Skip to content

fix(vuln): bump go 1.26.4 + go-git/v5 5.19.1 - #33

Merged
nanjingfm merged 1 commit into
alauda-v4.3.3from
fix/stdlib-1264-gogit-5191
Jun 10, 2026
Merged

nanjingfm merged 1 commit into
alauda-v4.3.3from
fix/stdlib-1264-gogit-5191

Conversation

@nanjingfm

Copy link
Copy Markdown
Collaborator

Summary

  • Bump go directive 1.26.3 → 1.26.4 (stdlib CVEs)
  • Bump go-git/v5 5.19.0 → 5.19.1

CVEs

Needed by gitlab-chart alauda-18.5.4 vuln scan (gomplate binary embeds these).

🤖 Generated with Claude Code

- stdlib CVE-2026-42504 / CVE-2026-27145 / CVE-2026-42507 (go 1.26.4)
- go-git/v5 CVE-2026-45570 / CVE-2026-45571 / GHSA-w5pp-99ch-qj29 (5.19.1)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@nanjingfm
nanjingfm merged commit fb39719 into alauda-v4.3.3 Jun 10, 2026
1 check passed
@nanjingfm
nanjingfm deleted the fix/stdlib-1264-gogit-5191 branch June 10, 2026 14:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant