Skip to content

Revendor moc v0.40.2, upgrade gRPC to v1.79.3 (CVE fix) - #373

Merged
Microsoft Corporation (raghavendra-nataraj) merged 1 commit into
masterfrom
fix/revendor-moc-grpc-cve
Apr 20, 2026
Merged

Revendor moc v0.40.2, upgrade gRPC to v1.79.3 (CVE fix)#373
Microsoft Corporation (raghavendra-nataraj) merged 1 commit into
masterfrom
fix/revendor-moc-grpc-cve

Conversation

@raghavendra-nataraj

Copy link
Copy Markdown
Contributor

Addresses CG alert for gRPC-Go authorization bypass CVE.

  • Upgrades github.com/microsoft/moc v0.39.0 → v0.40.2
  • Upgrades google.golang.org/grpc v1.76.0 → v1.79.3
  • Updates replace directive for x/sys compatibility

Related: microsoft/moc#429, microsoft/moc-pkg#721

Addresses CG alert for gRPC-Go authorization bypass CVE.
Updates replace directive for x/sys compatibility.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@raghavendra-nataraj

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@raghavendra-nataraj
Microsoft Corporation (raghavendra-nataraj) merged commit 91ecb8f into master Apr 20, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants