Skip to content

build(deps): bump github.com/open-policy-agent/opa-envoy-plugin from 0.34.2-envoy to 1.13.2-envoy-2 in /kubernetes/opa-plugins#4029

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/kubernetes/opa-plugins/github.com/open-policy-agent/opa-envoy-plugin-1.13.2-envoy-2
Open

build(deps): bump github.com/open-policy-agent/opa-envoy-plugin from 0.34.2-envoy to 1.13.2-envoy-2 in /kubernetes/opa-plugins#4029
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/kubernetes/opa-plugins/github.com/open-policy-agent/opa-envoy-plugin-1.13.2-envoy-2

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 18, 2026

Bumps github.com/open-policy-agent/opa-envoy-plugin from 0.34.2-envoy to 1.13.2-envoy-2.

Release notes

Sourced from github.com/open-policy-agent/opa-envoy-plugin's releases.

v1.13.2-envoy-2

input.parsed_field Security Vulnerability Fixed (GHSA-9f29-v6mm-pw6w)

This release contains a security fix for a security vulnerability in how the input.parsed_path field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (//) as authority components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served.

Please see the Security Advisory for more information.

Authored by @​thevilledev

What's Changed

New Contributors

Full Changelog: open-policy-agent/opa-envoy-plugin@v1.13.1-envoy...v1.13.2-envoy-2

v1.13.1-envoy

What's Changed

v1.13.0-envoy

What's Changed

v1.12.2-envoy

What's Changed

v1.12.1-envoy

What's Changed

v1.12.0-envoy

What's Changed

... (truncated)

Commits
  • 0f0ab2d build: bump go 1.25.5 -> 1.25.7 (#814)
  • 58c44d4 Merge commit from fork
  • dd0d204 build(deps): bump github.com/open-policy-agent/opa from 1.13.1 to 1.13.2
  • 3c08896 build(deps): bump github.com/envoyproxy/go-control-plane/envoy
  • 65ebda9 build(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.1 (#811)
  • 13cfadf fix: update Envoy and Rego config in quickstart (#807)
  • 70b0a0b build(deps): bump golang.org/x/tools from 0.41.0 to 0.42.0 (#810)
  • f1f68d5 docs(readme): add note about repository size (#808)
  • 7ed1120 build(deps): bump the go-opentelemetry-io group with 6 updates (#805)
  • 4d8262e build(deps): bump github.com/open-policy-agent/opa from 1.13.0 to 1.13.1 (#804)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [github.com/open-policy-agent/opa-envoy-plugin](https://github.com/open-policy-agent/opa-envoy-plugin) from 0.34.2-envoy to 1.13.2-envoy-2.
- [Release notes](https://github.com/open-policy-agent/opa-envoy-plugin/releases)
- [Changelog](https://github.com/open-policy-agent/opa-envoy-plugin/blob/main/CHANGELOG.md)
- [Commits](open-policy-agent/opa-envoy-plugin@v0.34.2-envoy...v1.13.2-envoy-2)

---
updated-dependencies:
- dependency-name: github.com/open-policy-agent/opa-envoy-plugin
  dependency-version: 1.13.2-envoy-2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Feb 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants