Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

go.mod: bump golang.org/net to 0.4.0 #12158

Merged
merged 1 commit into from
Dec 12, 2022
Merged

go.mod: bump golang.org/net to 0.4.0 #12158

merged 1 commit into from
Dec 12, 2022

Conversation

lbajolet-hashicorp
Copy link
Contributor

As with the go version to 1.18.9, this fix concerns mitigations to the GO-2022-1144 vulnerability.

Since we depend on golang.org/net too, we need to update it to a version that is not vulnerable anymore, and this is starting at version 0.4.0

As with the go version to 1.18.9, this fix concerns mitigations to the
GO-2022-1144 vulnerability.

Since we depend on golang.org/net too, we need to update it to a version
that is not vulnerable anymore, and this is starting at version 0.4.0
@lbajolet-hashicorp lbajolet-hashicorp requested a review from a team as a code owner December 12, 2022 21:11
Copy link
Contributor

@nywilken nywilken left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@nywilken nywilken added the tech-debt Issues and pull requests related to addressing technical debt or improving the codebase label Dec 12, 2022
@nywilken nywilken merged commit 027e920 into main Dec 12, 2022
@nywilken nywilken deleted the fix_gocve_net_update branch December 12, 2022 21:17
@github-actions
Copy link

I'm going to lock this pull request because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues.
If you have found a problem that seems related to this change, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jan 13, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
tech-debt Issues and pull requests related to addressing technical debt or improving the codebase
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants