fix(deps): vuln minor upgrades — 15 packages (minor: 6 · patch: 9) [sdk]#86
Conversation
Release Notesgoogle.golang.org/grpc (v1.70.0 → v1.80.0) — GitHub Releasev1.80.0Behavior Changes
Bug Fixes
New Features
Performance Improvements
(truncated) v1.79.3Security
v1.79.2Bug Fixes
v1.79.1Bug Fixes
v1.79.0API Changes
Behavior Changes
New Features
(truncated — see source for full notes) github.com/go-jose/go-jose/v4 (v4.0.5 → v4.1.4) — GitHub Releasev4.1.4What's ChangedFixes Panic in JWE decryption. See GHSA-78h2-9frx-2jm8 Full Changelog: go-jose/go-jose@v4.1.3...v4.1.4 v4.1.3This release drops Go 1.23 support as that Go release is no longer supported. With that, we can drop This release fixes a bug where a critical b64 header was ignored if in an unprotected header. It is now rejected instead of ignored. What's Changed
Full Changelog: go-jose/go-jose@v4.1.2...v4.1.3 v4.1.2What's Changedgo-jose v4.1.2 improves some documentation, errors, and removes the only 3rd-party dependency.
New Contributors
Full Changelog: go-jose/go-jose@v4.1.1...v4.1.2 v4.1.1What's Changed
New Contributors
Full Changelog: go-jose/go-jose@v4.1.0...v4.1.1 v4.1.0What's Changed
New Contributors
Full Changelog: go-jose/go-jose@v4.0.5...v4.1.0 cloud.google.com/go/cloudsqlconn (v1.4.3 → v1.21.0) — GitHub Releasev1.21.01.21.0 (2026-04-16)Features
v1.20.21.20.2 (2026-03-17)Bug Fixes
Note
v1.20.11.20.1 (2026-02-17)Bug Fixes
v1.20.01.20.0 (2026-01-12)Features
v1.19.11.19.1 (2025-12-09)Bug Fixes
v1.19.01.19.0 (2025-10-23)Features
Bug Fixes
(truncated — see source for full notes) github.com/hashicorp/go-version (v1.7.0 → v1.9.0) — GitHub Releasev1.9.0What's ChangedEnhancements
Internal
New Contributors
Full Changelog: hashicorp/go-version@v1.8.0...v1.9.0 v1.8.0What's Changed
New Contributors
(truncated) github.com/hashicorp/vault/api (v1.16.0 → v1.23.0) — GitHub Releasev1.21.4SECURITY:
CHANGES:
IMPROVEMENTS:
BUG FIXES:
(truncated) v1.21.3February 05, 2026SECURITY: auth/cert: ensure that the certificate being renewed matches the certificate attached to the session. CHANGES: core: Bump Go version to 1.25.6 FEATURES: UI: Hashi-Built External Plugin Support: Recognize and support Hashi-built plugins when run as external binaries IMPROVEMENTS: core/managed-keys (enterprise): Allow GCP managed keys to leverage workload identity federation credentials BUG FIXES: agent: Fix Vault Agent discarding cached tokens on transient server errors instead of retrying v1.21.21.21.2January 07, 2026CHANGES:
(truncated — see source for full notes) github.com/go-ldap/ldap/v3 (v3.4.10 → v3.4.13) — GitHub Releasev3.4.13What's Changed
New Contributors
Full Changelog: go-ldap/ldap@v3.4.12...v3.4.13 v3.4.12What's New
What's Changed
New Contributors
Full Changelog: go-ldap/ldap@v3.4.11...v3.4.12 v3.4.11What's Changed
New Contributors
(truncated — see source for full notes) github.com/google/certificate-transparency-go (v1.3.1 → v1.3.3) — GitHub Releasev1.3.3What's ChangedCTFE
ToolsLog list library
Submission proxy
Other
Misc
Dependency updates
(truncated) v1.3.2v1.3.2What's changed?
Misc
CTFE Storage Saving: Extra Data Issuance Chain Deduplication
CTFE Rate Limiting Of Non-Fresh Submissions(truncated — see source for full notes) github.com/hashicorp/go-kms-wrapping/v2 (v2.0.18 → v2.0.21) — Commit comparison
... and 2 more commits github.com/hashicorp/go-secure-stdlib/password (v0.1.1 → v0.1.5) — Commit comparison
... and 85 more commits github.com/hashicorp/go-secure-stdlib/plugincontainer (v0.4.1 → v0.4.2) — Commit comparison
... and 11 more commits github.com/sasha-s/go-deadlock (v0.3.5 → v0.3.9) — GitHub Releasev0.3.9Reduce allocations from callers (sasha-s/go-deadlock#54), add new unit tests, and fix existing -race unit test failures v0.3.8What's Changed
Full Changelog: sasha-s/go-deadlock@v0.3.7...v0.3.8 v0.3.7Release v0.3.7 Changes
What's NewThis release improves v0.3.6Release v0.3.6 Changes
What's NewThis release includes compatibility updates for Go 1.25 and dependency updates to ensure continued reliability of deadlock detection. google.golang.org/protobuf (v1.36.5 → v1.36.11) — GitHub Releasev1.36.11Full Changelog: protocolbuffers/protobuf-go@v1.36.10...v1.36.11 User-visible changes: Bug fixes: Maintenance: v1.36.10Full Changelog: protocolbuffers/protobuf-go@v1.36.9...v1.36.10 Bug fixes: Maintenance: v1.36.9Full Changelog: protocolbuffers/protobuf-go@v1.36.8...v1.36.9 User-visible changes: v1.36.8Maintenance: CL/696316: all: set Go language version to Go 1.23 v1.36.7Maintenance / optimizations: CL/683955: encoding/protowire: micro-optimize SizeVarint (-20% on Intel) (truncated — see source for full notes) Generated by ADMS Sources: 9 GitHub Releases, 3 Commit comparisons, 3 not available. |
|
Hey, sorry for the noise. This was caused by a bug in our automated dependency update system that incorrectly included upstream changelog content in PR comments, triggering notifications to external contributors. The feature flag has been turned off and we're working on a fix. Sorry about that again. |
Summary: Critical-severity security update — 15 packages upgraded (MINOR changes included)
Manifests changed:
sdk(go)✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.
Updates
Packages marked with "-" are updated due to dependency constraints.
Security Details
🚨 Critical & High Severity (4 fixed)
v5.6.0v5.9.11sdk/go.modv0.1.1v0.1.5sdk/go.modReview Checklist
Standard review:
Update Mode: Vulnerability Remediation (Critical/High)
🤖 Generated by DataDog Automated Dependency Management System