Skip to content

chore(deps): bump google.golang.org/grpc to v1.83.0 - #431

Open
ivanauth wants to merge 1 commit into
authzed:mainfrom
ivanauth:chore/bump-grpc-vuln
Open

chore(deps): bump google.golang.org/grpc to v1.83.0#431
ivanauth wants to merge 1 commit into
authzed:mainfrom
ivanauth:chore/bump-grpc-vuln

Conversation

@ivanauth

@ivanauth ivanauth commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Bumps google.golang.org/grpc v1.80.0 → v1.83.0 to fix GHSA-hrxh-6v49-42gf (xDS RBAC / HTTP/2 transport vulnerabilities, fixed upstream in v1.82.1), and golang.org/x/net v0.52.0 → v0.58.0 past its published html/idna advisories.

Snyk is currently red on every open PR in this repo because main carries the vulnerable versions — e.g. #427 and #428, which don't touch these deps. Once this merges, updating those branches should clear their checks.

go build ./... and govulncheck ./... are clean; TestLookupResources fails locally only because it dials a live server on localhost:50051.

Fixes GHSA-hrxh-6v49-42gf (GO-2026-6061): xDS RBAC and HTTP/2
transport server vulnerabilities, fixed upstream in grpc-go v1.82.1.
Also bumps golang.org/x/net past its published html/idna advisories.
Snyk is currently failing on every PR because of these.
@ivanauth
ivanauth requested a review from a team as a code owner August 13, 2026 22:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant