Skip to content

Wiz: Upgrade multiple dependencies (resolves 89 findings) - #76

Open
wiz-betterup[bot] wants to merge 1 commit into
mainfrom
wiz-auto-remediation-7041cadc36838d6e
Open

Wiz: Upgrade multiple dependencies (resolves 89 findings)#76
wiz-betterup[bot] wants to merge 1 commit into
mainfrom
wiz-auto-remediation-7041cadc36838d6e

Conversation

@wiz-betterup

@wiz-betterup wiz-betterup Bot commented Jul 26, 2026

Copy link
Copy Markdown

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 89 findings detected in this project

Changes were made to the following file(s):

  • go.mod

Vulnerabilities:

Component Findings Locations
github.com/Azure/go-ntlmssp
0.0.0-20221128193559-754e69321358 → 0.1.1
High CVE-2026-32952 /go.mod
github.com/cloudflare/circl
1.3.3 → 1.6.3
High GHSA-9763-4f94-gfch
Low CVE-2026-1229
Low CVE-2025-8556
/go.mod
github.com/docker/cli
23.0.4+incompatible → 29.2.0
High CVE-2025-15558 /go.mod
github.com/docker/docker
23.0.4+incompatible → 29.3.1
High CVE-2024-29018
High CVE-2024-24557
High CVE-2026-34040
Medium GHSA-jq35-85cj-fj4p
Medium CVE-2025-54410
/go.mod
github.com/go-git/go-billy/v5
5.4.1 → 5.9.0
High CVE-2026-44973
Medium CVE-2026-44740
/go.mod
github.com/go-git/go-git/v5
5.7.0 → 5.19.1
Critical CVE-2025-21613
Critical CVE-2023-49569
High CVE-2023-49568
High CVE-2026-45022
High CVE-2026-41506
High CVE-2025-21614
Medium CVE-2026-25934
Medium CVE-2026-45571
Medium GHSA-w5pp-99ch-qj29
Medium CVE-2026-34165
Low CVE-2026-45570
Low CVE-2026-33762
/go.mod
github.com/go-jose/go-jose/v3
3.0.0 → 3.0.5
High CVE-2026-34986
Medium GHSA-2c7c-3mj9-8fqh
Medium CVE-2024-28180
Medium CVE-2025-27144
/go.mod
github.com/golang-jwt/jwt/v4
4.5.0 → 4.5.2
High CVE-2025-30204
Low CVE-2024-51744
/go.mod
github.com/golang/glog
1.1.1 → 1.2.4
High CVE-2024-45339 /go.mod
github.com/hashicorp/go-retryablehttp
0.7.2 → 0.7.7
Medium CVE-2024-6104 /go.mod
github.com/in-toto/in-toto-golang
0.6.0 → 0.11.0
Medium GHSA-pmwq-pjrm-6p5r /go.mod
github.com/notaryproject/notation-go
1.0.0-rc.3 → 1.0.0-rc.6
High CVE-2023-33959 /go.mod
github.com/open-policy-agent/opa
0.51.0 → 1.4.0
High CVE-2025-46569
High CVE-2024-8260
/go.mod
github.com/sigstore/cosign
1.13.1 → 3.0.5
Medium CVE-2026-39395
Medium CVE-2023-46737
Low CVE-2026-24122
/go.mod
github.com/sigstore/fulcio
1.1.0 → 1.8.6
High CVE-2025-66506
High CVE-2026-49478
Medium CVE-2026-22772
/go.mod
github.com/sigstore/rekor
1.0.1 → 1.5.2
High CVE-2026-48702
High CVE-2023-30551
Medium CVE-2023-33199
Medium CVE-2026-23831
Medium CVE-2026-24117
/go.mod
github.com/sigstore/sigstore
1.5.2 → 1.10.4
Medium CVE-2026-24137 /go.mod
github.com/sirupsen/logrus
1.9.0 → 1.9.1
High CVE-2025-65637 /go.mod
go.mongodb.org/mongo-driver
1.11.3 → 1.17.7
Medium CVE-2026-2303 /go.mod
go.opentelemetry.io/contrib/instrumentat-
ion/net/http/otelhttp

0.41.1 → 0.44.0
High CVE-2023-45142 /go.mod
go.opentelemetry.io/otel/sdk
1.15.1 → 1.43.0
High CVE-2026-39883 /go.mod
golang.org/x/crypto
0.9.0 → 0.52.0
Critical CVE-2026-39831
Critical CVE-2024-45337
Critical CVE-2026-39834
Critical CVE-2026-39832
Critical CVE-2026-39830
Critical CVE-2026-39833
Critical CVE-2026-42508
Critical CVE-2026-46595
High CVE-2025-47913
High CVE-2026-46597
High CVE-2025-22869
High CVE-2026-39829
Medium CVE-2026-39828
Medium CVE-2026-39835
Medium CVE-2026-39827
Medium CVE-2023-48795
Medium CVE-2025-47914
Medium CVE-2025-58181
Medium CVE-2026-46598
/go.mod
golang.org/x/net
0.10.0 → 0.55.0
Critical CVE-2026-39821
High CVE-2023-45288
High CVE-2023-39325
High CVE-2023-44487
Medium CVE-2025-22872
Medium CVE-2025-22870
Medium CVE-2023-3978
Medium CVE-2026-25680
/go.mod
golang.org/x/oauth2
0.7.0 → 0.27.0
High CVE-2025-22868 /go.mod
google.golang.org/grpc
1.55.0 → 1.82.1
Critical CVE-2026-33186
High GHSA-hrxh-6v49-42gf
High CVE-2023-44487
/go.mod
google.golang.org/protobuf
1.30.0 → 1.33.0
High CVE-2024-24786 /go.mod
gopkg.in/go-jose/go-jose.v2
2.6.1 → 2.6.3
Medium CVE-2024-28180 /go.mod
oras.land/oras-go/v2
2.1.0 → 2.6.1
High CVE-2026-50151
Medium GHSA-vh4v-2xq2-g5cg
Medium CVE-2026-50162
Low CVE-2026-48978
/go.mod

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-betterup

wiz-betterup Bot commented Jul 26, 2026

Copy link
Copy Markdown
Author

⚠️ Lock file update issue

Please update the lock file manually before merging this PR.

go.sum
Internal Error

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants