Skip to content

VULN UPGRADE: google.golang.org/grpc (minor → v1.78.0) [grpc_check/tests]#2874

Closed
campaigner-prod[bot] wants to merge 1 commit intomasterfrom
engraver-auto-version-upgrade/minorpatch/go/tests/1-1767840668
Closed

VULN UPGRADE: google.golang.org/grpc (minor → v1.78.0) [grpc_check/tests]#2874
campaigner-prod[bot] wants to merge 1 commit intomasterfrom
engraver-auto-version-upgrade/minorpatch/go/tests/1-1767840668

Conversation

@campaigner-prod
Copy link
Copy Markdown
Contributor

Summary: High-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • grpc_check/tests (go)

Updates

Package From To Type Vulnerabilities Fixed
google.golang.org/grpc v1.48.0 v1.78.0 minor 1 HIGH

Security Details

🚨 Critical & High Severity (1 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
google.golang.org/grpc GHSA-m425-mq94-257g HIGH gRPC-Go HTTP/2 Rapid Reset vulnerability v1.48.0 1.56.3
⚠️ Dependencies that have Reached EOL (1)
Dependency Unsafe Version EOL Date New Version Path
google.golang.org/grpc v1.48.0 Jul 12, 2025 v1.78.0 grpc_check/tests/docker/go.mod

Review Checklist

Enhanced review recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment

Update Mode: Vulnerability Remediation (High)

🤖 Generated by DataDog Automated Dependency Management System

@github-actions
Copy link
Copy Markdown

This pull request has not been updated for more than 21 days. If there are no updates to this PR within 7 days, it will be closed. If you'd like to re-open this PR after it's been closed, you can start from the latest master branch or pull the latest changes into your branch and create a new pull request.

@github-actions github-actions Bot added the stale label Jan 29, 2026
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Feb 5, 2026

This pull request was not updated after an additional 7 days of no activity. If you would like to continue work on this PR, please re-open this PR or create a fresh branch off of the latest master branch.

@github-actions github-actions Bot closed this Feb 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants