fix(deps): vuln unstable upgrades — 9 packages (unstable: 1 · minor: 8) [src/productcatalogservice]#76
Conversation
Release Notesgoogle.golang.org/grpc (v1.59.0 → v1.80.0) — GitHub Releasev1.80.0Behavior Changes
Bug Fixes
New Features
Performance Improvements
(truncated) v1.79.3Security
v1.79.2Bug Fixes
v1.79.1Bug Fixes
v1.79.0API Changes
Behavior Changes
New Features
Bug Fixes
(truncated) v1.78.0Behavior Changes
New Features
(truncated — see source for full notes) go.opentelemetry.io/otel/sdk (v1.20.0 → v1.43.0) — GitHub Releasev1.43.0Added
Changed
(truncated) v1.42.0Added
Changed
Fixed
Removed
What's Changed
(truncated) v1.41.0This release is the last to support Go 1.24. The next release will require at least Go 1.25. Added
Fixed
What's Changed
(truncated — see source for full notes) google.golang.org/protobuf (v1.31.0 → v1.36.11) — GitHub Releasev1.36.11Full Changelog: protocolbuffers/protobuf-go@v1.36.10...v1.36.11 User-visible changes: Bug fixes: Maintenance: v1.36.10Full Changelog: protocolbuffers/protobuf-go@v1.36.9...v1.36.10 Bug fixes: Maintenance: v1.36.9Full Changelog: protocolbuffers/protobuf-go@v1.36.8...v1.36.9 User-visible changes: v1.36.8Maintenance: CL/696316: all: set Go language version to Go 1.23 v1.36.7Maintenance / optimizations: CL/683955: encoding/protowire: micro-optimize SizeVarint (-20% on Intel) v1.36.6Full Changelog: protocolbuffers/protobuf-go@v1.36.5...v1.36.6 User-visible changes: Maintenance: v1.36.5Full Changelog: protocolbuffers/protobuf-go@v1.36.4...v1.36.5 Bug fixes: Maintenance: v1.36.4Full Changelog: protocolbuffers/protobuf-go@v1.36.3...v1.36.4 Bug fixes: Maintenance: v1.36.3Full Changelog: protocolbuffers/protobuf-go@v1.36.2...v1.36.3 Bug fixes: (truncated — see source for full notes) go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc (v0.46.0 → v0.68.0) — ChangelogAdded
Changed
Fixed
Removed
Deprecated
go.opentelemetry.io/otel (v1.20.0 → v1.43.0) — GitHub Releasev1.43.0Added
Changed
(truncated) v1.42.0Added
Changed
Fixed
Removed
What's Changed
(truncated) v1.41.0This release is the last to support Go 1.24. The next release will require at least Go 1.25. Added
Fixed
What's Changed
(truncated — see source for full notes) go.opentelemetry.io/otel/metric (v1.20.0 → v1.43.0) — GitHub Releasev1.43.0Added
Changed
(truncated) v1.42.0Added
Changed
Fixed
Removed
What's Changed
(truncated) v1.41.0This release is the last to support Go 1.24. The next release will require at least Go 1.25. Added
Fixed
What's Changed
(truncated — see source for full notes) go.opentelemetry.io/otel/sdk/metric (v1.20.0 → v1.43.0) — GitHub Releasev1.43.0Added
Changed
(truncated) v1.42.0Added
Changed
Fixed
Removed
What's Changed
(truncated) v1.41.0This release is the last to support Go 1.24. The next release will require at least Go 1.25. Added
Fixed
What's Changed
(truncated — see source for full notes) go.opentelemetry.io/otel/trace (v1.20.0 → v1.43.0) — GitHub Releasev1.43.0Added
Changed
(truncated) v1.42.0Added
Changed
Fixed
Removed
What's Changed
(truncated) v1.41.0This release is the last to support Go 1.24. The next release will require at least Go 1.25. Added
Fixed
What's Changed
(truncated — see source for full notes) Generated by ADMS Sources: 7 GitHub Releases, 1 Changelog, 1 not available. |
|
Hey, sorry for the noise. This was caused by a bug in our automated dependency update system that incorrectly included upstream changelog content in PR comments, triggering notifications to external contributors. The feature flag has been turned off and we're working on a fix. Sorry about that again. |
Summary: Critical-severity security update — 9 packages upgraded (UNSTABLE changes included)
Manifests changed:
src/productcatalogservice(go)✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.
Updates
Packages marked with "-" are updated due to dependency constraints.
Security Details
🚨 Critical & High Severity (4 fixed)
ℹ️ Other Vulnerabilities (2)
Review Checklist
Standard review:
Update Mode: Vulnerability Remediation (Critical/High)
🤖 Generated by DataDog Automated Dependency Management System