Skip to content

Security fixes 28jul26 - #3226

Open
stevenhorsman wants to merge 2 commits into
confidential-containers:mainfrom
stevenhorsman:security-fixes-28jul26
Open

Security fixes 28jul26#3226
stevenhorsman wants to merge 2 commits into
confidential-containers:mainfrom
stevenhorsman:security-fixes-28jul26

Conversation

@stevenhorsman

Copy link
Copy Markdown
Member

Fixes for two high and one moderate severity security issues

stevenhorsman and others added 2 commits July 28, 2026 11:56
Upgrade google.golang.org/grpc from v1.79.3 to v1.82.1 in src/webhook
and from v1.81.1 to v1.82.1 in src/cloud-providers to fix CVE
GO-2026-6061 (vulnerabilities in the xDS RBAC authorization engine and
HTTP/2 transport server implementation).

Generated-By: IBM Bob
Signed-off-by: stevenhorsman <steven@uk.ibm.com>
Bumps [github.com/google/cel-go](https://github.com/google/cel-go) from 0.26.0 to 0.29.0.
- [Release notes](https://github.com/google/cel-go/releases)
- [Commits](cel-expr/cel-go@v0.26.0...v0.29.0)

---
updated-dependencies:
- dependency-name: github.com/google/cel-go
  dependency-version: 0.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security Vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants