Merging to release-5.13.1: [TT-17446] Tyk Gateway 5.13.1/5.14.0 CVEs (#8315)#8340
Conversation
<!-- Provide a general summary of your changes in the Title above --> ## Description - upgrade github.com/jackc/pgx/v5 to v5.9.2 - upgrade golang.org/x/crypto to v0.52.0 - upgrade golang.org/x/net to v0.55.0 - upgrade golang.org/x/image to v0.41.0 - upgrade golang.org/x/sys to v0.46.0 (minimum required by downgraded golang.org/x/crypto v0.52.0 and downgraded golang.org/x/net v0.55.0) ## Related Issue <!-- This project only accepts pull requests related to open issues. --> <!-- If suggesting a new feature or change, please discuss it in an issue first. --> <!-- If fixing a bug, there should be an issue describing it with steps to reproduce. --> <!-- OSS: Please link to the issue here. Tyk: please create/link the JIRA ticket. --> ## Motivation and Context <!-- Why is this change required? What problem does it solve? --> ## How This Has Been Tested <!-- Please describe in detail how you tested your changes --> <!-- Include details of your testing environment, and the tests --> <!-- you ran to see how your change affects other areas of the code, etc. --> <!-- This information is helpful for reviewers and QA. --> ## Screenshots (if appropriate) ## Types of changes <!-- What types of changes does your code introduce? Put an `x` in all the boxes that apply: --> - [ ] Bug fix (non-breaking change which fixes an issue) - [ ] New feature (non-breaking change which adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [ ] Refactoring or add test (improvements in base code or adds test coverage to functionality) ## Checklist <!-- Go over all the following points, and put an `x` in all the boxes that apply --> <!-- If there are no documentation updates required, mark the item as checked. --> <!-- Raise up any additional concerns not covered by the checklist. --> - [ ] I ensured that the documentation is up to date - [ ] I explained why this PR updates go.mod in detail with reasoning why it's required - [ ] I would like a code coverage CI quality gate exception and have explained why (cherry picked from commit 35b7c3d)
|
SentinelOne CNS Hardcoded Secret Detector SentinelOne CNS is a cloud-agnostic, agentless CSPM & CWPP solution that continuously detects and prevents vulnerabilities that have the highest probability of being exploited in Azure, AWS, Google Cloud, and Kubernetes. |
|
This pull request addresses security vulnerabilities (CVEs) by updating several Go dependencies in the Tyk Gateway. The changes are confined to the Files Changed Analysis
The following dependencies were upgraded:
Architecture & Impact Assessment
Scope Discovery & Context Expansion
Metadata
Powered by Visor from Probelabs Last updated: 2026-06-22T12:13:33.263Z | Triggered by: pr_opened | Commit: 1a15d46 💡 TIP: You can chat with Visor using |
✅ Architecture Check PassedNo architecture issues found – changes LGTM. \n\n✅ Architecture Check PassedNo architecture issues found – changes LGTM. \n\n✅ Performance Check PassedNo performance issues found – changes LGTM. ✅ Quality Check PassedNo quality issues found – changes LGTM. Powered by Visor from Probelabs Last updated: 2026-06-22T12:13:02.150Z | Triggered by: pr_opened | Commit: 1a15d46 💡 TIP: You can chat with Visor using |
🚨 Jira Linter FailedCommit: The Jira linter failed to validate your PR. Please check the error details below: 🔍 Click to view error detailsNext Steps
This comment will be automatically deleted once the linter passes. |
|



TT-17446 Tyk Gateway 5.13.1/5.14.0 CVEs (#8315)
Description
golang.org/x/crypto v0.52.0 and downgraded golang.org/x/net v0.55.0)
Related Issue
Motivation and Context
How This Has Been Tested
Screenshots (if appropriate)
Types of changes
functionality to change)
coverage to functionality)
Checklist
why it's required
explained why