This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 2d
Containers & Orchestration
✓ No known CVEs patched
This release patches 2 known CVEs
Affected surfaces
auth
rbac
deps
breaking_upgrade
Summary
AI summarygrpc-go updated to v1.82.1 and quinn-proto to v0.11.16, patching xDS RBAC, HTTP/2 vulnerabilities, and remote memory exhaustion.
Full changelog
v0.7.1 — security patch release
Security
- grpc-go updated to v1.82.1. Patches xDS RBAC and HTTP/2 vulnerabilities. Applied across all 6 Go modules.
- quinn-proto updated to v0.11.16. Patches remote memory exhaustion from unbounded out-of-order stream reassembly.
Security Fixes
- grpc-go v1.82.1 — patches xDS RBAC and HTTP/2 vulnerabilities
- quinn-proto v0.11.16 — patches remote memory exhaustion from unbounded out-of-order stream reassembly
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Pullrun
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]