prometheus / prometheus/pushgateway
Update dependencies to fix CVE-2026-46600 and CVE-2026-56854
Open
Beginner friendly
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 3.4k
- Forks
- 496
- PR merge metrics
- No merged PRs in 30d
Description
[Scan Info]
Vulnerable Component: go://golang.org/x/net:0.55.0
Fix Versions: 0.56.0
[Scan Info]
Vulnerable Component: go://golang.org/x/crypto:0.52.0
Fix Versions: 0.55.0
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Locate the Go dependency manifest and inspect the entries for golang.org/x/net and golang.org/x/crypto. Update them to the listed fixed versions, then run the repository's tests and verify that the dependency scan no longer reports CVE-2026-46600 or CVE-2026-56854.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Clearly specified
- Newbie friendliness
- 78/100