Skip to content

chore: bump deps to patch CVEs - #185

Open
ErickGledson wants to merge 1 commit into
dunglas:mainfrom
ErickGledson:fix/cve-dependencies
Open

ErickGledson wants to merge 1 commit into
dunglas:mainfrom
ErickGledson:fix/cve-dependencies

Conversation

@ErickGledson

@ErickGledson ErickGledson commented Sep 15, 2026 •

Copy link
Copy Markdown

golang.org/x/crypto: v0.55.0 -> v0.56.0 (CVE-2026-56855, CVE-2026-78662)
github.com/caddyserver/caddy/v2: v2.11.3 -> v2.11.4 (CVE-2026-52844, CVE-2026-52845, CVE-2026-52846)
golang.org/x/mod: v0.38.0 -> v0.40.0 (CVE-2026-56864, CVE-2026-56865)
google.golang.org/grpc: v1.81.1 -> v1.83.2 (CVE-2026-84303, CVE-2026-84304, CVE-2026-84445, GHSA-hrxh-6v49-42gf)

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

golang.org/x/crypto: v0.55.0 -> v0.56.0 (CVE-2026-56855, CVE-2026-78662)
github.com/caddyserver/caddy/v2: v2.11.3 -> v2.11.4 (CVE-2026-52844, CVE-2026-52845, CVE-2026-52846)
golang.org/x/mod: v0.38.0 -> v0.40.0 (CVE-2026-56864, CVE-2026-56865)
google.golang.org/grpc: v1.81.1 -> v1.83.2 (CVE-2026-84303, CVE-2026-84304, CVE-2026-84445, GHSA-hrxh-6v49-42gf)

@dunglas dunglas left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, could you sign the CLA please?

@ErickGledson

ErickGledson commented Sep 15, 2026 •

Copy link
Copy Markdown
Author

I signed the CLA, but the status has not been updated yet.

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants