Skip to content

chore: refresh vulnerable Go runtime dependencies#148

Merged
haasonsaas merged 2 commits into
mainfrom
fix/identity-service-token-bearer-auth
Jul 13, 2026
Merged

chore: refresh vulnerable Go runtime dependencies#148
haasonsaas merged 2 commits into
mainfrom
fix/identity-service-token-bearer-auth

Conversation

@haasonsaas

Copy link
Copy Markdown
Contributor

Repairs the security lane that failed after #147 auto-merged: use Go 1.26.5 for CI/Bazel and pgx v5.9.2, with regenerated vendor and Bazel lock state.\n\nValidation:\n- GOTOOLCHAIN=go1.26.5 go run golang.org/x/vuln/cmd/govulncheck@v1.3.0 ./... (zero reachable vulnerabilities)\n- GOTOOLCHAIN=go1.26.5 GOFLAGS=-mod=vendor go test ./... -count=1

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang/​github.com/​jackc/​pgx/​v5@​v5.9.1 ⏵ v5.9.273 +1100 +1100100100

View full report

@haasonsaas
haasonsaas merged commit c70135b into main Jul 13, 2026
6 checks passed
@haasonsaas
haasonsaas deleted the fix/identity-service-token-bearer-auth branch July 13, 2026 22:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant