• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

supabase / auth / 30364483649
72%

Build:
DEFAULT BRANCH: master
Ran 28 Jul 2026 01:45PM UTC
Jobs 1
Files 196
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Jul 2026 01:39PM UTC coverage: 72.126%. Remained the same
30364483649

push

github

web-flow
fix: update google.golang.org/grpc to v1.82.1 (#2651)

## What kind of change does this PR introduce?

This change updates google.golang.org/grpc to resolve
https://pkg.go.dev/vuln/GO-2026-6061

## What is the current behavior?

```bash
モ make vulncheck
tools/bin/govulncheck ./... | go run ./hack/vulncheck-filter
ignoring GO-2026-5004: pgx/v4 SQL injection via dollar-quoted placeholder confusion, no fix available. Transitive via pop/v6.
ignoring GO-2026-4518: pgproto3/v2 DoS, no fix available (EOL). Transitive via pgconn v1 + pop/v6.

Vulnerability #1: GO-2026-6061
    Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2
    transport server implementation in google.golang.org/grpc
  More info: https://pkg.go.dev/vuln/GO-2026-6061
  Module: google.golang.org/grpc
    Found in: google.golang.org/grpc@v1.81.1
    Fixed in: google.golang.org/grpc@v1.82.1
    Example traces found:
      #1: internal/observability/metrics.go:165:16: observability.ConfigureMetrics calls sync.Once.Do, which eventually calls transport.ClientStream.Close
      #2: internal/observability/metrics.go:165:16: observability.ConfigureMetrics calls sync.Once.Do, which eventually calls transport.ClientStream.Header
      #3: internal/observability/metrics.go:165:16: observability.ConfigureMetrics calls sync.Once.Do, which eventually calls transport.ClientStream.Read
      #4: internal/observability/metrics.go:165:16: observability.ConfigureMetrics calls sync.Once.Do, which eventually calls transport.ClientStream.RecvCompress
      #5: internal/observability/metrics.go:165:16: observability.ConfigureMetrics calls sync.Once.Do, which eventually calls transport.ClientStream.TrailersOnly
      #6: internal/observability/metrics.go:165:16: observability.ConfigureMetrics calls sync.Once.Do, which eventually calls transport.ClientStream.Write
      #7: internal/observability/metrics.go:165:16: observability.ConfigureMetrics calls sync.Once.Do, which eventually calls transport.... (continued)

18294 of 25364 relevant lines covered (72.13%)

666.57 hits per line

Jobs
ID Job ID Ran Files Coverage
1 30364483649.1 28 Jul 2026 01:45PM UTC 196
72.13
GitHub Action Run
Source Files on build 30364483649
  • Tree
  • List 196
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 4a596c0d on github
  • Prev Build on master (#30281184886)
  • Next Build on master (#30364523892)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc