Skip to content

[INS-425] Updated google.golang.org/grpc v1.78.0 --> v1.79.3#4852

Merged
MuneebUllahKhan222 merged 1 commit intotrufflesecurity:mainfrom
MuneebUllahKhan222:grpc-vulnerability-fix
Apr 1, 2026
Merged

[INS-425] Updated google.golang.org/grpc v1.78.0 --> v1.79.3#4852
MuneebUllahKhan222 merged 1 commit intotrufflesecurity:mainfrom
MuneebUllahKhan222:grpc-vulnerability-fix

Conversation

@MuneebUllahKhan222
Copy link
Copy Markdown
Contributor

@MuneebUllahKhan222 MuneebUllahKhan222 commented Mar 31, 2026

Description:

This PR updates the grpc Go package from version v1.78.0 to v1.79.3 to address a critical security vulnerability identified in the older version reported by dependabot here.

Checklist:

  • Tests passing (make test-community)?
  • Lint passing (make lint this requires golangci-lint)?

Note

Medium Risk
Primarily a dependency-only change, but it updates core RPC/telemetry libraries (grpc, opentelemetry, envoy protos) which could impact runtime behavior and compatibility if any gRPC-based integrations exist.

Overview
Upgrades google.golang.org/grpc from v1.78.0 to v1.79.3 in go.mod/go.sum to incorporate security and bugfix updates.

Also refreshes related transitive dependencies, including go.opentelemetry.io/otel v1.38.0v1.39.0, github.com/envoyproxy/protoc-gen-validate v1.2.1v1.3.0, and updated Envoy/xDS module versions reflected in go.sum.

Written by Cursor Bugbot for commit 141f601. This will update automatically on new commits. Configure here.

@MuneebUllahKhan222 MuneebUllahKhan222 requested a review from a team March 31, 2026 07:16
@MuneebUllahKhan222 MuneebUllahKhan222 merged commit 681b305 into trufflesecurity:main Apr 1, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants