Skip to content

security: vulnerability remediation#306

Merged
ulziibay-kernel merged 1 commit into
mainfrom
security/vuln-remediation
Jul 22, 2026
Merged

security: vulnerability remediation#306
ulziibay-kernel merged 1 commit into
mainfrom
security/vuln-remediation

Conversation

@kernel-internal

@kernel-internal kernel-internal Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Vulnerability Remediation

This PR was generated by the Socket-centric vulnerability remediation workflow. Review the planned dependency changes and confirmation evidence before merging.

Fixed

CVE/GHSA Package Ecosystem Old Version New Version Manifest Confirmation
GHSA-3fxj-6jh8-hvhx github.com/go-chi/chi/v5 None v5.2.3 5.3.0 confirmed

Not Included

  • Deferred by batch limit: 27 advisories. They will be considered by future runs.
  • Other deferred scanner findings: 2.
  • Unconfirmed attempted fixes: 0.
Deferred details
CVE/GHSA Package Reason
Unavailable from detector golang.org/x/crypto Missing CVE/GHSA identifier required for Socket fix planning.
Unavailable from detector google.golang.org/grpc Missing CVE/GHSA identifier required for Socket fix planning.

Note

Low Risk
Patch-level router dependency bump with no code changes; typical low-risk security remediation, though HTTP routing behavior should be smoke-tested.

Overview
Bumps github.com/go-chi/chi/v5 from v5.2.3 to v5.3.0 in go.mod and go.sum to address GHSA-3fxj-6jh8-hvhx. There are no application source changes; the API still routes HTTP through chi (cmd/api).

go mod also moves github.com/klauspost/compress, github.com/pierrec/lz4/v4, and gopkg.in/yaml.v3 from indirect to direct require entries—dependency graph housekeeping only, not new features.

Reviewed by Cursor Bugbot for commit 884c69e. Bugbot is set up for automated code reviews on this repo. Configure here.

@socket-security

socket-security Bot commented Jul 15, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgithub.com/​go-chi/​chi/​v5@​v5.2.3 ⏵ v5.3.070 +1100 +24100100100

View full report

@kernel-internal
kernel-internal Bot force-pushed the security/vuln-remediation branch from 574241f to 884c69e Compare July 22, 2026 04:09
@ulziibay-kernel
ulziibay-kernel merged commit 8c15a6c into main Jul 22, 2026
13 checks passed
@ulziibay-kernel
ulziibay-kernel deleted the security/vuln-remediation branch July 22, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant