[TT-17190] Merging to release-5.13: [TT-17190] Upgrade apache/thrift to 0.23.0 (#8194)#8196
Conversation
<!-- Provide a general summary of your changes in the Title above --> ## Description Fix CVE-160: CVE-2026-41602 -> Requires Apache Thrift 0.23.0 ## Related Issue <!-- This project only accepts pull requests related to open issues. --> <!-- If suggesting a new feature or change, please discuss it in an issue first. --> <!-- If fixing a bug, there should be an issue describing it with steps to reproduce. --> <!-- OSS: Please link to the issue here. Tyk: please create/link the JIRA ticket. --> ## Motivation and Context <!-- Why is this change required? What problem does it solve? --> ## How This Has Been Tested <!-- Please describe in detail how you tested your changes --> <!-- Include details of your testing environment, and the tests --> <!-- you ran to see how your change affects other areas of the code, etc. --> <!-- This information is helpful for reviewers and QA. --> ## Screenshots (if appropriate) ## Types of changes <!-- What types of changes does your code introduce? Put an `x` in all the boxes that apply: --> - [ ] Bug fix (non-breaking change which fixes an issue) - [ ] New feature (non-breaking change which adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [ ] Refactoring or add test (improvements in base code or adds test coverage to functionality) ## Checklist <!-- Go over all the following points, and put an `x` in all the boxes that apply --> <!-- If there are no documentation updates required, mark the item as checked. --> <!-- Raise up any additional concerns not covered by the checklist. --> - [ ] I ensured that the documentation is up to date - [ ] I explained why this PR updates go.mod in detail with reasoning why it's required - [ ] I would like a code coverage CI quality gate exception and have explained why <!---TykTechnologies/jira-linter starts here--> ### Ticket Details <details> <summary> <a href="https://tyktech.atlassian.net/browse/TT-17190" title="TT-17190" target="_blank">TT-17190</a> </summary> | | | |---------|----| | Status | In Dev | | Summary | Additional CVE fixes (Gateway & Dashboard) | Generated at: 2026-05-11 15:48:19 </details> <!---TykTechnologies/jira-linter ends here--> (cherry picked from commit 2648662)
|
This pull request upgrades Files Changed AnalysisThe change is limited to updating the version of the Architecture & Impact Assessment
graph TD
A[Tyk Gateway] -->|uses| B(Distributed Tracing Module)
B -->|integrates with| C(uber/jaeger-client-go)
C -->|depends on for transport| D(apache/thrift)
D -- PR updates --> E(apache/thrift v0.23.0)
Scope Discovery & Context ExpansionThe direct scope is a minimal dependency version change. However, the functional impact is concentrated on the Jaeger tracing integration. Any breaking changes or subtle incompatibilities in the new version of Metadata
Powered by Visor from Probelabs Last updated: 2026-05-11T17:28:14.110Z | Triggered by: pr_opened | Commit: a01248b 💡 TIP: You can chat with Visor using |
✅ Security Check PassedNo security issues found – changes LGTM. ✅ Security Check PassedNo security issues found – changes LGTM. \n\n \n\n✅ Performance Check PassedNo performance issues found – changes LGTM. ✅ Quality Check PassedNo quality issues found – changes LGTM. Powered by Visor from Probelabs Last updated: 2026-05-11T17:28:07.134Z | Triggered by: pr_opened | Commit: a01248b 💡 TIP: You can chat with Visor using |
|



TT-17190 Upgrade apache/thrift to 0.23.0 (#8194)
Description
Fix CVE-160: CVE-2026-41602 -> Requires Apache Thrift 0.23.0
Related Issue
Motivation and Context
How This Has Been Tested
Screenshots (if appropriate)
Types of changes
functionality to change)
coverage to functionality)
Checklist
why it's required
explained why
Ticket Details
TT-17190
Generated at: 2026-05-11 18:37:00