Skip to content

[Cycode] Fix for vulnerable manifest file dependency - github.com/jackc/pgx/v5 updated to version 5.9.0 - #95

Open
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-8902cb1c-afac-4365-a9d4-535c667ff51f
Open

cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-8902cb1c-afac-4365-a9d4-535c667ff51f

Conversation

@cycode-security

@cycode-security cycode-security Bot commented Jun 26, 2026

Copy link
Copy Markdown

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
go.mod 1

📂 go.mod

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
github.com/jackc/pgx/v5 5.7.5 5.9.0

Note

Low Risk
Single dependency patch bump with no logic changes; typical low-risk security maintenance, though any pgx behavior change could affect PostgreSQL proxy connectivity.

Overview
Bumps github.com/jackc/pgx/v5 in go.mod from 5.7.5 to 5.9.0 to address a reported vulnerable dependency (Cycode).

There are no application code changes in this PR—only the direct module version in go.mod. Perses uses pgx (e.g. pgxpool / stdlib) for PostgreSQL datasource proxy connections in internal/api/impl/proxy.

Reviewed by Cursor Bugbot for commit 5e586f5. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants