chore: update vulnerable packages by keegancsmith · Pull Request #1229 · sourcegraph/src-cli

Conversation

@keegancsmith

Copy link Copy Markdown

Member

I did the minimal upgrades needed to resolve the CVE's reported by trivy.

Test Plan: CI

I did the minimal upgrades needed to resolve the CVE's reported by
trivy.

- CVE-2025-54410 github.com/docker/docker v25.0.6 -> v28.0.0
- GHSA-vrw8-fxc6-2r93 github.com/go-chi/chi/v5 v5.0.10 -> v5.2.2
- CVE-2025-47908 github.com/rs/cors v1.9.0 -> v1.11.0
- CVE-2025-47914 golang.org/x/crypto v0.43.0 -> v0.45.0
- CVE-2025-58181 golang.org/x/crypto

Test Plan: CI

@keegancsmith keegancsmith requested review from a team and evict

December 8, 2025 12:29
Copy link Copy Markdown

Contributor

@evict evict left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🙏

@keegancsmith keegancsmith merged commit d1a299e into main

Dec 8, 2025

6 of 8 checks passed

@keegancsmith keegancsmith deleted the k/vuln branch

December 8, 2025 12:49

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

@burmudar burmudar burmudar approved these changes

@evict evict evict approved these changes

@eseliger eseliger eseliger approved these changes

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

4 participants

@keegancsmith @burmudar @evict @eseliger