Skip to content

Conversation

@ulucinar
Copy link

Summary

This PR fixes CVE vulnerabilities identified by security scanning.

Vulnerabilities Fixed

CVE/GHSA Severity Package Fixed Version
GHSA-6v2p-p543-phr9 High golang.org/x/oauth2 v0.27.0
CVE-2025-61723 High stdlib go1.24.11
CVE-2025-61725 High stdlib go1.24.11
CVE-2025-58188 High stdlib go1.24.11
CVE-2025-58187 High stdlib go1.24.11
CVE-2025-61729 High stdlib go1.24.11
GHSA-j5w8-q4qc-rx2x Medium golang.org/x/crypto v0.45.0
GHSA-f6x5-jh6r-wrfv Medium golang.org/x/crypto v0.45.0
CVE-2025-58185 Medium stdlib go1.24.11
CVE-2025-47912 Medium stdlib go1.24.11
CVE-2025-58186 Medium stdlib go1.24.11
CVE-2025-61724 Medium stdlib go1.24.11
CVE-2025-58189 Medium stdlib go1.24.11
CVE-2025-58183 Medium stdlib go1.24.11
CVE-2025-61727 Medium stdlib go1.24.11

Changes Made

  • Updated golang.org/x/oauth2 from v0.22.0 to v0.27.0
  • Updated golang.org/x/crypto from v0.36.0 to v0.45.0
  • Updated Go toolchain from go1.24.4 to go1.24.11
  • Ran go mod tidy to update transitive dependencies

References

Verification

  • Rescanned with cve-scan skill after fixes
  • All listed vulnerabilities resolved

- Update golang.org/x/oauth2 to v0.27.0 (fixes GHSA-6v2p-p543-phr9)
- Update golang.org/x/crypto to v0.45.0 (fixes GHSA-j5w8-q4qc-rx2x, GHSA-f6x5-jh6r-wrfv)
- Update Go toolchain to go1.24.11 (fixes CVE-2025-61723, CVE-2025-61725, CVE-2025-58188, CVE-2025-58187, CVE-2025-61729, CVE-2025-58185, CVE-2025-47912, CVE-2025-58186, CVE-2025-61724, CVE-2025-58189, CVE-2025-58183, CVE-2025-61727)

Signed-off-by: Alper Rifat Ulucinar <ulucinar@users.noreply.github.com>
@ulucinar
Copy link
Author

Build Failure Analysis

Check: push
Status: Failed
Analyzed: 2026-01-22T09:09:37Z

Summary

The push check failed with HTTP 404 error when downloading the up CLI tool from https://cli.upbound.io.

Root Cause

The upbound/action-up@v1 GitHub Action attempted to download the up CLI binary (version v0.39.0-384.g0a0c8634) but received an HTTP 404 (Not Found) response. This is a transient CI infrastructure issue where the requested binary was temporarily unavailable from the download server.

This failure is NOT related to the code changes in this PR. All other checks (build, lint, unit-test) passed successfully.

Error Details

##[error]Unexpected HTTP response: 404

This occurred during the upbound/action-up@v1 step with parameters:

Recommendation

Retry the workflow. This is a transient infrastructure issue. Re-running the failed job should resolve the problem as the CLI binary availability is typically restored quickly.


This analysis was generated by the build-failure-analyze skill.

@ulucinar ulucinar closed this Jan 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants