Eight open Dependabot alerts, all transitive through the Pulumi SDK:
grpc < 1.82.2 / <= 1.83.0 (#3, #4 high; #5 medium) -> v1.83.2
otel/sdk, otlptrace, otlptracegrpc <= 1.44.0 (#6-8) -> v1.45.0
otel/sdk/log, otlplog/otlploggrpc < 0.21.0 (#9-10) -> v0.21.0
This supersedes Dependabot PR #1, which bumps grpc only and predates the
otel alerts.
otel/log v0.21 changed its API, so the otelslog bridge has to move with
it: v0.18.0 no longer compiles against it. v0.20.1 is the release built
for that otel line.
govulncheck then reported ten reachable standard-library and x/net
vulnerabilities disclosed since the last pin (net/http HTTP/2 and CONNECT
handling, net/textproto, crypto/tls ECH, os on Windows), all fixed in
go1.26.9 and golang.org/x/net v0.60.0. Raising the toolchain floor is the
same remedy as before; x/net v0.60.0 requires go 1.26, which lifts the
go directive from 1.25.11 to 1.26.0.
The Pulumi SDK and pulumi-gcp direct dependencies are deliberately left
where they are, so this does not also change provider behaviour ahead of
the first deploy.
govulncheck now reports no reachable vulnerabilities. GO-2026-5932
(x/crypto/openpgp, no fix available, not called) remains, as before.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>