Skip to content

[SECURITY] Align dependency updates to compatibility baseline - #162

Merged
hferentschik merged 2 commits into
mainfrom
dd/chore/security-dependency-updates-20260922
Sep 22, 2026
Merged

hferentschik merged 2 commits into
mainfrom
dd/chore/security-dependency-updates-20260922

Conversation

@marchmallow

@marchmallow marchmallow commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Motivation & Context

  • Goal: Apply a bounded subset of dependency security updates while keeping shared dependency versions at or below the established downstream compatibility baseline; observable codec and server behavior does not change.
  • Why now: Multiple automated security-update PRs contain overlapping dependency changes, including versions that are ahead of the downstream consumer's selected dependency graph. This branch consolidates the compatible subset without claiming to resolve every reported advisory.
  • Sequencing: Merge after [BUGFIX] Drain deduplicated upload request bodies #161. This branch starts at main and intentionally does not include the body-drain fix. Rebase after [BUGFIX] Drain deduplicated upload request bodies #161 lands so the handler and third-party-license metadata changes remain independently reviewable.
  • Included dependency resolutions:
    • internal: golang.org/x/crypto v0.9.0 → v0.55.0, golang.org/x/net v0.10.0 → v0.58.0, golang.org/x/mod v0.8.0 → v0.40.0, and golang.org/x/sys v0.8.0 → v0.47.0.
    • codec: google.golang.org/grpc v1.79.1 → v1.83.0, golang.org/x/net v0.50.0 → v0.58.0, golang.org/x/sys v0.41.0 → v0.47.0, and golang.org/x/text v0.34.0 → v0.41.0.
    • server: github.com/jackc/pgx/v5 v5.7.4 → v5.10.0, github.com/apache/thrift v0.21.0 → v0.24.0, go.opentelemetry.io/otel/sdk v1.40.0 → the v1.44.x compatibility baseline, github.com/go-jose/go-jose/v4 v4.1.3 → v4.1.4, AWS EventStream v1.7.5 → v1.7.16, plus the shared x/crypto, x/net, and gRPC resolutions above.
    • Test dependencies: keep github.com/stretchr/testify at v1.11.1 rather than advancing beyond the compatibility baseline.
    • CI/release workflows: pin actions/checkout, actions/setup-go, and golangci/golangci-lint-action to reviewed full SHAs.
  • Security scope: This is intentionally a partial remediation. It does not assert that every finding reported by the automated update PRs is resolved. Newer versions that exceed the current compatibility baseline remain deferred for separate compatibility review.
  • Follow-up: Revisit the deferred findings after the downstream baseline and supported Go toolchain advance. The broad go.temporal.io/server update in fix(deps): vuln minor upgrades — 15 packages (minor: 11 · patch: 4) [server/go.mod] #160 also remains deferred because its selected server and API versions do not compile together.

Interface Changes

  • No public APIs, configuration, release behavior, or payload handling changes.
  • GitHub Actions execute the same action releases through immutable commit SHAs rather than mutable tags.

Validation

  • GOTOOLCHAIN=go1.25.6 make build — passed.
  • GOTOOLCHAIN=go1.25.6 make test_codec — passed.
  • Non-container server packages — passed.
  • GOTOOLCHAIN=go1.25.6 make lint — passed with zero issues.
  • GOTOOLCHAIN=go1.25.6 make check_copyright and GOTOOLCHAIN=go1.25.6 make check_license — passed.
  • The earlier hosted CI run passed the complete suite, including container-backed Azure and S3 tests. A new CI run is required for the compatibility-aligned commit.

Risks

  • This bounded update intentionally leaves some automated security findings unresolved. They remain visible in the existing update PRs and require follow-up rather than being treated as fixed here.
  • Dependency versions are aligned by public module version. A downstream consumer may apply its own module replacements, which still require integration validation when consuming the next release.
  • Provider-specific behavior relies on hosted container-backed tests in addition to the local non-container suite.

@marchmallow marchmallow changed the title [KTLO] Consolidate security dependency updates [SECURITY] Consolidate dependency updates Sep 22, 2026
@marchmallow marchmallow changed the title [SECURITY] Consolidate dependency updates [SECURITY] Align dependency updates to compatibility baseline Sep 22, 2026
@marchmallow
marchmallow marked this pull request as ready for review September 22, 2026 11:00
@hferentschik
hferentschik merged commit 668cb4c into main Sep 22, 2026
3 checks passed
@hferentschik
hferentschik deleted the dd/chore/security-dependency-updates-20260922 branch September 22, 2026 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants