Skip to content

Conversation

@cq-bot
Copy link
Contributor

@cq-bot cq-bot commented Nov 14, 2025

This PR contains the following updates:

Package Type Update Change
github.com/dvsekhvalnov/jose2go indirect minor v1.6.0 -> v1.7.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2025-63811

An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.


Release Notes

dvsekhvalnov/jose2go (github.com/dvsekhvalnov/jose2go)

v1.7.0

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@cq-bot cq-bot added automerge Automatically merge once required checks pass security labels Nov 14, 2025
@cq-bot
Copy link
Contributor Author

cq-bot commented Nov 14, 2025

/gen sha=f969cfd398cdeafb6dc2002e7d2710e6634e1f22 dir=plugins/destination/snowflake

@kodiakhq kodiakhq bot merged commit 00e8f5c into main Nov 14, 2025
16 checks passed
@kodiakhq kodiakhq bot deleted the renovate/go-github.com-dvsekhvalnov-jose2go-vulnerability branch November 14, 2025 22:35
kodiakhq bot pushed a commit that referenced this pull request Dec 19, 2025
🤖 I have created a release *beep* *boop*
---


## [5.1.6](plugins-destination-snowflake-v5.1.5...plugins-destination-snowflake-v5.1.6) (2025-12-19)


### Bug Fixes

* **deps:** Update module github.com/cloudquery/plugin-sdk/v4 to v4.92.1 ([#21682](#21682)) ([8a7596b](8a7596b))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v4 to v4.93.0 ([#21710](#21710)) ([f0f2c5b](f0f2c5b))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v4 to v4.93.1 ([#21725](#21725)) ([aa46079](aa46079))
* **deps:** Update module github.com/dvsekhvalnov/jose2go to v1.7.0 [SECURITY] ([#21620](#21620)) ([00e8f5c](00e8f5c))
* **deps:** Update module golang.org/x/crypto to v0.45.0 [SECURITY] ([#21647](#21647)) ([d3f1ff8](d3f1ff8))

---
This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/plugin/destination/snowflake automerge Automatically merge once required checks pass security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants