Skip to content

build(deps): update gRPC to 1.83.1 - #100

Open
stephenlclarke wants to merge 1 commit into
apple:mainfrom
stephenlclarke:upstream/grpc-http2-fragmentation
Open

stephenlclarke wants to merge 1 commit into
apple:mainfrom
stephenlclarke:upstream/grpc-http2-fragmentation

Conversation

@stephenlclarke

Copy link
Copy Markdown

Summary

Update google.golang.org/grpc from 1.80.0 to 1.83.1 and regenerate the checked-in module metadata and vendor tree with the repository's Go 1.25.5 toolchain.

This resolves GHSA-vp52-pcj8-j9qc / CVE-2026-84304, a heap-exhaustion issue caused by HTTP/2 DATA-frame fragmentation. Version 1.83.1 is the first patched release.

The Go module solver also raises the companion OpenTelemetry, x/*, and genproto versions required by gRPC 1.83.1. No application source or public API changes are included.

Testing

  • GOTOOLCHAIN=go1.25.5 go mod verify
  • GOTOOLCHAIN=go1.25.5 go test -mod=vendor ./pkg/api ./pkg/build/... ./pkg/fssync ./pkg/server ./pkg/stream
  • Replayed go mod tidy && go mod vendor under Go 1.25.5; git diff --exit-code remained clean.

The focused go vet invocation reports two existing protoimpl.MessageState lock-copy warnings in pkg/fssync/diffcopy_test.go; the same warnings reproduce unchanged at base commit e18d2182fd060dbf1c68113a74e7564d563dde27.

Risk

The change is dependency-only. The vendored delta is larger than the direct version line because gRPC 1.83.1 advances minimum transitive versions; it is generated deterministically by the dependency command already enforced by CI.

@stephenlclarke
stephenlclarke force-pushed the upstream/grpc-http2-fragmentation branch from b8ba887 to 68b576f Compare September 28, 2026 08:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant