fleet/third_party
Sharon Katz 3f1f0ee1fc
Bump pgx/v5 to v5.9.2 in goval-dictionary (CVE-2026-33816) (#44706)
## Summary

- Bumps `github.com/jackc/pgx/v5` from v5.5.4 to v5.9.2 in
`third_party/goval-dictionary/` to resolve critical code scanning alert
CVE-2026-33816.

**Severity:** Critical (per Trivy/CVE scoring)

**Impact:** Low — the vulnerable package (`pgx/v5`) is a PostgreSQL
driver, but Fleet only uses goval-dictionary with SQLite. The Postgres
code path is never executed.

**Fix:** Bump `pgx/v5` from v5.5.4 to v5.9.2 in
`third_party/goval-dictionary/go.mod`. No code changes needed.

Closes #44699

## Test plan

- [ ] CI passes — only `go.mod` and `go.sum` changed
- [ ] Verify Trivy scan no longer flags CVE-2026-33816

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated third-party package dependencies to latest versions for
improved compatibility and stability.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-04 17:43:27 -04:00
..
goval-dictionary Bump pgx/v5 to v5.9.2 in goval-dictionary (CVE-2026-33816) (#44706) 2026-05-04 17:43:27 -04:00
vuln-check Update go to 1.26.2 and update tooling to update it (#43771) 2026-04-20 13:40:57 -03:00
README.md Updated httpsig-go library to 1.2.0 and removed vendored version. (#32426) 2025-08-28 14:28:30 -05:00