Skip to content

Security Patching#2074

Open
revitteth wants to merge 1 commit intozkevmfrom
feat/security
Open

Security Patching#2074
revitteth wants to merge 1 commit intozkevmfrom
feat/security

Conversation

@revitteth
Copy link
Copy Markdown
Collaborator

Go dependency updates:

  • golang.org/x/crypto v0.35.0/v0.37.0 → v0.45.0 (CVE-2025-47914, CVE-2025-58181)
  • golang.org/x/net v0.36.0/v0.39.0 → v0.41.0/v0.47.0 (CVE-2025-22872 XSS)
  • google.golang.org/grpc v1.63.2 → v1.68.0 (GO-2024-2978 metadata leak)
  • prometheus/client_golang v1.19.0 → v1.20.5

Container security fixes:

  • Fix malformed entrypoint in Dockerfile.release (/usr/local/bincdk-/erigon)
  • Pin Alpine base images from :latest to :3.20
  • Add non-root user to rpc_cache Dockerfile

@revitteth revitteth force-pushed the feat/security branch 2 times, most recently from 5d30f98 to f46af54 Compare December 16, 2025 14:33
@revitteth revitteth enabled auto-merge December 16, 2025 15:29
@revitteth revitteth force-pushed the feat/security branch 3 times, most recently from 56add99 to c5af146 Compare December 16, 2025 16:14
  Go dependency updates:
  - golang.org/x/crypto v0.35.0/v0.37.0 → v0.45.0 (CVE-2025-47914, CVE-2025-58181)
  - golang.org/x/net v0.36.0/v0.39.0 → v0.41.0/v0.47.0 (CVE-2025-22872 XSS)
  - google.golang.org/grpc v1.63.2 → v1.68.0 (GO-2024-2978 metadata leak)
  - prometheus/client_golang v1.19.0 → v1.20.5

  Container security fixes:
  - Fix malformed entrypoint in Dockerfile.release (/usr/local/bincdk-/erigon)
  - Pin Alpine base images from :latest to :3.20
  - Add non-root user to rpc_cache Dockerfile
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants