Skip to content

Update Go references and vulnerable dependencies - #1204

Merged
collin-lee merged 2 commits into
envoyproxy:mainfrom
endgame01:codex/update-go-1.26.5
Aug 5, 2026
Merged

Update Go references and vulnerable dependencies#1204
collin-lee merged 2 commits into
envoyproxy:mainfrom
endgame01:codex/update-go-1.26.5

Conversation

@endgame01

@endgame01 endgame01 commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Summary

Updates Go from 1.26.4 to 1.26.5 across CI, module files, and Docker images. It also updates vulnerable dependencies found during review:

  • gRPC to 1.83.0 in both modules
  • OpenTelemetry to 1.44.0
  • related xDS example dependencies

This consolidates the updates from #1181 and #1184 and fixes the gRPC and OpenTelemetry advisories reported by govulncheck.

Validation

  • govulncheck reports no vulnerabilities in either module
  • unit tests pass for both modules
  • Docker race and integration tests pass

Signed-off-by: Phellippe Lima <phellippe.end@gmail.com>
Signed-off-by: Phellippe Lima <phellippe.end@gmail.com>
@endgame01 endgame01 changed the title Update Go references to 1.26.5 Update Go references and vulnerable dependencies Aug 3, 2026
@endgame01
endgame01 marked this pull request as ready for review August 3, 2026 11:37
@collin-lee
collin-lee merged commit 91e3066 into envoyproxy:main Aug 5, 2026
6 checks passed
@phpinhei-te

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants