Skip to content

Bump dependencies with known vulnerabilities - #6081

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
auto/bump-vuln-deps
Open

Bump dependencies with known vulnerabilities#6081
github-actions[bot] wants to merge 1 commit into
mainfrom
auto/bump-vuln-deps

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Bump dependencies flagged by govulncheck -scan module to their fixed versions.

Each CVE links to its Go advisory page.

Vulnerabilities in the Go standard library are left to the Bump Go toolchain workflow.

If a bump promotes a new direct dependency, double-check its license annotation in go.mod and NOTICE.

@github-actions github-actions Bot added the Dependencies Pull requests that update a dependency file label Jul 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants