chore: fix CVE-2026-33186 for grpc go below 1.80.1#2443
Conversation
On-behalf-of: Gergely Brautigam <gergely.brautigam@sap.com> Signed-off-by: Gergely Brautigam <182850+Skarlso@users.noreply.github.com>
✅ Deploy Preview for ocm-website ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (9)
📒 Files selected for processing (9)
📝 WalkthroughWalkthroughGo module dependencies are updated across nine files in bindings and CLI directories, bumping security and compatibility packages (crypto, net, gRPC, OpenTelemetry) to newer versions and adding indirect dependencies for OpenTelemetry SDK, YAML serialization, and Google Protobuf tooling. A new replace directive for ThalesIgnite/crypto11 is added in the Kubernetes controller module. ChangesDependency Version Updates
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related PRs
Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What this PR does / why we need it
Fixes CVE-2026-33186 for grpc go below 1.80.1 version throughout the entire monorepo.
Which issue(s) this PR fixes
Testing
How to test the changes
Verification
task testandtask test/integrationif applicable)go workis enabled (seego.work)ocm