Skip to content

fix(deps): upgrade github.com/jackc/pgx/v5 to 5.9.2 (COMP-2457) - #78

Merged
cristianrcv merged 1 commit into
masterfrom
fix/COMP-2457-pgx-5-9-2
Sep 15, 2026
Merged

cristianrcv merged 1 commit into
masterfrom
fix/COMP-2457-pgx-5-9-2

Conversation

@cristianrcv

Copy link
Copy Markdown
Contributor

Summary

Upgrades github.com/jackc/pgx/v5 from v5.7.6 to v5.9.2.

Why this is being reopened: PRs #74 and #75 both proposed this upgrade (to 5.9.0) and were both closed without merging during a de-duplication pass. The result was that pgx stayed on the vulnerable 5.7.6 on master, while COMP-2457 and COMP-2458 were left reading as resolved. The vulnerability is still live on master today.

Why 5.9.2 and not 5.9.0

Targeting 5.9.2 clears three open Dependabot alerts in one change rather than leaving one behind:

Alert Severity Vulnerable range Cleared by
#10 critical < 5.9.0 5.9.0
#13 critical < 5.9.0 5.9.0
#11 low < 5.9.2 5.9.2

Scope of the diff

Limited to go.mod and go.sum (5 insertions, 5 deletions). The go directive and the sibling golang.org/x modules are already current from the merged x/crypto upgrade (#71), so none of the cascading version bumps seen in the earlier attempts are needed here.

Verification

go mod verify (all modules verified), go build ./..., go vet ./... and go test ./... all pass.

JIRA

COMP-2457: Fix pgx contains memory-safety vulnerability
Also resolves COMP-2458 (same upgrade, duplicate ticket).

🤖 Generated with Claude Code

PR #74 and #75 both proposed this upgrade to 5.9.0 and were closed
without merging, so pgx stayed on the vulnerable 5.7.6 on master while
COMP-2457/2458 read as resolved. This reopens the fix.

Targets 5.9.2 rather than the advisories' minimum 5.9.0 so that the
low-severity alert 11 (< 5.9.2) is cleared in the same change as the
two critical alerts 10 and 13 (< 5.9.0).

The go directive and the sibling golang.org/x modules are already
current from the merged x/crypto upgrade (#71), so the diff is limited
to go.mod and go.sum.

Verified: go mod verify, go build ./..., go vet ./... and go test ./...
all pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@cristianrcv
cristianrcv merged commit c36c068 into master Sep 15, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants