Skip to content

Commit beb1bcc

Browse files
fix: address high & critical vuln alerts (#946)
Dependabot has raised a few high or critical alerts that needed addressing Addressing all of the below except for `https://github.com/smartcontractkit/chainlink-deployments-framework/security/dependabot/22` which is a [transitive dependency](https://github.com/smartcontractkit/chainlink-deployments-framework/security/dependabot/22) <img width="819" height="320" alt="Screenshot 2026-04-21 at 4 17 53 pm" src="https://github.com/user-attachments/assets/7728d748-5d6d-464f-8a35-5f0f44898166" />
1 parent cb237fb commit beb1bcc

3 files changed

Lines changed: 32 additions & 27 deletions

File tree

.changeset/floppy-boxes-move.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"chainlink-deployments-framework": patch
3+
---
4+
5+
bump packages to address security vuln

go.mod

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ require (
5656
golang.org/x/crypto v0.48.0
5757
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa
5858
golang.org/x/oauth2 v0.35.0
59-
google.golang.org/grpc v1.79.2
59+
google.golang.org/grpc v1.79.3
6060
google.golang.org/protobuf v1.36.11
6161
gopkg.in/yaml.v3 v3.0.1
6262
)
@@ -87,7 +87,7 @@ require (
8787
github.com/klauspost/cpuid/v2 v2.2.10 // indirect
8888
github.com/lib/pq v1.10.9 // indirect
8989
github.com/minio/sha256-simd v1.0.1 // indirect
90-
github.com/moby/spdystream v0.5.0 // indirect
90+
github.com/moby/spdystream v0.5.1 // indirect
9191
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
9292
github.com/smartcontractkit/chainlink-common v0.10.1-0.20260217160002-b56cb5356cc7 // indirect
9393
github.com/smartcontractkit/chainlink-common/pkg/chipingress v0.0.10 // indirect
@@ -142,7 +142,7 @@ require (
142142
github.com/btcsuite/btcd/btcec/v2 v2.3.4 // indirect
143143
github.com/btcsuite/btcd/btcutil v1.1.6 // indirect
144144
github.com/btcsuite/btcd/chaincfg/chainhash v1.1.0 // indirect
145-
github.com/buger/jsonparser v1.1.1 // indirect
145+
github.com/buger/jsonparser v1.1.2 // indirect
146146
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
147147
github.com/cespare/xxhash/v2 v2.3.0 // indirect
148148
github.com/cloudevents/sdk-go/binding/format/protobuf/v2 v2.16.1 // indirect
@@ -306,7 +306,7 @@ require (
306306
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
307307
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 // indirect
308308
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.65.0 // indirect
309-
go.opentelemetry.io/otel v1.41.0 // indirect
309+
go.opentelemetry.io/otel v1.43.0 // indirect
310310
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.12.2 // indirect
311311
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp v0.12.2 // indirect
312312
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.36.0 // indirect
@@ -318,17 +318,17 @@ require (
318318
go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.36.0 // indirect
319319
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.36.0 // indirect
320320
go.opentelemetry.io/otel/log v0.15.0 // indirect
321-
go.opentelemetry.io/otel/metric v1.41.0 // indirect
322-
go.opentelemetry.io/otel/sdk v1.41.0 // indirect
321+
go.opentelemetry.io/otel/metric v1.43.0 // indirect
322+
go.opentelemetry.io/otel/sdk v1.43.0 // indirect
323323
go.opentelemetry.io/otel/sdk/log v0.15.0 // indirect
324-
go.opentelemetry.io/otel/sdk/metric v1.41.0 // indirect
325-
go.opentelemetry.io/otel/trace v1.41.0 // indirect
324+
go.opentelemetry.io/otel/sdk/metric v1.43.0 // indirect
325+
go.opentelemetry.io/otel/trace v1.43.0 // indirect
326326
go.opentelemetry.io/proto/otlp v1.9.0 // indirect
327327
go.uber.org/multierr v1.11.0 // indirect
328328
go.uber.org/ratelimit v0.3.1 // indirect
329329
golang.org/x/net v0.50.0 // indirect
330330
golang.org/x/sync v0.19.0 // indirect
331-
golang.org/x/sys v0.41.0 // indirect
331+
golang.org/x/sys v0.42.0 // indirect
332332
golang.org/x/term v0.40.0 // indirect
333333
golang.org/x/text v0.34.0 // indirect
334334
golang.org/x/time v0.14.0

go.sum

Lines changed: 18 additions & 18 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)