Skip to content

Wiz: Upgrade multiple dependencies (resolves 87 findings) - #93

Open
wiz-betterup[bot] wants to merge 1 commit into
masterfrom
wiz-auto-remediation-b1cd8ce5772fc894
Open

Wiz: Upgrade multiple dependencies (resolves 87 findings)#93
wiz-betterup[bot] wants to merge 1 commit into
masterfrom
wiz-auto-remediation-b1cd8ce5772fc894

Conversation

@wiz-betterup

@wiz-betterup wiz-betterup Bot commented Aug 20, 2026

Copy link
Copy Markdown

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 87 findings detected in this project

Changes were made to the following file(s):

  • docs/requirements.txt
  • go.mod
  • ui-test/package.json

Vulnerabilities:

Component Findings Locations
chromedriver
94.0.0 → 119.0.1
High CVE-2023-26156 /ui-test/package.json
github.com/Azure/azure-sdk-for-go/sdk/az-
identity

1.1.0 → 1.6.0-beta.4.0.20240610221955-50774cd97099
Medium CVE-2024-35255 /go.mod
github.com/argoproj/gitops-engine
0.7.1-0.20230809134534-ed7c77a9290b → 0.7.1-0.20250129155113-4c6e03c463141
Medium CVE-2025-23216 /go.mod
github.com/cloudflare/circl
1.3.3 → 1.6.3
High GHSA-9763-4f94-gfch
Low CVE-2026-1229
Low CVE-2025-8556
/go.mod
github.com/go-git/go-billy/v5
5.4.1 → 5.9.0
High CVE-2026-44973
Medium CVE-2026-44740
/go.mod
github.com/go-git/go-git/v5
5.8.1 → 5.19.2
Critical CVE-2023-49569
Critical CVE-2025-21613
High CVE-2026-71556
High CVE-2026-41506
High CVE-2026-45022
High CVE-2023-49568
High CVE-2025-21614
Medium CVE-2026-71557
Medium CVE-2026-25934
Medium GHSA-w5pp-99ch-qj29
Medium CVE-2026-45571
Medium CVE-2026-34165
Low CVE-2026-33762
Low CVE-2026-45570
/go.mod
github.com/go-jose/go-jose/v3
3.0.1 → 3.0.5
High CVE-2026-34986
Medium CVE-2025-27144
Medium CVE-2024-28180
/go.mod
github.com/golang-jwt/jwt/v4
4.5.0 → 4.5.2
High CVE-2025-30204
Low CVE-2024-51744
/go.mod
github.com/golang/glog
1.1.2 → 1.2.4
High CVE-2024-45339 /go.mod
github.com/hashicorp/go-retryablehttp
0.7.4 → 0.7.7
Medium CVE-2024-6104 /go.mod
github.com/moby/spdystream
0.2.0 → 0.5.1
High CVE-2026-35469 /go.mod
github.com/slack-go/slack
0.12.1 → 0.23.1
Medium GHSA-gxhx-2686-5h9g /go.mod
go.mongodb.org/mongo-driver
1.11.3 → 1.17.7
Medium CVE-2026-2303 /go.mod
go.opentelemetry.io/otel/sdk
1.21.0 → 1.43.0
High CVE-2026-24051
High CVE-2026-39883
/go.mod
golang.org/x/crypto
0.16.0 → 0.52.0
Critical CVE-2026-39830
Critical CVE-2026-42508
Critical CVE-2024-45337
Critical CVE-2026-39833
Critical CVE-2026-39831
Critical CVE-2026-39832
Critical CVE-2026-46595
Critical CVE-2026-39834
High CVE-2026-46597
High CVE-2026-39829
High CVE-2025-47913
High CVE-2025-22869
Medium CVE-2026-39827
Medium CVE-2026-39828
Medium CVE-2026-46598
Medium CVE-2026-39835
Medium CVE-2023-48795
Medium CVE-2025-47914
Medium CVE-2025-58181
/go.mod
golang.org/x/net
0.19.0 → 0.55.0
Critical CVE-2026-39821
High CVE-2023-45288
Medium CVE-2025-22872
Medium CVE-2025-22870
Medium CVE-2026-25680
/go.mod
golang.org/x/oauth2
0.13.0 → 0.27.0
High CVE-2025-22868 /go.mod
google.golang.org/grpc
1.60.0 → 1.82.1
Critical CVE-2026-33186
High GHSA-hrxh-6v49-42gf
/go.mod
google.golang.org/protobuf
1.31.0 → 1.33.0
High CVE-2024-24786 /go.mod
jinja2
3.0.3 → 3.1.6
Medium CVE-2024-56326
Medium CVE-2024-34064
Medium CVE-2025-27516
Medium CVE-2024-56201
Medium CVE-2024-22195
/docs/requirements.txt
k8s.io/kubernetes
1.24.15 → 1.32.10
High CVE-2023-3676
High CVE-2023-3955
High CVE-2024-10220
High CVE-2024-0793
High CVE-2023-5528
Medium CVE-2024-5321
Medium CVE-2025-13281
Medium CVE-2025-0426
Medium CVE-2025-5187
Low CVE-2021-25743
Low CVE-2024-3177
/go.mod
markdown
3.3.7 → 3.8.1
High CVE-2025-69534 /docs/requirements.txt
mkdocs-material
7.1.8 → 9.5.5
High CVE-2021-40978
High CVE-2023-50447
/docs/requirements.txt
oras.land/oras-go/v2
2.2.1 → 2.6.2
High CVE-2026-50163
High CVE-2026-50151
Medium GHSA-vh4v-2xq2-g5cg
Medium CVE-2026-50162
Low CVE-2026-48978
/go.mod
pygments
2.15.0 → 2.20.0
Low CVE-2026-4539 /docs/requirements.txt

To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio.

@wiz-betterup

wiz-betterup Bot commented Aug 20, 2026

Copy link
Copy Markdown
Author

⚠️ Lock file update issue

Please update the lock file manually before merging this PR.

ui-test/yarn.lock
Unsupported package manager version

go.sum
Internal Error

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants