Skip to content

chore(deps): fix CVE vulnerabilities#32

Merged
l-qing merged 1 commit into
alauda-v1.33.7from
fix/alauda-v1.33.7-cve
Apr 22, 2026
Merged

chore(deps): fix CVE vulnerabilities#32
l-qing merged 1 commit into
alauda-v1.33.7from
fix/alauda-v1.33.7-cve

Conversation

@nanjingfm

Copy link
Copy Markdown

Fixed CVEs

Severity CVE Package Version Change
HIGH CVE-2026-35469 github.com/moby/spdystream v0.5.0 → v0.5.1
HIGH CVE-2026-39883 go.opentelemetry.io/otel/sdk v1.40.0 → v1.43.0
MEDIUM CVE-2025-11065 github.com/go-viper/mapstructure/v2 v2.2.1 → v2.4.0
MEDIUM CVE-2024-45339 github.com/golang/glog v1.2.2 → v1.2.4

Also upgraded Go to latest version.

Verified: trivy scan shows 0 vulnerabilities after fix.

@nanjingfm nanjingfm force-pushed the fix/alauda-v1.33.7-cve branch from dc62d15 to c05583c Compare April 22, 2026 03:00
@l-qing l-qing merged commit 0c8acf0 into alauda-v1.33.7 Apr 22, 2026
2 checks passed
@l-qing l-qing deleted the fix/alauda-v1.33.7-cve branch April 22, 2026 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants