Bump go-jose/go-jose/v4 to v4.1.4 to resolve CVE-2026-34986

Bumps the indirect dependency github.com/go-jose/go-jose/v4 from v4.1.3 to v4.1.4 to resolve CVE-2026-34986 (HIGH).

This is the same patched version used by openbao v2.5.5; the openbao/api/v2 submodule we depend on has not yet published a release past v2.5.1, so the indirect dependency is bumped directly.

This issue carries the security-fix-in-public label, so the fix is made directly on the public repository.

Closes https://gitlab.com/gitlab-org/gitlab-runner/-/issues/39547

Edited by Lachlan Grant

Merge request reports

Loading