[9.4](backport #49975) Update transient dependency github.com/go-jose/go-jose/v4 to v4.1.4#50016
[9.4](backport #49975) Update transient dependency github.com/go-jose/go-jose/v4 to v4.1.4#50016ycombinator merged 1 commit into9.4from
Conversation
🤖 GitHub commentsJust comment with:
|
|
Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane) |
TL;DRThree jobs failed, but all signs point to CI environment/transient issues rather than a regression in this PR: both FIPS ECH jobs failed on Elastic Cloud API Remediation
Investigation detailsRoot Cause
Evidence
Verification
Follow-up
Note 🔒 Integrity filtering filtered 3 itemsIntegrity filtering activated and filtered the following items during workflow execution.
What is this? | From workflow: PR Buildkite Detective Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not. |
…49975) Bumps transient dependency github.com/go-jose/go-jose/v4 from v4.1.3 to v4.1.4 to address CVE-2026-34986. (cherry picked from commit 0ef3a09)
8ac5b37 to
890543b
Compare
Proposed commit message
Bumps transient dependency
github.com/go-jose/go-jose/v4from v4.1.3 to v4.1.4.AgentBeat is not believed to invoke the vulnerable code path (
cipher.KeyUnwrapviaParseEncrypted+Decrypt), as go-jose is only pulled in transitively through the Azure SDK for JWS signature verification. This update is being applied as standard maintenance.Checklist
CHANGELOG.next.asciidocorCHANGELOG-developer.next.asciidoc.This is an automatic backport of pull request Update transient dependency github.com/go-jose/go-jose/v4 to v4.1.4 #49975 done by Mergify.