Bump x/oauth2 and x/crypto to resolve CVE-2025-22868 + CVE-2025-22869 in Alloy #2933
Open
1 of 3 tasks
Labels
enhancement
New feature or request
Request
Let's keep the Grafana Alloy Go-modules and -packages up-to-date. The current latest Docker-Image tag
v1.7.1
using an older ofgolang.org/x/crypto
andgolang.org/x/oauth2
.Hence, picking up fixes for CVE-2025-22868 and CVE-2025-22869:
Use case
golang.org/x/crypto
tov0.35.0
or above.golang.org/x/oauth2
tov0.27.0
or above.Those dependency updates just aim to silence some (SBOM-based) scanners.
The text was updated successfully, but these errors were encountered: