Skip to content

Add cve fix - #253

Merged
szjakabgetbridge merged 1 commit into
masterfrom
PLT-1220
Jul 9, 2026
Merged

Add cve fix#253
szjakabgetbridge merged 1 commit into
masterfrom
PLT-1220

Conversation

@szjakabgetbridge

Copy link
Copy Markdown
Member

JIRA

Changes

Package │ Before │ After │ CVE
go-git/go-git/v5 │ v5.13.0 │ v5.19.0 │ GHSA-389r-gv7p-r3rp
go-git/go-billy/v5 │ v5.6.0 │ v5.9.0 │ GHSA-qw64-3x98-g7q2
go-jose/go-jose/v3 │ v3.0.3 │ v3.0.5 │ GHSA-78h2-9frx-2jm8
containerd/containerd │ v1.7.11 │ v1.7.29 │ GHSA-pwhc-rpq9-4c8w
google.golang.org/grpc │ v1.59.0 │ v1.79.3 │ GHSA-p77j-4mvh-x3m3

docker/docker remains at v25.0.6. GHSA-rg2x-37c3-w2rh and GHSA-x86f-5xw2-fm2r have no released patch. additional ticket will be created

Checklist

    • Feature Flag Required
    • Bug

Test plan

    • Walk-through
    • Peer review
    • Inspection
  • Detailed steps and prerequisites for validating the change:

Risk Analysis - the risk of change is evaluated

    • Low - Majority of the changes are low risk which doesn’t require extra testing, only code review by 1 reviewer
        • 1 reviewer
    • Medium - Some portions of changes are medium risk which needs peer testing and review by 2 reviewers
        • 2 reviewers
        • peer testing
    • High - A very few breaking changes are high risk and need very throughout testing and review and also a coordinated release process.
        • 2 reviewers
        • peer testing
        • coordinated release

@szjakabgetbridge
szjakabgetbridge requested a review from a team as a code owner July 4, 2026 17:22

@jppakalapati jppakalapati left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good

@szjakabgetbridge
szjakabgetbridge merged commit 4a6908f into master Jul 9, 2026
1 check passed
@szjakabgetbridge
szjakabgetbridge deleted the PLT-1220 branch July 9, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants