This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalUpgrade vulnerable Go dependencies in the runtime to mitigate identified security risks.
Why it matters: Severity rated 80; upgrading addresses critical security vulnerabilities affecting all deployments using these dependencies.
Summary
AI summarySecurity fixes updating vulnerable Go dependencies.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Upgrade vulnerable Go dependencies to mitigate security risks Upgrade vulnerable Go dependencies to mitigate security risks Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Add CodeQL Weekly workflow for security scanning Add CodeQL Weekly workflow for security scanning Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Medium |
Bump golang.org/x/crypto from 0.51.0 to 0.52.0 Bump golang.org/x/crypto from 0.51.0 to 0.52.0 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Full changelog
Changelog
- 0c5b0d140b101fc1b5f4bac9cd9cb39479a35787 Add CodeQL Weekly workflow for security scan
- 59c23f7466db92c4f1b84dde48e8b7e586c4c8e4 Merge pull request #66 from mochow13/dependabot/go_modules/golang.org/x/crypto-0.52.0
- e7d66b977f8dff161fdd67170cf7696bb4487851 Merge pull request #67 from mochow13/fix/security-dependencies
- c4a1302fb6f815aa6100f02f2c5b722ee915a9dc Merge pull request #72 from mochow13/fix/dependabot-vulnerabilities
- 45a9e5c9b53a50222b0d761d5f000bdbe595f133 chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0
- 3e6a4a4b80e5609231e66eca0f034d05c75389a9 chore(release): bump version to 0.31.2
- c6a976caf4ac2131a90f5c2ae830d72edb8f36cc chore(release): streamline publishing instructions
- dfbc9b371c54383e89432fe1a99508cc032dc428 ci(security): scan reachable Go vulnerabilities
- 620a54fa7cadff86b00de05a773573cc949b979b fix(security): update vulnerable Go dependencies
- 7bbde40039e39596b4bb6b5c91efdc987420f846 fix(security): upgrade vulnerable Go dependencies
Security Fixes
- fix(security): update vulnerable Go dependencies
- fix(security): upgrade vulnerable Go dependencies
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Keen Code
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]