Skip to content

Conversation

@wiz-betterup
Copy link

@wiz-betterup wiz-betterup bot commented Jan 4, 2026

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 41 findings detected in this project

Changes were made to the following file(s):

  • /go.mod

Vulnerabilities:

Component Findings Locations
github.com/cloudflare/circl
1.3.3 → 1.6.1
High GHSA-9763-4f94-gfch
Low CVE-2025-8556
/go.mod
github.com/docker/docker
23.0.4+incompatible → 28.0.0
High CVE-2024-29018
High CVE-2024-24557
Medium GHSA-jq35-85cj-fj4p
Medium CVE-2025-54410
/go.mod
github.com/go-git/go-git/v5
5.7.0 → 5.13.0
Critical CVE-2025-21613
Critical CVE-2023-49569
High CVE-2023-49568
High CVE-2025-21614
/go.mod
github.com/go-jose/go-jose/v3
3.0.0 → 3.0.4
Medium GHSA-2c7c-3mj9-8fqh
Medium CVE-2024-28180
Medium CVE-2025-27144
/go.mod
github.com/golang-jwt/jwt/v4
4.5.0 → 4.5.2
High CVE-2025-30204
Low CVE-2024-51744
/go.mod
github.com/golang/glog
1.1.1 → 1.2.4
High CVE-2024-45339 /go.mod
github.com/hashicorp/go-retryablehttp
0.7.2 → 0.7.7
Medium CVE-2024-6104 /go.mod
github.com/notaryproject/notation-go
1.0.0-rc.3 → 1.0.0-rc.6
High CVE-2023-33959 /go.mod
github.com/open-policy-agent/opa
0.51.0 → 1.4.0
High CVE-2025-46569
High CVE-2024-8260
/go.mod
github.com/sigstore/cosign
1.13.1 → 1.13.2
Medium CVE-2023-46737 /go.mod
github.com/sigstore/fulcio
1.1.0 → 1.8.3
High CVE-2025-66506 /go.mod
github.com/sigstore/rekor
1.0.1 → 1.2.0
High CVE-2023-30551
Medium CVE-2023-33199
/go.mod
github.com/sirupsen/logrus
1.9.0 → 1.9.1
High CVE-2025-65637 /go.mod
go.opentelemetry.io/contrib/instrumentat-
ion/net/http/otelhttp

0.41.1 → 0.44.0
High CVE-2023-45142 /go.mod
golang.org/x/crypto
0.9.0 → 0.45.0
Critical CVE-2024-45337
High CVE-2025-22869
Medium CVE-2023-48795
Medium CVE-2025-47914
Medium CVE-2025-58181
/go.mod
golang.org/x/net
0.10.0 → 0.38.0
High CVE-2023-45288
High CVE-2023-39325
High CVE-2023-44487
Medium CVE-2025-22872
Medium CVE-2025-22870
Medium CVE-2023-3978
/go.mod
golang.org/x/oauth2
0.7.0 → 0.27.0
High CVE-2025-22868 /go.mod
google.golang.org/grpc
1.55.0 → 1.56.3
High GHSA-m425-mq94-257g /go.mod
google.golang.org/protobuf
1.30.0 → 1.33.0
High CVE-2024-24786 /go.mod
gopkg.in/go-jose/go-jose.v2
2.6.1 → 2.6.3
Medium CVE-2024-28180 /go.mod

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-betterup wiz-betterup bot closed this Jan 5, 2026
@wiz-betterup wiz-betterup bot deleted the wiz-auto-remediation-9ec3f114f330666f branch January 5, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant