Skip to content

fix(deps): bump google.golang.org/grpc to v1.79.3 and Go to 1.24#318

Draft
alethenorio wants to merge 1 commit intomasterfrom
push-smzppsktykxs
Draft

fix(deps): bump google.golang.org/grpc to v1.79.3 and Go to 1.24#318
alethenorio wants to merge 1 commit intomasterfrom
push-smzppsktykxs

Conversation

@alethenorio
Copy link
Copy Markdown
Contributor

Fixes CRITICAL security vulnerability (CVSS 9.1): gRPC-Go authorization bypass via missing leading slash in :path header (dependabot alert #26).

Changes

  • Bump google.golang.org/grpc from v1.65.0 to v1.79.3 (root module)
  • Bump google.golang.org/grpc from v1.70.0 to v1.79.3 (cmd/saga module)
  • Bump Go from 1.23 to 1.24 in both go.mod files and CI workflow (required by gRPC v1.79.3)

Related

Fixes CRITICAL security vulnerability (CVSS 9.1): gRPC-Go authorization
bypass via missing leading slash in :path header (dependabot alert #26).

Also bumps Go from 1.23 to 1.24 in go.mod and CI workflow, as gRPC v1.79.3
requires Go 1.24+.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant