Skip to content

[Cycode] Fix for vulnerable manifest file dependency - github.com/google/cel-go updated to version 0.29.0 - #114

Open
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-2c9ecb5b-8cc3-4955-a9c3-3c959f634a79
Open

[Cycode] Fix for vulnerable manifest file dependency - github.com/google/cel-go updated to version 0.29.0#114
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-2c9ecb5b-8cc3-4955-a9c3-3c959f634a79

Conversation

@cycode-security

@cycode-security cycode-security Bot commented Jul 25, 2026

Copy link
Copy Markdown

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
go.mod 1

📂 go.mod

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
github.com/google/cel-go 0.26.1 0.29.0

Note

Low Risk
Single direct dependency version bump with no code changes; low blast radius aside from possible CEL runtime behavior differences across minor releases.

Overview
Bumps github.com/google/cel-go from 0.26.1 to 0.29.0 in go.mod to address a reported vulnerable dependency (Cycode).

No application source changes in this diff; the library is used for CEL assertions in custom dashboard lint rules (CustomLintRule in the API config layer). After merge, run go mod tidy / refresh go.sum if not already included so builds pin the new version.

Reviewed by Cursor Bugbot for commit 4e49667. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants