Skip to content

build(deps): Bump google.golang.org/grpc from 1.79.1 to 1.79.2 - #1279

Merged
lklimek merged 1 commit into
v1.6-devfrom
dependabot/go_modules/google.golang.org/grpc-1.79.2
Mar 17, 2026
Merged

lklimek merged 1 commit into
v1.6-devfrom
dependabot/go_modules/google.golang.org/grpc-1.79.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 10, 2026 •

Copy link
Copy Markdown
Contributor

Bumps google.golang.org/grpc from 1.79.1 to 1.79.2.

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.79.2

Bug Fixes

  • stats: Prevent redundant error logging in health/ORCA producers by skipping stats/tracing processing when no stats handler is configured. (grpc/grpc-go#8874)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Mar 10, 2026
@lklimek

lklimek commented Mar 11, 2026

Copy link
Copy Markdown
Collaborator

Dependency Security Review: google.golang.org/grpc v1.79.1 → v1.79.2

Change Summary

Field Value
Package google.golang.org/grpc (grpc-go)
Old version 1.79.1
New version 1.79.2
Commits 3 (version bump to dev, cherry-pick of #8874, release tag)
Nature Bug fix (patch release)
Files changed go.mod, go.sum (in this repo)

Upstream Changes

The sole functional change is a cherry-pick of grpc/grpc-go#8874: prevent redundant error logging in health/ORCA producers by skipping stats/tracing processing when no stats handler is configured.

The implementation moves the stats.Handler reference from the transport level (http2Client) to the per-stream level (ClientStream). Internal streams (health check, ORCA) now pass nil as the stats handler, so stats/tracing callbacks are never invoked for them. This is a clean, focused fix with no behavioral changes to user-facing RPC streams.

Files modified upstream (8 total): internal/transport/client_stream.go, internal/transport/http2_client.go, internal/transport/transport.go, stream.go, version.go, plus test files.

Known Vulnerabilities

Advisory Affected Versions Affects v1.79.2?
GHSA-xr7q-jx4m-x55m (metadata PII in logs) 1.64.0 - 1.64.1 No
GHSA-m425-mq94-257g (HTTP/2 Rapid Reset) < 1.58.3 No

No CVEs or advisories affect v1.79.1 or v1.79.2. The OSV and GitHub Advisory databases show no active vulnerabilities for this version range.

Library Audit Findings

Severity Finding Details
INFO Stats handler moved to per-stream scope The statsHandler field is added to ClientStream struct. Internal streams (health, ORCA) pass nil, external RPC streams pass a.statsHandler. No security implications -- this is a correctness fix for error logging.

No CRITICAL, HIGH, MEDIUM, or LOW findings. The change is minimal and well-scoped.

Codebase Compliance

Tenderdash uses gRPC in 11 Go files, primarily for:

  • ABCI gRPC client/server (abci/client/grpc_client.go, abci/server/grpc_server.go)
  • Private validator gRPC service (privval/grpc/)
  • Protobuf-generated service stubs

The upstream change affects internal transport behavior only. Tenderdash does not directly call any of the modified internal APIs (NewStream, ClientStream fields). The fix will silently eliminate spurious error logs if health checking or ORCA producers are used without a stats handler configured.

No action required in the tenderdash codebase.

Risk Assessment

Rating: Safe

This is a minimal patch release with a single bug fix that reduces unnecessary error logging. No security implications, no API changes, no breaking changes. The upstream diff is small (112 insertions, 60 deletions -- mostly test updates for the new function signature).

CI Status

❌ CI is not green. The tests (01) check failed with:

FAIL: TestReactor_SyncTime (12.86s)
    Error: Condition never satisfied
    Messages: expected node to be partially synced

This failure is in internal/blocksync/reactor_test.go:319 -- a blocksync reactor test unrelated to gRPC. This appears to be a flaky test (race condition in worker-pool shutdown), not caused by the gRPC dependency update.

This PR cannot be merged until CI is green. A rebase may resolve the flaky test failure.

Recommendations

  1. Rebase and re-run CI to confirm the test failure is transient/flaky
  2. Approve and merge once CI passes -- this is a safe, low-risk patch update
  3. Consider investigating the TestReactor_SyncTime flakiness separately if it recurs

🤖 Co-authored by Claudius the Magnificent AI Agent

@lklimek

lklimek commented Mar 11, 2026

Copy link
Copy Markdown
Collaborator

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/google.golang.org/grpc-1.79.2 branch from e3f2d53 to d44fee4 Compare March 11, 2026 13:32
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.79.1 to 1.79.2.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.79.1...v1.79.2)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.79.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/google.golang.org/grpc-1.79.2 branch from d44fee4 to daf8e1d Compare March 11, 2026 14:23
@lklimek
lklimek merged commit 333c24c into v1.6-dev Mar 17, 2026
15 checks passed
@lklimek
lklimek deleted the dependabot/go_modules/google.golang.org/grpc-1.79.2 branch March 17, 2026 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant