Skip to content

Wiz: Upgrade multiple dependencies (resolves 38 findings)#56

Open
wiz-betterup[bot] wants to merge 1 commit into
mainfrom
wiz-auto-remediation-a5a291a21c916610
Open

Wiz: Upgrade multiple dependencies (resolves 38 findings)#56
wiz-betterup[bot] wants to merge 1 commit into
mainfrom
wiz-auto-remediation-a5a291a21c916610

Conversation

@wiz-betterup

@wiz-betterup wiz-betterup Bot commented Jun 18, 2026

Copy link
Copy Markdown

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 38 findings detected in this project

Changes were made to the following file(s):

  • go.mod

Vulnerabilities:

Component Findings Locations
github.com/containerd/containerd
1.7.0 → 1.7.29
High CVE-2024-25621
High CVE-2024-40635
Medium GHSA-7ww5-4wqc-m92c
Medium CVE-2025-64329
/go.mod
github.com/distribution/distribution/v3
3.0.0-20221208165359-362910506bc2 → 3.1.1
High CVE-2026-35172
High CVE-2026-33540
Medium CVE-2026-41888
/go.mod
github.com/docker/cli
20.10.21+incompatible → 29.2.0
High CVE-2025-15558 /go.mod
github.com/docker/docker
20.10.24+incompatible → 29.3.1
High CVE-2024-24557
High CVE-2024-29018
High CVE-2026-34040
Medium CVE-2025-54410
Medium GHSA-jq35-85cj-fj4p
/go.mod
github.com/moby/spdystream
0.2.0 → 0.5.1
High CVE-2026-35469 /go.mod
golang.org/x/crypto
0.5.0 → 0.52.0
Critical CVE-2024-45337
Critical CVE-2026-39833
Critical CVE-2026-46595
Critical CVE-2026-39832
Critical CVE-2026-39831
Critical CVE-2026-39830
Critical CVE-2026-42508
Critical CVE-2026-39834
High CVE-2025-47913
High CVE-2025-22869
Medium CVE-2025-58181
Medium CVE-2023-48795
Medium CVE-2025-47914
/go.mod
golang.org/x/net
0.8.0 → 0.55.0
Critical CVE-2026-39821
High CVE-2023-44487
High CVE-2023-45288
High CVE-2023-39325
Medium CVE-2025-22870
Medium CVE-2023-3978
Medium CVE-2025-22872
/go.mod
golang.org/x/oauth2
0.4.0 → 0.27.0
High CVE-2025-22868 /go.mod
google.golang.org/grpc
1.53.0 → 1.79.3
Critical CVE-2026-33186
High CVE-2023-44487
/go.mod
google.golang.org/protobuf
1.28.1 → 1.33.0
High CVE-2024-24786 /go.mod

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants