Skip to content

Upgrade github.com/jackc/pgx/v5 to fix CVEs (v5.4.36)#4375

Merged
reinkrul merged 1 commit into
V5.4from
fix/pgx-go-2026-5004-v5.4
Jul 1, 2026
Merged

Upgrade github.com/jackc/pgx/v5 to fix CVEs (v5.4.36)#4375
reinkrul merged 1 commit into
V5.4from
fix/pgx-go-2026-5004-v5.4

Conversation

@reinkrul

Copy link
Copy Markdown
Member

Summary

  • Upgrade github.com/jackc/pgx/v5 from v5.5.4 to v5.9.2 (indirect dependency)
  • Add release notes for v5.4.36

Fixes the following vulnerabilities:

Advisory Package Description
GO-2026-5004 github.com/jackc/pgx/v5 SQL injection in the non-default simple protocol when a dollar-quoted string literal contains an attacker-controlled value that looks like a placeholder. Fixed in v5.9.2.

Assisted by AI

@qltysh

qltysh Bot commented Jun 30, 2026

Copy link
Copy Markdown
Contributor

Qlty


Coverage Impact

⬆️ Merging this pull request will increase total coverage on V5.4 by 0.09%.

🚦 See full report on Qlty Cloud »

🛟 Help
  • Diff Coverage: Coverage for added or modified lines of code (excludes deleted files). Learn more.

  • Total Coverage: Coverage for the whole repository, calculated as the sum of all File Coverage. Learn more.

  • File Coverage: Covered Lines divided by Covered Lines plus Missed Lines. (Excludes non-executable lines including blank lines and comments.)

    • Indirect Changes: Changes to File Coverage for files that were not modified in this PR. Learn more.

@reinkrul
reinkrul merged commit e56a10b into V5.4 Jul 1, 2026
9 checks passed
@reinkrul
reinkrul deleted the fix/pgx-go-2026-5004-v5.4 branch July 1, 2026 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants