Skip to content

Bump grpc, otel, and aws-sdk-go-v2 to address security advisories#154

Open
andrew wants to merge 1 commit into
mainfrom
bump-vulnerable-deps
Open

Bump grpc, otel, and aws-sdk-go-v2 to address security advisories#154
andrew wants to merge 1 commit into
mainfrom
bump-vulnerable-deps

Conversation

@andrew
Copy link
Copy Markdown
Contributor

@andrew andrew commented Jun 2, 2026

Resolves four open Dependabot alerts on indirect dependencies pulled in via gocloud.dev.

  • google.golang.org/grpc v1.79.1 -> v1.81.1 (GHSA-p77j-4mvh-x3m3, critical)
  • go.opentelemetry.io/otel/sdk v1.41.0 -> v1.44.0 (GHSA-hfvc-g4fc-pqhx, high)
  • github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.6 -> v1.7.11 (GHSA-xmrv-pmrh-hhx2, medium)
  • github.com/aws/aws-sdk-go-v2/service/s3 v1.96.3 -> v1.102.2 (medium, likely false positive but bumped for consistency)

Bumped via go get ...@latest and go mod tidy.

Resolves four open Dependabot alerts on indirect dependencies pulled
in via gocloud.dev:

- google.golang.org/grpc v1.79.1 -> v1.81.1 (GHSA-p77j-4mvh-x3m3)
- go.opentelemetry.io/otel/sdk v1.41.0 -> v1.44.0 (GHSA-hfvc-g4fc-pqhx)
- aws-sdk-go-v2/aws/protocol/eventstream v1.7.6 -> v1.7.11 (GHSA-xmrv-pmrh-hhx2)
- aws-sdk-go-v2/service/s3 v1.96.3 -> v1.102.2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant