Skip to content

deps: update vulnerable Go modules - #84

Merged
cowbon merged 1 commit into
mainfrom
cve-fix
Jul 24, 2026
Merged

deps: update vulnerable Go modules#84
cowbon merged 1 commit into
mainfrom
cve-fix

Conversation

@cowbon

@cowbon cowbon commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator

Updates Go module dependencies to address reported vulnerability advisories.

  • golang.org/x/text v0.39.0
  • golang.org/x/net v0.56.0
  • Compatible golang.org/x companion modules updated by the resolver

Validation: go test -mod=mod ./...

Note: the remaining scanner findings concern the Go 1.26.4 standard library (fixed in Go 1.26.5) and the unmaintained x/crypto/openpgp package, which is not imported by this project.

Signed-off-by: Ian Chin Wang <ian.chin.wang@oracle.com>

@jraman567 jraman567 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @cowbon. LGTM

@cowbon
cowbon merged commit b9ba647 into main Jul 24, 2026
2 checks passed
@cowbon
cowbon deleted the cve-fix branch July 24, 2026 20:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants