Bump go-jose/go-jose/v4 to v4.1.4 to resolve CVE-2026-34986
Bumps the indirect dependency github.com/go-jose/go-jose/v4 from v4.1.3 to v4.1.4 to resolve CVE-2026-34986 (HIGH).
This is the same patched version used by openbao v2.5.5; the openbao/api/v2 submodule we depend on has not yet published a release past v2.5.1, so the indirect dependency is bumped directly.
This issue carries the security-fix-in-public label, so the fix is made directly on the public repository.
Closes https://gitlab.com/gitlab-org/gitlab-runner/-/issues/39547
Edited by Lachlan Grant