build(deps): Bump google.golang.org/grpc from 1.79.1 to 1.79.2 - #1279
Conversation
Dependency Security Review:
|
| Field | Value |
|---|---|
| Package | google.golang.org/grpc (grpc-go) |
| Old version | 1.79.1 |
| New version | 1.79.2 |
| Commits | 3 (version bump to dev, cherry-pick of #8874, release tag) |
| Nature | Bug fix (patch release) |
| Files changed | go.mod, go.sum (in this repo) |
Upstream Changes
The sole functional change is a cherry-pick of grpc/grpc-go#8874: prevent redundant error logging in health/ORCA producers by skipping stats/tracing processing when no stats handler is configured.
The implementation moves the stats.Handler reference from the transport level (http2Client) to the per-stream level (ClientStream). Internal streams (health check, ORCA) now pass nil as the stats handler, so stats/tracing callbacks are never invoked for them. This is a clean, focused fix with no behavioral changes to user-facing RPC streams.
Files modified upstream (8 total): internal/transport/client_stream.go, internal/transport/http2_client.go, internal/transport/transport.go, stream.go, version.go, plus test files.
Known Vulnerabilities
| Advisory | Affected Versions | Affects v1.79.2? |
|---|---|---|
| GHSA-xr7q-jx4m-x55m (metadata PII in logs) | 1.64.0 - 1.64.1 | No |
| GHSA-m425-mq94-257g (HTTP/2 Rapid Reset) | < 1.58.3 | No |
No CVEs or advisories affect v1.79.1 or v1.79.2. The OSV and GitHub Advisory databases show no active vulnerabilities for this version range.
Library Audit Findings
| Severity | Finding | Details |
|---|---|---|
| INFO | Stats handler moved to per-stream scope | The statsHandler field is added to ClientStream struct. Internal streams (health, ORCA) pass nil, external RPC streams pass a.statsHandler. No security implications -- this is a correctness fix for error logging. |
No CRITICAL, HIGH, MEDIUM, or LOW findings. The change is minimal and well-scoped.
Codebase Compliance
Tenderdash uses gRPC in 11 Go files, primarily for:
- ABCI gRPC client/server (
abci/client/grpc_client.go,abci/server/grpc_server.go) - Private validator gRPC service (
privval/grpc/) - Protobuf-generated service stubs
The upstream change affects internal transport behavior only. Tenderdash does not directly call any of the modified internal APIs (NewStream, ClientStream fields). The fix will silently eliminate spurious error logs if health checking or ORCA producers are used without a stats handler configured.
No action required in the tenderdash codebase.
Risk Assessment
Rating: Safe
This is a minimal patch release with a single bug fix that reduces unnecessary error logging. No security implications, no API changes, no breaking changes. The upstream diff is small (112 insertions, 60 deletions -- mostly test updates for the new function signature).
CI Status
❌ CI is not green. The tests (01) check failed with:
FAIL: TestReactor_SyncTime (12.86s)
Error: Condition never satisfied
Messages: expected node to be partially synced
This failure is in internal/blocksync/reactor_test.go:319 -- a blocksync reactor test unrelated to gRPC. This appears to be a flaky test (race condition in worker-pool shutdown), not caused by the gRPC dependency update.
This PR cannot be merged until CI is green. A rebase may resolve the flaky test failure.
Recommendations
- Rebase and re-run CI to confirm the test failure is transient/flaky
- Approve and merge once CI passes -- this is a safe, low-risk patch update
- Consider investigating the
TestReactor_SyncTimeflakiness separately if it recurs
🤖 Co-authored by Claudius the Magnificent AI Agent
|
@dependabot rebase |
e3f2d53 to
d44fee4
Compare
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.79.1 to 1.79.2. - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.79.1...v1.79.2) --- updated-dependencies: - dependency-name: google.golang.org/grpc dependency-version: 1.79.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
d44fee4 to
daf8e1d
Compare
Bumps google.golang.org/grpc from 1.79.1 to 1.79.2.
Release notes
Sourced from google.golang.org/grpc's releases.
Commits
8902ab6Change the version to release 1.79.2 (#8947)a928670Cherry-pick #8874 to v1.79.x (#8904)06df363Change version to 1.79.2-dev (#8903)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)