Skip to content

Upgrade github.com/jackc/pgx/v5 to fix CVEs (v6.2.9)#4374

Merged
reinkrul merged 1 commit into
V6.2from
fix/pgx-go-2026-5004-v6.2
Jul 1, 2026
Merged

Upgrade github.com/jackc/pgx/v5 to fix CVEs (v6.2.9)#4374
reinkrul merged 1 commit into
V6.2from
fix/pgx-go-2026-5004-v6.2

Conversation

@reinkrul

Copy link
Copy Markdown
Member

Summary

  • Upgrade github.com/jackc/pgx/v5 from v5.7.5 to v5.9.2
  • Add release notes for v6.2.9

Fixes the following vulnerabilities:

Advisory Package Description
GO-2026-5004 github.com/jackc/pgx/v5 SQL injection in the non-default simple protocol when a dollar-quoted string literal contains an attacker-controlled value that looks like a placeholder. Fixed in v5.9.2.

Assisted by AI

@qltysh

qltysh Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Qlty


Coverage Impact

⬇️ Merging this pull request will decrease total coverage on V6.2 by 0.02%.

🚦 See full report on Qlty Cloud »

🛟 Help
  • Diff Coverage: Coverage for added or modified lines of code (excludes deleted files). Learn more.

  • Total Coverage: Coverage for the whole repository, calculated as the sum of all File Coverage. Learn more.

  • File Coverage: Covered Lines divided by Covered Lines plus Missed Lines. (Excludes non-executable lines including blank lines and comments.)

    • Indirect Changes: Changes to File Coverage for files that were not modified in this PR. Learn more.

@reinkrul
reinkrul merged commit d6afd52 into V6.2 Jul 1, 2026
9 of 10 checks passed
@reinkrul
reinkrul deleted the fix/pgx-go-2026-5004-v6.2 branch July 1, 2026 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants