #6762 from thaJeztah/bump_x_deps08ed2bccli/command/container: make injecting config.json failures a warningUpdates
github.com/go-chi/chi/v5from 5.2.2 to 5.2.4Release notes
Sourced from github.com/go-chi/chi/v5's releases.
Commits
6eb3588middleware: harden RedirectSlashes handler (#1044)de0d16eUpdate comment about min Go version (#1023)9fb4a15update reverseMethodMap in RegisterMethod (#1022)51c977cRefactor to use atomic type (#1019)563ab11Refactor graceful shutdown example (#994)a52c582Bump minimum Go and use new features (#1017)9b9fb55Replace methodTypString func with reverseMethodMap (#1018)0265fcdrefactor: iterative wildcard collapsing and add test for consecutive wildcard...cf537d4Optimize throttle middleware by avoiding unnecessary timer creation (#1011)9040e95fix/608 - Fix flaky Throttle middleware test by synchronizing token usage (#1...Updates
github.com/hashicorp/go-getterfrom 1.7.9 to 1.8.6Release notes
Sourced from github.com/hashicorp/go-getter's releases.
... (truncated)
Commits
d23bff4Merge pull request #608 from hashicorp/dependabot/go_modules/go-security-9c51...2c4aba8Merge pull request #613 from hashicorp/pull/v1.8.6fe61ed9Merge pull request #611 from hashicorp/SECVULN-41053d533656Merge pull request #606 from hashicorp/pull/CRT388f23dAdditional test for local branch and headb7ceaa5harden checkout ref handling and added regression tests769cc14Release version bump up6086a6aReview Comments Addressede02063cRevert "SECVULN Fix for git checkout argument injection enables arbitrary fil...c93084d[chore] : Bump google.golang.org/grpcUpdates
github.com/opencontainers/runcfrom 1.1.14 to 1.3.6Release notes
Sourced from github.com/opencontainers/runc's releases.
... (truncated)
Changelog
Sourced from github.com/opencontainers/runc's changelog.
... (truncated)
Commits
491b69bVERSION: release v1.3.6d934454merge CVE-2026-41579 fixes into release-1.39432ad3rootfs: make cgroupv1 subsystem symlinks fd-baseda8e53f2rootfs: make /dev initialisation code fd-based78c50d4rootfs: switch createDevices argument order083e21elibct: use preopened rootfs more42cfcbePre-open container root directory2e9b6a8libct: minor refactor in mountToRootfsedf5328libct: mountCgroupV1: address TODO3661a9dintegration: add some tests for bind mount through dangling symlinksUpdates
github.com/quic-go/quic-gofrom 0.48.1 to 0.59.1Release notes
Sourced from github.com/quic-go/quic-go's releases.
... (truncated)
Commits
438abf0http3: implement trailer validation logic (#5642)7659dd8ackhandler: fix counting of packets queued for PTO probing (#5539)bd4aea9ackhandler: fix qlogging of outstanding packet count (#5538)76b3e07ackhandler: remove unused declaredLost field in the packet (#5537)2020668expose local and remote settings in ConnectionState (#5533)d082d9ffix flaky TestHTTP3Qlog (#5532)c5f15f2http3: close qlogger after all streams have been handled (#5524)f6dbf89polish the security policy (#5526)29cb6ffqlogwriter: fix race between RecordEvent and Close (#5523)e8a6e37http3: fix race between new streams and GOAWAY (#5522)Updates
github.com/shamaton/msgpack/v2from 2.2.3 to 2.4.1Release notes
Sourced from github.com/shamaton/msgpack/v2's releases.
... (truncated)
Commits
ee0de4bMerge pull request #69 from shamaton/fix/v2-format65a5b02format README.mddea8799format test.yml66c6fa9format go files111d580Merge pull request #67 from shamaton/v2-add-tagpr-config4ad554eAdd tagpr config for v204a026eMerge pull request #66 from shamaton/v2-ext-frame-bounds-backportd20ec6cfix: validate ext frame bounds before byte-slice decode3b5ba18Merge pull request #52 from shamaton/feature/time-local-utc-decode1306fa7add Announcement to READMEUpdates
golang.org/x/cryptofrom 0.46.0 to 0.49.0Commits
982eaa6go.mod: update golang.org/x dependencies159944fssh,acme: clean up tautological/impossible nil conditionsa408498acme: only require prompt if server has terms of servicecab0f71all: upgrade go directive to at least 1.25.0 [generated]2f26647x509roots/fallback: update bundlee08b067go.mod: update golang.org/x dependencies7d0074cscrypt: fix panic on parameters <= 0506e022go.mod: update golang.org/x dependencies7dacc38chacha20poly1305: error out in fips140=only modeUpdates
golang.org/x/netfrom 0.48.0 to 0.52.0Commits
316e20cgo.mod: update golang.org/x dependencies9767a42internal/http3: add support for plugging into net/http4a81284http2: update docs to disrecommend this packagedec6603dns/dnsmessage: reject too large of names early during unpack8afa12fhttp2: deprecate write schedulers38019a2http2: add missing copyright header to export_test.go039b87finternal/http3: return error when Write is used after status 304 is set6267c6cinternal/http3: add HTTP 103 Early Hints support to ClientConn591bdf3internal/http3: add HTTP 103 Early Hints support to Server1faa6d8internal/http3: avoid potential race when aborting RoundTrip