chore(deps): bump the gomod group across 1 directory with 14 updates - #717
dependabot[bot] wants to merge 1 commit into
Security Analysis Passed
No security issues found
Details
Kusari Analysis Results:
✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.
Both independent analyses unanimously recommend merging this PR. The primary security benefit is the upgrade of golang.org/x/crypto from v0.40.0 to v0.46.0, which resolves three active CVEs: CVE-2025-47913 (High severity DoS via SSH agent panic), CVE-2025-47914 (Low severity out-of-bounds read in SSH agent), and CVE-2025-58181 (Low severity unbounded memory consumption in SSH GSSAPI). The new version v0.46.0 carries no active advisories. The code analysis returned zero findings across all severity levels, confirming no secrets, no code-level vulnerabilities, and no workflow concerns were introduced. All remaining dependency changes are routine version bumps with permissive licenses and no new vulnerabilities. Maintenance score warnings on go.uber.org/zap, github.com/spf13/cobra, and sigs.k8s.io/yaml are low-risk operational signals and not security blockers. The combined risk profile is net-positive: merging actively reduces the attack surface by eliminating three known vulnerabilities while introducing no new risks.
Note
View full detailed analysis result for more information on the output and the checks that were run.
@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: aa5a7e9, performed at: 2026-05-05T10:20:04Z