Skip to content

fix(deps): fix Go dependency vulnerabilities on alauda-v1.42.3#32

Merged
l-qing merged 1 commit into
alauda-v1.42.3from
fix/vuln-alauda-v1.42.3-by-go-vuln-fix-3
Apr 22, 2026
Merged

fix(deps): fix Go dependency vulnerabilities on alauda-v1.42.3#32
l-qing merged 1 commit into
alauda-v1.42.3from
fix/vuln-alauda-v1.42.3-by-go-vuln-fix-3

Conversation

@l-qing
Copy link
Copy Markdown

@l-qing l-qing commented Apr 22, 2026

  • Upgrade github.com/go-git/go-git/v5 from v5.17.1 to v5.18.0 to address GHSA-3xc5-wrhm-f963.
  • Run Trivy re-scan for the root module and the gotestdata module with 0 remaining fixable vulnerabilities.
  • Verify go build ./... passes in the repository root and in syft/pkg/cataloger/golang/internal/gotestdata/go-source.

- upgrade github.com/go-git/go-git/v5 from v5.17.1 to v5.18.0 (GHSA-3xc5-wrhm-f963)

- verify trivy re-scan reports 0 remaining fixable vulnerabilities

- verify go build ./... passes for the root module and gotestdata module
@lentil1016
Copy link
Copy Markdown

/lgtm

@l-qing l-qing merged commit e89bef7 into alauda-v1.42.3 Apr 22, 2026
5 of 6 checks passed
@l-qing l-qing deleted the fix/vuln-alauda-v1.42.3-by-go-vuln-fix-3 branch April 22, 2026 05:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants