chore(deps): bump github.com/controlplaneio/sandbox-probe/v6 from 6.15.1 to 6.19.1 - #31
Conversation
Bumps [github.com/controlplaneio/sandbox-probe/v6](https://github.com/controlplaneio/sandbox-probe) from 6.15.1 to 6.19.1. - [Release notes](https://github.com/controlplaneio/sandbox-probe/releases) - [Commits](controlplaneio/sandbox-probe@v6.15.1...v6.19.1) --- updated-dependencies: - dependency-name: github.com/controlplaneio/sandbox-probe/v6 dependency-version: 6.19.1 dependency-type: indirect update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Kusari Analysis Results:
Both analyses support proceeding. Dependency analysis: this is a routine bump of sandbox-probe (v6.15.1 to v6.19.1) that actually remediates two SSH DoS vulnerabilities (GO-2026-6354/CVE-2026-78662 and GO-2026-6355/CVE-2026-56855) via the golang.org/x/crypto 0.55.0 to 0.56.0 update. One advisory, GO-2026-5932 (unmaintained openpgp package), is carried over unchanged with no fix available (fix_status: NO_FIX, is_fixable: false) - this PR neither introduces nor worsens it, and no upstream fix exists, so it is not actionable at this time. If the codebase uses golang.org/x/crypto/openpgp, consider migrating to the maintained fork github.com/ProtonMail/go-crypto/openpgp as a longer-term improvement, though this is not required for this PR. No deprecated/EOL/copyleft license issues, typosquatting, or dependency confusion were found. Code analysis found no code issues, exposed secrets, or workflow issues. Overall, the security posture improves with this PR, and no blocking issues were identified. Note View full detailed analysis result for more information on the output and the checks that were run.
Found this helpful? Give it a 👍 or 👎 reaction! |
Bumps github.com/controlplaneio/sandbox-probe/v6 from 6.15.1 to 6.19.1.
Release notes
Sourced from github.com/controlplaneio/sandbox-probe/v6's releases.
Commits
72a42b0Merge pull request #65 from controlplaneio/dependabot/github_actions/gha-abc5...3cb8cf2Merge pull request #66 from controlplaneio/dependabot/go_modules/gomod-c522b8...2eb3b94chore(deps): Bump the gomod group across 1 directory with 6 updatesfa59f35chore(deps): Bump the gha group with 4 updatesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)