Skip to content

Wiz: Upgrade multiple dependencies (resolves 46 findings)#2

Open
wiz-code-21c5ec5a85[bot] wants to merge 1 commit into
develfrom
wiz-auto-remediation-e126dd9aff2a775c
Open

Wiz: Upgrade multiple dependencies (resolves 46 findings)#2
wiz-code-21c5ec5a85[bot] wants to merge 1 commit into
develfrom
wiz-auto-remediation-e126dd9aff2a775c

Conversation

@wiz-code-21c5ec5a85
Copy link
Copy Markdown

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 46 findings detected in this project

Changes were made to the following file(s):

  • erigon-lib/go.mod
  • go.mod

Vulnerabilities:

Component Findings Locations
github.com/consensys/gnark-crypto
0.12.1 → 0.18.1
High GHSA-fj2x-735w-74vq /erigon-lib/go.mod
/go.mod
github.com/docker/docker
1.6.2 → 25.0.13
High CVE-2024-29018
High CVE-2019-13509
High CVE-2018-12608
High CVE-2024-24557
Medium CVE-2022-24769
Medium CVE-2025-54410
Medium CVE-2020-27534
Medium CVE-2021-41091
Medium CVE-2021-41089
Medium CVE-2021-41190
Medium CVE-2022-36109
Medium GHSA-jq35-85cj-fj4p
Low GHSA-vp35-85q5-9f25
/go.mod
github.com/go-chi/chi/v5
5.0.11 → 5.2.2
Medium GHSA-vrw8-fxc6-2r93 /go.mod
github.com/golang-jwt/jwt/v4
4.5.0 → 4.5.2
High CVE-2025-30204
Low CVE-2024-51744
/go.mod
github.com/quic-go/quic-go
0.38.2 → 0.57.0
High CVE-2024-22189
High CVE-2025-59530
Medium CVE-2025-64702
Medium CVE-2024-53259
/go.mod
github.com/quic-go/webtransport-go
0.5.3 → 0.10.0
High CVE-2026-21434
High CVE-2026-21435
Medium CVE-2026-21438
/go.mod
github.com/rs/cors
1.10.1 → 1.11.0
High CVE-2025-47908 /go.mod
github.com/sirupsen/logrus
1.9.0 → 1.9.1
High CVE-2025-65637 /erigon-lib/go.mod
/go.mod
github.com/vektah/gqlparser/v2
2.5.10 → 2.5.14
Low CVE-2023-49559 /go.mod
golang.org/x/crypto
0.22.0 → 0.45.0
Critical CVE-2024-45337
High CVE-2025-47913
High CVE-2025-22869
Medium CVE-2025-58181
Medium CVE-2025-47914
/erigon-lib/go.mod
/go.mod
golang.org/x/net
0.21.0 → 0.38.0
High CVE-2023-45288
Medium CVE-2025-22870
Medium CVE-2025-22872
/erigon-lib/go.mod
golang.org/x/net
0.24.0 → 0.38.0
Medium CVE-2025-22872
Medium CVE-2025-22870
/go.mod
google.golang.org/grpc
1.63.2 → 1.79.3
Critical CVE-2026-33186 /erigon-lib/go.mod
/go.mod

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-code-21c5ec5a85
Copy link
Copy Markdown
Author

wiz-code-21c5ec5a85 Bot commented Apr 26, 2026

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 1 High 1 Medium
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 High 1 Medium

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-code-21c5ec5a85
Copy link
Copy Markdown
Author

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 1 High 1 Medium
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 High 1 Medium

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-code-21c5ec5a85
Copy link
Copy Markdown
Author

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities 1 High 1 Medium
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 High 1 Medium

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants