Skip to content

Bump grpc to v1.82.1 to fix GHSA-hrxh-6v49-42gf - #402

Merged
anisaoshafi merged 1 commit into
mainfrom
devx-1013-fix-high-vulnerability-reported-by-trivy-scan
Jul 22, 2026
Merged

Bump grpc to v1.82.1 to fix GHSA-hrxh-6v49-42gf#402
anisaoshafi merged 1 commit into
mainfrom
devx-1013-fix-high-vulnerability-reported-by-trivy-scan

Conversation

@anisaoshafi

@anisaoshafi anisaoshafi commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator

In the recent Dependency Scan, Trivy reported HIGH vulnerability: https://github.com/localstack/lstk/actions/runs/29902094074/job/88864916947,

PR upgrades google.golang.org/grpc (indirect, via OpenTelemetry's OTLP HTTP exporter) from v1.81.1 to v1.82.1, fixing GHSA-hrxh-6v49-42gf (xDS RBAC authorization bypass, HTTP/2 Rapid Reset mitigation bypass, and RBAC engine panic).

As a result, it resolves code-scanning alert https://github.com/localstack/lstk/security/code-scanning/7

@anisaoshafi anisaoshafi added semver: patch docs: skip Pull request does not require documentation changes labels Jul 22, 2026
@anisaoshafi
anisaoshafi marked this pull request as ready for review July 22, 2026 08:45
@anisaoshafi
anisaoshafi requested a review from a team as a code owner July 22, 2026 08:45
@anisaoshafi
anisaoshafi enabled auto-merge (squash) July 22, 2026 08:46
@anisaoshafi
anisaoshafi requested a review from gtsiolis July 22, 2026 08:51
@anisaoshafi
anisaoshafi merged commit 848a36f into main Jul 22, 2026
20 of 21 checks passed
@anisaoshafi
anisaoshafi deleted the devx-1013-fix-high-vulnerability-reported-by-trivy-scan branch July 22, 2026 08:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs: skip Pull request does not require documentation changes semver: patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants