Skip to content

fix: bump buger/jsonparser to v1.1.2 to fix DoS vulnerability#950

Merged
merlimat merged 2 commits into
mainfrom
fix/bump-buger-jsonparser-1.1.2
Mar 19, 2026
Merged

fix: bump buger/jsonparser to v1.1.2 to fix DoS vulnerability#950
merlimat merged 2 commits into
mainfrom
fix/bump-buger-jsonparser-1.1.2

Conversation

@merlimat

Copy link
Copy Markdown
Collaborator

Summary

Test plan

  • make build passes

Update github.com/buger/jsonparser from v1.1.1 to v1.1.2 across all
workspace modules to address the high-severity denial of service
vulnerability (Dependabot alerts #36, #37, #38).

Signed-off-by: Matteo Merli <[email protected]>
@merlimat
merlimat merged commit b7b1493 into main Mar 19, 2026
9 checks passed
@merlimat
merlimat deleted the fix/bump-buger-jsonparser-1.1.2 branch March 19, 2026 20:51
mattisonchao added a commit that referenced this pull request Mar 20, 2026
PR #950 (buger/jsonparser bump) included unrelated files from a dirty
working tree: design docs, WAL data backups, and an entire
kube-prometheus-stack Helm chart.
mattisonchao added a commit that referenced this pull request Mar 20, 2026
PR #950 (buger/jsonparser bump) included unrelated files from a dirty
working tree: design docs, WAL data backups, and an entire
kube-prometheus-stack Helm chart.

Signed-off-by: mattisonchao <[email protected]>
mattisonchao added a commit that referenced this pull request Mar 20, 2026
### Motivation

PR #950 (buger/jsonparser bump) accidentally included unrelated files
from a dirty working tree during a merge conflict resolution.

### Modification

- Remove `SHARD_SPLIT_DESIGN.md` and `TRANSACTION_DESIGN.md` design docs
- Remove `data.BACKUP/` directory containing WAL data files
- Remove `config.yaml` and `kind-config.yaml`
- Remove `kube-prometheus-stack/` Helm chart directory (CRDs, Grafana
dashboards, templates, etc.)

Signed-off-by: mattisonchao <[email protected]>
mattisonchao added a commit that referenced this pull request Mar 20, 2026
Remove oxia-cluster.yaml, oxia.zsh, perf.yaml, sm.yaml, test.json,
and test.yaml which were also part of the dirty working tree.

Signed-off-by: mattisonchao <[email protected]>
mattisonchao added a commit that referenced this pull request Mar 20, 2026
mattisonchao added a commit that referenced this pull request Mar 20, 2026
Remove oxia-cluster.yaml, oxia.zsh, perf.yaml, sm.yaml, test.json,
test.yaml, and maelstrom binary from the dirty working tree merge.

Signed-off-by: mattisonchao <[email protected]>
mattisonchao added a commit that referenced this pull request Mar 20, 2026
### Motivation

Follow-up to #953 — additional files from the dirty working tree in #950
were missed in the first cleanup.

### Modification

- Remove `oxia-cluster.yaml`, `oxia.zsh`, `perf.yaml`, `sm.yaml`,
`test.json`, `test.yaml`
- Remove `maelstrom` binary (75MB)

Signed-off-by: mattisonchao <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant