Skip to content

dep(grpc): Update google.golang.org/grpc to v1.83.2 for CVE-2026-84445 - #151

Merged
Brindrajsinh-Chauhan merged 1 commit into
release-op-node/v1.18.2from
fix/grpc-cve-2026-84445
Sep 9, 2026
Merged

Brindrajsinh-Chauhan merged 1 commit into
release-op-node/v1.18.2from
fix/grpc-cve-2026-84445

Conversation

@Chengxuan

Copy link
Copy Markdown

Description

CVE patch. Bumps google.golang.org/grpc (indirect dependency) from v1.83.1 to v1.83.2 for CVE-2026-84445 (HIGH). Bumped via go get + go mod tidy, verified by building op-node, op-batcher, and op-proposer (via just) using the go1.26 toolchain this fork's Dockerfile pins.

Note: PR #147 on this branch is a separate, older, stale attempt targeting a different CVE (bumps grpc only to v1.82.1) and is left untouched here.

Details

  • CVE patch
  • Fork sync
  • Routine dependency bump

🤖 Generated with Claude Code

CVE-2026-84445 (HIGH). Indirect dependency, bumped via go get + go mod
tidy. Verified by building op-node, op-batcher, and op-proposer (via
just) using the go1.26 toolchain this fork's Dockerfile pins.
@Brindrajsinh-Chauhan
Brindrajsinh-Chauhan merged commit f874fdd into release-op-node/v1.18.2 Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants