Skip to content

deps: bump google.golang.org/grpc v1.82.2 for CVE-2026-84445 - #81

Merged
baijum merged 1 commit into
release-3.21from
bump-grpc-1.82.2-release-3.21
Sep 30, 2026
Merged

baijum merged 1 commit into
release-3.21from
bump-grpc-1.82.2-release-3.21

Conversation

@baijum

@baijum baijum commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Bumps google.golang.org/grpc from v1.82.1 to v1.82.2 to fix CVE-2026-84445
  • gRPC-Go: Denial of Service via malformed RPC requests (CVSS 7.5, Important)
  • Servers using xds.NewGRPCServer() could panic on an RPC missing the :authority and Host headers, terminating the entire server process
  • Fixed in gRPC-Go 1.82.2 and 1.83.2

Jira: HELM-857 / OCPTOOLS-2684

Changes

Only the gRPC dependency bump — no changes to go directive, Kubernetes API versions, or any other dependencies.

🤖 Generated with Claude Code

Fix gRPC-Go Denial of Service via malformed RPC requests (CVSS 7.5).
Servers using xds.NewGRPCServer() could panic on an RPC missing
the :authority and Host headers, terminating the server process.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@openshift-ci
openshift-ci Bot requested a review from martinszuc September 30, 2026 05:14
@openshift-ci

openshift-ci Bot commented Sep 30, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: baijum

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@baijum
baijum merged commit b746c33 into release-3.21 Sep 30, 2026
24 checks passed
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:15 AM UTC · Completed 5:25 AM UTC

Commit: 3386c07 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.71

@fullsend-ai-review

Copy link
Copy Markdown

Review skipped — this PR is already merged.

The /fs-review command only reviews open PRs/MRs.

Posted by fullsend pre-review check

@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 5:15 AM UTC · Completed 5:26 AM UTC

Commit: 3386c07 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.62

@fullsend-ai-review

Copy link
Copy Markdown

Review skipped — this PR is already merged.

The /fs-review command only reviews open PRs/MRs.

Posted by fullsend post-review check

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #81 — deps: bump grpc v1.82.2 for CVE-2026-84445

Timeline

  1. 05:13:59Z — baijum opens PR deps: bump google.golang.org/grpc v1.82.2 for CVE-2026-84445 #81 targeting release-3.21 (single-commit gRPC dependency bump, co-authored with Claude Opus 4.6)
  2. 05:14:03Z — fullsend dispatches review (run 36672469196)
  3. 05:14:15Z — openshift-ci auto-approves (author self-approval via OWNERS)
  4. 05:14:44Z — PR merged (45 seconds after creation)
  5. 05:15:11Z — Review agent posts "Started" comment
  6. 05:15:14Z — Review agent detects PR is already merged, posts "Review skipped" (3 seconds after starting)
  7. 05:15:56Z — Retro agent dispatched (run 36672524265)

Observations

This is a straightforward vendored dependency bump fixing CVE-2026-84445 (gRPC-Go DoS, CVSS 7.5). PR #81 is the same fix as PR #78 but targeting release-3.21 instead of release-3.22. Both PRs exhibited the same merge-before-review pattern.

No novel proposals are warranted. All improvement opportunities identified are already tracked in existing open issues:

What went well

Agents repo

Discovered from run 36387333268 logs: fullsend-ai/agents@v0.43.0 (commit 7ab05564b3c9).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant