Skip to content

chore(deps): bump the gomod group across 1 directory with 14 updates - #717

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/gomod-281d57c534
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/gomod-281d57c534

chore(deps): bump the gomod group across 1 directory with 14 updates

aa5a7e9
Select commit
Loading
Failed to load commit list.
Kusari Inspector / Kusari Inspector succeeded May 5, 2026 in 50s

Security Analysis Passed

No security issues found

Details

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both independent analyses unanimously recommend merging this PR. The primary security benefit is the upgrade of golang.org/x/crypto from v0.40.0 to v0.46.0, which resolves three active CVEs: CVE-2025-47913 (High severity DoS via SSH agent panic), CVE-2025-47914 (Low severity out-of-bounds read in SSH agent), and CVE-2025-58181 (Low severity unbounded memory consumption in SSH GSSAPI). The new version v0.46.0 carries no active advisories. The code analysis returned zero findings across all severity levels, confirming no secrets, no code-level vulnerabilities, and no workflow concerns were introduced. All remaining dependency changes are routine version bumps with permissive licenses and no new vulnerabilities. Maintenance score warnings on go.uber.org/zap, github.com/spf13/cobra, and sigs.k8s.io/yaml are low-risk operational signals and not security blockers. The combined risk profile is net-positive: merging actively reduces the attack surface by eliminating three known vulnerabilities while introducing no new risks.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: aa5a7e9, performed at: 2026-05-05T10:20:04Z