chore(deps): bump go-messaging-amqp to v0.0.5 and amqp091-go to v1.15.0
authz_client / test (push) Skipped
authz_client / vulnerabilities (push) Skipped
pre-commit / pre-commit (push) Skipped
authz_client / vulnerabilities (pull_request) Successful in 48s
authz_client / test (pull_request) Successful in 1m0s
pre-commit / pre-commit (pull_request) Successful in 2m15s

govulncheck reports GO-2026-6372 against amqp091-go v1.12.0, pulled in
indirectly: a broker-controlled oversized payload can exhaust memory. Fixed in
v1.13.0; take v1.15.0. The advisory fails CI on main too, and this is the first
build since it was published.

go-messaging-amqp goes to v0.0.5 at the same time, which is what every migrated
service already runs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XMvdB7bcwn1CrQKM4dCshM
This commit is contained in:
argoyleandClaude Opus 5 committed 2026-09-16 07:16:09 +02:00
1 parent 92f78d369a
commit 55e16832c1
2 files changed
+6 -6

No files matched your search

+2 -2
View File
@@ -3,7 +3,7 @@ module gitea.unbound.se/shiny/authz_client
go 1.26.2
require (
codeberg.org/messaging/go-messaging-amqp v0.0.4
codeberg.org/messaging/go-messaging-amqp v0.0.5
codeberg.org/messaging/messaging v0.0.5
github.com/stretchr/testify v1.12.1
)
@@ -19,7 +19,7 @@ require (
github.com/prometheus/client_model v0.6.2 // indirect
github.com/prometheus/common v0.66.1 // indirect
github.com/prometheus/procfs v0.16.1 // indirect
github.com/rabbitmq/amqp091-go v1.12.0 // indirect
github.com/rabbitmq/amqp091-go v1.15.0 // indirect
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
go.opentelemetry.io/otel v1.44.0 // indirect
go.opentelemetry.io/otel/metric v1.44.0 // indirect