Skip to content

chore: bump up dependencies to address CVEs#647

Open
shvbsle wants to merge 1 commit intoNVIDIA:mainfrom
shvbsle:main
Open

chore: bump up dependencies to address CVEs#647
shvbsle wants to merge 1 commit intoNVIDIA:mainfrom
shvbsle:main

Conversation

@shvbsle
Copy link
Copy Markdown

@shvbsle shvbsle commented Mar 27, 2026

Bumps Go toolchain and gRPC dependency to fix two vulnerability findings in dcgm-exporter-4.5.2-4.8.1:

Dependency Old Version New Version CVE Severity
google.golang.org/grpc v1.71.1 v1.79.3 CVE-2026-33186 CRITICAL
go/stdlib (Go toolchain) go1.24.13 go1.26.1 CVE-2026-25679 HIGH

Testing

Ran tests on a g5 gpu and ensured all tests pass:

go test ./... 2>&1

Signed-off-by: Shiv shvbsle@amazon.com

@shvbsle shvbsle marked this pull request as ready for review March 27, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant