Skip to content

fix: clear remaining AR high (google.golang.org/grpc) - #159

Merged
thomasrockhu-codecov merged 1 commit into
masterfrom
th/slack-app-grpc-high
Aug 13, 2026
Merged

fix: clear remaining AR high (google.golang.org/grpc)#159
thomasrockhu-codecov merged 1 commit into
masterfrom
th/slack-app-grpc-high

Conversation

@thomasrockhu-codecov

Copy link
Copy Markdown
Contributor

Summary

  • Pin google.golang.org/grpc@v1.82.1 when building berglas from source to clear the remaining fixable AR high (GHSA-hrxh-6v49-42gf on grpc 1.79.3 in /usr/local/bin/berglas).
  • Bump berglas source tag to v2.0.15 and image VERSION to v0.0.2 so CI publishes a new digests for rescan.

Context

Post-#158 ci-latest is 0 critical / 1 high fixable. The high is grpc 1.79.3 → fixed in 1.82.1.

Test plan

  • CI Build and Push succeeds (ci-release-<sha>)
  • AR scan of the new CI digest shows 0 critical / 0 fixable high for google.golang.org/grpc
  • Merge to master so production workflow publishes the remediated image

Made with Cursor

Pin google.golang.org/grpc@v1.82.1 when building berglas from source so the
remaining fixable high in AR (1.79.3) is cleared; bump image VERSION to v0.0.2.

Co-authored-by: Cursor <cursoragent@cursor.com>
@thomasrockhu-codecov
thomasrockhu-codecov merged commit df4b7ef into master Aug 13, 2026
4 checks passed
@thomasrockhu-codecov
thomasrockhu-codecov deleted the th/slack-app-grpc-high branch August 13, 2026 19:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants