fix: upgrade vulnerable Go dependencies to fix CRITICAL/HIGH CVEs - #240
Open
qiluo-msft wants to merge 3 commits into
Open
fix: upgrade vulnerable Go dependencies to fix CRITICAL/HIGH CVEs#240qiluo-msft wants to merge 3 commits into
qiluo-msft wants to merge 3 commits into
Conversation
- google.golang.org/grpc v1.28.0 -> v1.82.1 (CVE-2026-33186, GHSA-hrxh-6v49-42gf) - golang.org/x/text v0.3.3 -> v0.39.0 (CVE-2020-14040, CVE-2021-38561, CVE-2026-56852) - antchfx/xpath v1.1.10 -> v1.3.6 (CVE-2026-32287, direct dependency) - antchfx/jsonquery v1.1.4 -> v1.3.7 (parent of vulnerable xpath) - antchfx/xmlquery v1.3.1 -> v1.5.1 (parent of vulnerable xpath) Signed-off-by: qiluo <qiluo@microsoft.com>
Signed-off-by: qiluo <qiluo@microsoft.com>
- Add replace directive to pin github.com/golang/glog to v0.0.0-20160126235308-23def4e6c14b (grpc v1.82.1 requires v1.2.5 but patches/glog.patch targets the old API which no longer exists in v1.2.5) - Restore go directive to 1.24.4 to avoid requiring CI toolchain upgrade Signed-off-by: qiluo <qiluo@microsoft.com>
|
/azp run |
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
There was a problem hiding this comment.
Pull request overview
This PR updates Go module dependencies in sonic-mgmt-common (shared libraries/models for SONiC management, including translib/CVL) to address reported CRITICAL/HIGH CVEs, primarily by bumping key modules and regenerating dependency locks.
Changes:
- Upgraded
google.golang.org/grpc,golang.org/x/text, and theantchfx/*query+antchfx/xpathdependency chain to newer versions. - Updated transitive dependency versions/hashes via
go mod tidyoutput (go.sumrefresh). - Added a
replacedirective to pingithub.com/golang/glogto the pre-v1 API to keeppatches/glog.patchapplicable.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| go.mod | Bumps direct/indirect module versions and adds a replace to pin glog for patch compatibility. |
| go.sum | Regenerates checksum set to match the updated dependency graph. |
| github.com/go-redis/redis/v7 v7.4.1 | ||
| github.com/godbus/dbus/v5 v5.1.0 | ||
| github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b | ||
| github.com/golang/glog v1.2.5 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why I did it
Trivy CVE scan identified multiple CRITICAL and HIGH severity vulnerabilities in the Go module dependencies of sonic-mgmt-common.
How I did it
Updated
go.modand regeneratedgo.sumviago mod tidywith the following version bumps:google.golang.org/grpcgolang.org/x/textgithub.com/antchfx/xpathgithub.com/antchfx/jsonquerygithub.com/antchfx/xmlqueryAdditionally:
replacedirective to pingithub.com/golang/glogtov0.0.0-20160126235308-23def4e6c14b—grpc v1.82.1transitively requiresglog v1.2.5, butpatches/glog.patchwas written for the old glog API (which no longer exists in v1.2.5). The pin preserves the existing patch compatibility.godirective at1.24.4(reverted fromgo mod tidy's1.25.0bump) to avoid forcing a CI toolchain upgrade.How to verify it
trivy fs . --severity CRITICAL,HIGHCRITICAL count should drop to 0 for these packages; HIGH count should decrease substantially.