<!-- Hello Thanos maintainers, We are currently running Thanos v0.42.4 (the latest stable release) in our FedRAMP-regulated production environment. Our vulnerability scanners have identified the following CVEs that require dependency updates: 1. CVE-2026-42151 & CVE-2026-42154 - Require Prometheus v0.311.3 2. CVE-2026-56852 - Requires golang.org/x/text v0.39.0 3. GHSA-hrxh-6v49-42gf - Requires google.golang.org/grpc v1.82.1 Looking at https://github.com/thanos-io/thanos/blob/v0.42.4/go.mod, Thanos v0.42.4 currently vendors: - github.com/prometheus/prometheus v0.309.1 (needs v0.311.3) - golang.org/x/text v0.38.0 (needs v0.39.0) - google.golang.org/grpc v1.81.1 (needs v1.82.1) Could you please provide an update on plans to release v0.42.5 or v0.43.0 with these updated dependencies? Thank you for your work on this project! Ref: CVE-2026-42151, CVE-2026-42154, CVE-2026-56852, GHSA-hrxh-6v49-42gf -->