Skip to content

fix critical vuln alert for 1.18#107

Merged
cicoyle merged 1 commit into
dapr:mainfrom
cicoyle:fix-critical-security-alerts-1.18
May 26, 2026
Merged

fix critical vuln alert for 1.18#107
cicoyle merged 1 commit into
dapr:mainfrom
cicoyle:fix-critical-security-alerts-1.18

Conversation

@cicoyle
Copy link
Copy Markdown

@cicoyle cicoyle commented May 26, 2026

Signed-off-by: Cassandra Coyle <cassie@diagrid.io>
Copilot AI review requested due to automatic review settings May 26, 2026 20:04
@cicoyle cicoyle requested a review from a team as a code owner May 26, 2026 20:04
@cicoyle cicoyle changed the title fix critical alert for 1.18 fix critical vuln alert for 1.18 May 26, 2026
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates module dependencies to resolve reported vulnerability alerts originating from durabletask-go, aligning with the referenced Dapr CLI Dependabot advisory and the OpenTelemetry vulnerability notice.

Changes:

  • Bump github.com/jackc/pgx/v5 from v5.7.4 to v5.9.2.
  • Bump core OpenTelemetry modules (otel, sdk, trace, and indirect metric) from v1.39.0 to v1.40.0.
  • Update go.sum accordingly (including removal of now-unreferenced sums such as golang.org/x/crypto).

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
go.mod Updates dependency versions for pgx and OpenTelemetry modules to address vulnerability alerts.
go.sum Refreshes checksums to match the updated module graph after the dependency bumps.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@cicoyle cicoyle merged commit f81b4b8 into dapr:main May 26, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants