Skip to content

Bump github.com/hashicorp/consul/api from 1.34.4 to 1.34.5 - #374

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/hashicorp/consul/api-1.34.5
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/hashicorp/consul/api-1.34.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 19, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/hashicorp/consul/api from 1.34.4 to 1.34.5.

Commits
  • 0548ce8 sub module release
  • c115f1d fix: upgrade golang.org/x/mod and golang.org/x/crypto to address CVEs (#23913)
  • 78ab247 fix: update debian docker images from bullseye to bookworm (#23909)
  • 132d262 api-gateway: fix cold-start Envoy crash from aggregate clusters missing EDS ...
  • c04f913 security: escape regex metacharacters in SPIFFE RBAC patterns (#23900)
  • 13cdc76 security: bound RPC header size to prevent pre-auth memory exhaustion (#23898)
  • 645a489 security: gate Lua/Wasm extensions and bootstrap escape-hatch keys behind mes...
  • 4fefef9 security: reject non-default PeerName in Catalog.Deregister (#23897)
  • 281d039 security: fix catalog node-ID ACL bypass allowing cross-node takeover (#23899)
  • cdf07d5 fix sec vuln for qs, xmldom and fast-uri (#23895)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/hashicorp/consul/api](https://github.com/hashicorp/consul) from 1.34.4 to 1.34.5.
- [Release notes](https://github.com/hashicorp/consul/releases)
- [Changelog](https://github.com/hashicorp/consul/blob/main/CHANGELOG.md)
- [Commits](hashicorp/consul@api/v1.34.4...api/v1.34.5)

---
updated-dependencies:
- dependency-name: github.com/hashicorp/consul/api
  dependency-version: 1.34.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants