Skip to content

fix: address govulncheck issues#466

Merged
joe0BAB merged 1 commit intomainfrom
chore/bump
Feb 23, 2026
Merged

fix: address govulncheck issues#466
joe0BAB merged 1 commit intomainfrom
chore/bump

Conversation

@joe0BAB
Copy link
Collaborator

@joe0BAB joe0BAB commented Feb 20, 2026

No description provided.

@joe0BAB joe0BAB marked this pull request as ready for review February 23, 2026 08:28
@joe0BAB joe0BAB self-assigned this Feb 23, 2026
@joe0BAB joe0BAB requested a review from Benehiko February 23, 2026 08:29
Copy link

@docker-agent docker-agent bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review Summary

✅ This PR successfully updates dependencies to address govulncheck security issues.

The dependency version bumps are standard security patches following typical Go ecosystem patterns:

  • Protobuf & gRPC: Minor version updates (protobuf v1.36.9→v1.36.11, grpc v1.75.0→v1.78.0)
  • OpenTelemetry: Package updates from v1.38.0 to v1.40.0 across the board
  • golang.org/x packages: Security updates addressing known vulnerabilities
  • filippo.io/age: Updated to v1.3.1 with new transitive dependency filippo.io/hpke v0.4.0 (both maintained by the same trusted author)

All version constraints are consistent across the monorepo modules, and vendor/ has been properly updated. No breaking changes, compatibility issues, or security concerns detected.

@joe0BAB joe0BAB merged commit 36e7c56 into main Feb 23, 2026
26 of 27 checks passed
@joe0BAB joe0BAB deleted the chore/bump branch February 23, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants