Skip to content

chore(deps): refresh Go dependencies#940

Draft
alexluong wants to merge 3 commits into
mainfrom
deps
Draft

chore(deps): refresh Go dependencies#940
alexluong wants to merge 3 commits into
mainfrom
deps

Conversation

@alexluong
Copy link
Copy Markdown
Collaborator

Most open Dependabot alerts in go.mod haven't been actioned, including a couple of criticals (pgx memory safety, grpc auth bypass). This brings every direct Go dep up to latest and clears the backlog so future bumps stay incremental instead of multi-year jumps.

Docker advisories (#407/#408/#409) remain open — no upstream patch, test-only dep via testcontainers.

npm and pip alerts in sdks/*, website/, internal/portal/, examples/ are out of scope for this PR.

alexluong added 3 commits May 30, 2026 02:35
Clears dependabot alerts on pgx (#334 crit), grpc (#242 crit), jwt,
x/oauth2, go-redis, aws s3/kinesis, otel cluster, ch-go, x/crypto.

Docker advisories #407/#408/#409 remain open: upstream has no patched
release yet, test-only dep via testcontainers.
Full sweep via go get -u ./... after the security-driven bumps.
Notable: gocloud.dev 0.39→0.45, sentry-go 0.31→0.46, viper 1.19→1.21,
testcontainers 0.36→0.42, gin-contrib/static, miniredis, sprig,
otelgrpc/otelhttp contrib, golang-migrate.

outpost-go SDK held at v0.4.0 — v1.x is a breaking API change that
would require updating cmd/seed; out of scope for a deps refresh.
cmd/seed was the only internal consumer of sdks/outpost-go and held the
module on v0.4.0. Replacing with direct HTTP calls removes the dep
entirely and unblocks future SDK regenerations.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant