Skip to content

fix: resolve Dependabot security alerts - #13

Merged
kgrodzicki merged 1 commit into
masterfrom
fix/dependabot-security-alerts
Aug 11, 2026
Merged

fix: resolve Dependabot security alerts#13
kgrodzicki merged 1 commit into
masterfrom
fix/dependabot-security-alerts

Conversation

@kgrodzicki

Copy link
Copy Markdown
Member

Resolves all 15 open Dependabot security alerts by upgrading:

  • google.golang.org/grpc v1.79.3 → v1.82.1 (xDS RBAC and HTTP/2 vulnerabilities, high)
  • golang.org/x/crypto v0.48.0 → v0.52.0 (13 alerts incl. multiple critical SSH vulnerabilities)
  • golang.org/x/net v0.50.0 → v0.55.0 (HTML parser DoS, medium)

Transitive dependencies updated via go mod tidy. Build and all tests pass.

🤖 Generated with Claude Code

@kgrodzicki
kgrodzicki merged commit be0976b into master Aug 11, 2026
2 checks passed
@kgrodzicki
kgrodzicki deleted the fix/dependabot-security-alerts branch August 11, 2026 09:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant