Skip to content

chore: Bump deps to resolve CVEs#14

Merged
brendan-kellam merged 1 commit into
mainfrom
bkellam/fix-cves
May 16, 2026
Merged

chore: Bump deps to resolve CVEs#14
brendan-kellam merged 1 commit into
mainfrom
bkellam/fix-cves

Conversation

@brendan-kellam
Copy link
Copy Markdown

No description provided.

@brendan-kellam brendan-kellam merged commit 2566953 into main May 16, 2026
14 of 15 checks passed
@brendan-kellam brendan-kellam deleted the bkellam/fix-cves branch May 16, 2026 00:06
mjdusa pushed a commit to mjdusa/zoekt that referenced this pull request May 19, 2026
- google.golang.org/grpc 1.75.0 -> 1.80.0 (addresses GHSA critical sourcebot-dev#11:
  authorization bypass via missing leading slash in :path).
- go.opentelemetry.io/otel* 1.42.0/1.33.0 -> 1.43.0 (addresses sourcegraph#15 high:
  BSD kenv PATH hijack, and sourcebot-dev#14 medium: unbounded OTLP HTTP response body).

Fixes Dependabot alerts 11, 14, 15 on sourcebot-dev/zoekt.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant