Skip to content

chore(cve-fix): bump vulnerable dependencies - #3308

Open
neogopher wants to merge 1 commit into
devspace-sh:mainfrom
neogopher:fix-snyk-cves
Open

chore(cve-fix): bump vulnerable dependencies#3308
neogopher wants to merge 1 commit into
devspace-sh:mainfrom
neogopher:fix-snyk-cves

Conversation

@neogopher

Copy link
Copy Markdown
Contributor

What issue type does this pull request address? (keep at least one, remove the others)
/kind bugfix

What does this pull request do? Which issues does it resolve? (use resolves #<issue_number> if possible)
resolves #

Please provide a short message that should be published in the DevSpace release notes
Fixed an issue where DevSpace ...

What else do we need to know?

Direct dependencies bumped:
- google.golang.org/grpc v1.74.2 -> v1.83.2 (CVE-2026-33186 and others)
- golang.org/x/net v0.47.0 -> v0.58.0 (CVE-2026-39821 and others)
- golang.org/x/crypto v0.40.0 -> v0.56.0 (multiple x/crypto/ssh CVEs)
- gopkg.in/src-d/go-git.v4 v4.13.1 -> github.com/go-git/go-git/v5 v5.19.2
  (CVE-2023-49569, Path Traversal; go-git.v4 has no available fix and is
  unmaintained, so this is a migration to the maintained v5 module, not a
  version bump)

Indirect fixes reached by bumping k8s.io/api, k8s.io/apimachinery,
k8s.io/cli-runtime, k8s.io/client-go, k8s.io/component-base, and
k8s.io/kubectl in lockstep to v0.35.8:
- github.com/moby/spdystream v0.4.0 -> v0.5.1
@netlify

netlify Bot commented Sep 8, 2026

Copy link
Copy Markdown

Deploy Preview for devspace-docs canceled.

Built without sensitive environment variables

Name Link
🔨 Latest commit 39ce932
🔍 Latest deploy log https://app.netlify.com/projects/devspace-docs/deploys/6aa009d5c6fca40008ff2435

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant