Skip to content

chore: upgrade grpc to 1.83.2 to resolve Dependabot alert - #9873

Merged
nishantmonu51 merged 3 commits into
mainfrom
hsingh/dependabot-grpc
Sep 21, 2026
Merged

nishantmonu51 merged 3 commits into
mainfrom
hsingh/dependabot-grpc

Conversation

@himadrisingh

@himadrisingh himadrisingh commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Resolves one open Dependabot security alert:

  • google.golang.org/grpc 1.82.1 → 1.83.2 — GHSA-vp52-pcj8-j9qc (high): heap memory exhaustion (OOM) via HTTP/2 DATA frame fragmentation

Split out from the other Dependabot upgrades because this bump cascades ~28 transitive upgrades via MVS, notably google.golang.org/api 0.230 → 0.264 and cloud.google.com/go/bigquery 1.66 → 1.72. The cascade is inherent to grpc 1.83.2's module graph, not an artifact of go mod tidy — I verified this by applying the bump in isolation. The BigQuery and GCS driver paths are worth extra attention in CI.

Verified go build ./... passes. Overlaps with #9874 on go.mod, so whichever merges second needs a rebase.

Checklist:

  • Covered by tests
  • Ran it and it works as intended
  • Reviewed the diff before requesting a review
  • Checked for unhandled edge cases
  • Linked the issues it closes
  • Checked if the docs need to be updated. If so, create a separate Linear DOCS issue
  • Intend to cherry-pick into the release branch
  • I'm proud of this work!

Developed in collaboration with Claude Code

🤖 Generated with Claude Code

`google.golang.org/grpc` 1.82.1 -> 1.83.2 (GHSA-vp52-pcj8-j9qc: heap memory exhaustion via HTTP/2 DATA frame fragmentation)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@nishantmonu51 nishantmonu51 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 , LGTM post CI failures are fixed.

@nishantmonu51 nishantmonu51 added dependencies Pull requests that update a dependency file Size:M Medium change: 100-499 lines labels Sep 16, 2026

@nishantmonu51 nishantmonu51 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The branch no longer merges cleanly onto main: git merge-tree reports content conflicts in both go.mod and go.sum after four main commits touching them since the merge-base (#9877, #9889, #9852, #9879). main is already ahead on golang.org/x/mod (0.40.0), golang.org/x/tools (0.49.0) and golang.org/x/telemetry (2026-08-11), so go mod tidy needs re-running after the rebase to keep those at main's versions rather than the lower ones selected here.

Two server-side behavior changes ride along and are worth knowing about, though neither needs action: grpc 1.83.0 stops reading a connection once 100 non-DATA/non-HEADERS control frames are queued (tunable via GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT), and 1.83.2 rejects requests missing both :authority and Host with HTTP 400 / Internal. Well-formed clients are fine, but an unusual proxy in front of the runtime or admin servers could start seeing 400s.

Comment thread go.mod
golang.org/x/sys v0.47.0
golang.org/x/term v0.45.0
golang.org/x/text v0.41.0
google.golang.org/api v0.264.0

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The MVS cascade takes google.golang.org/api from 0.230.0 to 0.264.0, whose option/option.go now marks WithCredentialsJSON as deprecated, so staticcheck reports SA1019: option.WithCredentialsJSON is deprecated at cli/cmd/admin/start.go:288 and the lint check on this head is red for exactly that reason (run 34362286664). That is the only caller of the deprecated WithCredentialsJSON/WithCredentialsFile/WithServiceAccountFile family in the repo; the GCS and BigQuery drivers use option.WithCredentials(*google.Credentials), which is unaffected. option.WithAuthCredentialsJSON(option.ServiceAccount, []byte(conf.AssetsBucketGoogleCredentialsJSON)) is the upstream replacement and fits here, since AssetsBucketGoogleCredentialsJSON is operator-supplied service-account JSON.

himadrisingh and others added 2 commits September 21, 2026 13:44
Resolves conflicts in go.mod/go.sum from the grpc 1.83.2 upgrade
(google.golang.org/api transitively bumped to 0.264.0, unrelated
golang.org/x/mod, x/telemetry, x/tools indirect bumps from main taken
as-is) and regenerates go.sum via `go mod tidy`.

Also fixes a lint failure introduced by the google.golang.org/api
bump: option.WithCredentialsJSON is deprecated in 0.264.0, so switch
the sole caller in cli/cmd/admin/start.go to the replacement
option.WithAuthCredentialsJSON(option.ServiceAccount, ...).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The earlier go mod tidy run during the merge left stale go.sum entries
(e.g. still referencing the pre-upgrade grpc v1.82.1 and cloud.google.com/go
v0.121.0) that go build's implicit -mod=mod updates papered over without
fully cleaning up. Re-running go mod tidy on a clean tree produces a
consistent go.sum matching go.mod.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@nishantmonu51
nishantmonu51 merged commit 26e6a4a into main Sep 21, 2026
15 of 16 checks passed
@nishantmonu51
nishantmonu51 deleted the hsingh/dependabot-grpc branch September 21, 2026 09:19
nishantmonu51 pushed a commit that referenced this pull request Sep 23, 2026
* chore: upgrade `grpc` to 1.83.2 to resolve Dependabot alert

`google.golang.org/grpc` 1.82.1 -> 1.83.2 (GHSA-vp52-pcj8-j9qc: heap memory exhaustion via HTTP/2 DATA frame fragmentation)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Fully regenerate go.sum with go mod tidy

The earlier go mod tidy run during the merge left stale go.sum entries
(e.g. still referencing the pre-upgrade grpc v1.82.1 and cloud.google.com/go
v0.121.0) that go build's implicit -mod=mod updates papered over without
fully cleaning up. Re-running go mod tidy on a clean tree produces a
consistent go.sum matching go.mod.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 26e6a4a)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file Size:M Medium change: 100-499 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants