Skip to content

cmd/atlas: Upgrade golang.org/grpc to v1.79.3 for CVE-2026-33186 - #3697

Open
lacurnow wants to merge 1 commit into
ariga:masterfrom
lacurnow:cve-2026-33186-grpc-upgrade
Open

cmd/atlas: Upgrade golang.org/grpc to v1.79.3 for CVE-2026-33186#3697
lacurnow wants to merge 1 commit into
ariga:masterfrom
lacurnow:cve-2026-33186-grpc-upgrade

Conversation

@lacurnow

@lacurnow lacurnow commented Mar 20, 2026

Copy link
Copy Markdown

Summary:
Bumps google.golang.org/grpc from v1.73.0 to v1.79.3 in cmd/atlas/go.mod to address CVE-2026-33186 (Critical).

Motivation:
The compiled atlas-community-linux-amd64 binary is flagged by JFrog Xray with a critical vulnerability in the bundled grpc version. This is blocking downstream users from passing Docker image security scans in CI/CD pipelines.

Changes:

  • Bumped google.golang.org/grpc to v1.79.3 in cmd/atlas/go.mod
  • Updated go.sum accordingly

Thanks a bunch for maintaining Atlas!

Ps; Once merged, could a new community binary release be published - thanks

@a8m
a8m requested review from giautm and masseelch March 20, 2026 13:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant