Skip to content

fix: upgrade buger/jsonparser to v1.1.2 (GHSA-6g7g-w4f8-9c9x)#25266

Merged
Shelnutt2 merged 1 commit into
release/2.29from
seth/upgrade-jsonparser-v2.29
May 13, 2026
Merged

fix: upgrade buger/jsonparser to v1.1.2 (GHSA-6g7g-w4f8-9c9x)#25266
Shelnutt2 merged 1 commit into
release/2.29from
seth/upgrade-jsonparser-v2.29

Conversation

@Shelnutt2
Copy link
Copy Markdown
Contributor

Summary

Bumps github.com/buger/jsonparser from v1.1.1 to v1.1.2 on the release/2.29 branch to remediate a high-severity denial-of-service vulnerability.

Advisory GHSA-6g7g-w4f8-9c9x
Severity High
Previous version v1.1.1
Fixed version v1.1.2

Changes

  • go.mod: github.com/buger/jsonparser v1.1.1 -> v1.1.2
  • go.sum: updated checksums

Testing

  • go build ./... passes
  • No API or behavioral changes; this is a transitive dependency bump

Linear issue

Closes ENT-67


Note

This PR was authored by Coder Agents.

Bumps github.com/buger/jsonparser from v1.1.1 to v1.1.2 to fix
a high-severity denial-of-service vulnerability on the v2.29.x
release branch.

Ref: GHSA-6g7g-w4f8-9c9x
@Shelnutt2 Shelnutt2 added dependencies Pull requests that update a dependency file cherry-pick/v2.29 Needs to be cherry-picked to the 2.29 release branch labels May 13, 2026
@Shelnutt2 Shelnutt2 merged commit cd5d736 into release/2.29 May 13, 2026
34 checks passed
@Shelnutt2 Shelnutt2 deleted the seth/upgrade-jsonparser-v2.29 branch May 13, 2026 12:25
@github-actions github-actions Bot locked and limited conversation to collaborators May 13, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

cherry-pick/v2.29 Needs to be cherry-picked to the 2.29 release branch dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants