Skip to content

Pin grpc to 1.83.2 to clear GO-2026-6443 - #304

Merged
KeiaiLab-PHIL merged 1 commit into
mainfrom
fix/grpc-1.83.2
Oct 6, 2026
Merged

KeiaiLab-PHIL merged 1 commit into
mainfrom
fix/grpc-1.83.2

Conversation

@KeiaiLab-PHIL

Copy link
Copy Markdown
Contributor

Scorecard VulnerabilitiesID flags grpc v1.84.0 (indirect, via
controller-runtime -> k8s.io/apiserver). The Go vulndb marks
GO-2026-6443 (server panic on missing authority/Host) as affecting
<1.82.2, 1.83.0-1.83.1 and 1.84.0-dev through 1.84.0; the only 1.84+
fix is an unreleased 1.85.0-dev. 1.83.2 is the newest released fixed
version. govulncheck now reports 0 findings.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Signed-off-by: phil phil@keiailab.com

🤖 Generated with Claude Code

Scorecard VulnerabilitiesID flags grpc v1.84.0 (indirect, via
controller-runtime -> k8s.io/apiserver). The Go vulndb marks
GO-2026-6443 (server panic on missing authority/Host) as affecting
<1.82.2, 1.83.0-1.83.1 and 1.84.0-dev through 1.84.0; the only 1.84+
fix is an unreleased 1.85.0-dev. 1.83.2 is the newest released fixed
version. govulncheck now reports 0 findings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: phil <phil@keiailab.com>
@KeiaiLab-PHIL
KeiaiLab-PHIL enabled auto-merge (squash) October 6, 2026 02:46
@KeiaiLab-PHIL
KeiaiLab-PHIL merged commit 6992322 into main Oct 6, 2026
5 checks passed
@KeiaiLab-PHIL
KeiaiLab-PHIL deleted the fix/grpc-1.83.2 branch October 6, 2026 02:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant