Skip to content

[9.2](backport #6602) build(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3#6606

Open
mergify[bot] wants to merge 1 commit into9.2from
mergify/bp/9.2/pr-6602
Open

[9.2](backport #6602) build(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3#6606
mergify[bot] wants to merge 1 commit into9.2from
mergify/bp/9.2/pr-6602

Conversation

@mergify
Copy link
Contributor

@mergify mergify bot commented Mar 18, 2026

Bumps google.golang.org/grpc from 1.79.2 to 1.79.3.

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.79.3

Security

  • server: fix an authorization bypass where malformed :path headers (missing the leading slash) could bypass path-based restricted "deny" rules in interceptors like grpc/authz. Any request with a non-canonical path is now immediately rejected with an Unimplemented error. (#8981)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

This is an automatic backport of pull request #6602 done by [Mergify](https://mergify.com).

* build(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3

Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.79.2 to 1.79.3.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.79.2...v1.79.3)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.79.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Post dependabot file modifications

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <dependabot[bot]@users.noreply.github.com>
(cherry picked from commit 9aa343d)
@mergify mergify bot requested a review from a team as a code owner March 18, 2026 08:47
@mergify mergify bot requested a review from blakerouse March 18, 2026 08:47
@mergify mergify bot added the backport label Mar 18, 2026
@mergify mergify bot requested a review from michel-laterman March 18, 2026 08:47
@github-actions github-actions bot added automation dependency Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team labels Mar 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants