fix(deps): patch 5 Dependabot vulnerabilities (2 critical, 1 high, 2 medium)#2103
Conversation
…medium) - google.golang.org/grpc: 1.78.0 -> 1.79.3 (GHSA-p77j-4mvh-x3m3, critical) - github.com/jackc/pgx/v5: 5.8.0 -> 5.9.2 (GHSA-9jj7-4m8r-rfcm critical, GHSA-j88v-2chj-qfwx low) - go.opentelemetry.io/otel: 1.39.0 -> 1.41.0 (GHSA-mh2q-q3fh-2475, high) - com.itextpdf:itext7-core: 7.1.7 -> 7.2.0 (GHSA-hhh6-cm2m-3fhc, GHSA-8c9h-4q7g-fp7h, GHSA-c32g-2mgr-cfq7, medium x3) - org.postgresql:postgresql: 42.7.2 -> 42.7.11 (GHSA-98qh-xjc8-98pq, high)
|
itext7-core is not used at all in this project, dependency is removable, the real pdf dependency is: flying-saucer-pdf v9.1.22 |
Signed-off-by: Osmany Montero <osmontero@icloud.com>
❌ Go dependencies check failedThere are outdated Go dependencies, or modules that could not be inspected. Script output |
🛑 AI review — Engineer review requiredThis PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. @Kbayero @osmontero please review. 🛑
|
Dependabot Remediation
Patches 5 open Dependabot alerts that affect the release/v11.2.9 branch.
Fixes
google.golang.org/grpcgithub.com/jackc/pgx/v5go.opentelemetry.io/otelcom.itextpdf:itext7-coreorg.postgresql:postgresqlFiles Changed
plugins/compliance-orchestrator/go.mod+go.sumagent-manager/go.mod+go.suminstaller/go.mod+go.sumbackend/pom.xmluser-auditor/pom.xmlAll
go mod tidypasses cleanly.Not Fixed (Out of Scope)
dompurify,follow-redirects,postcss,uuid,webpack-dev-serverare transitive from Angular 7 build toolchain. Require major framework upgrade.github.com/docker/docker(6 alerts) — no upstream patch available yet.mutate/pip deps (4 alerts) — directory removed; stale alerts on default branch only.