Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 12, 2025

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/net v0.34.0 -> v0.38.0 age confidence

GitHub Vulnerability Alerts

CVE-2025-22870

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

CVE-2025-22872

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. , , etc contexts).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner March 12, 2025 22:27
Copy link
Contributor Author

renovate bot commented Mar 12, 2025

ℹ Artifact update notice

File name: modules/project_cleanup/function_source/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 4 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.22.7 -> 1.23.0
go (toolchain) 1.23.6 -> 1.24.7
golang.org/x/crypto v0.32.0 -> v0.36.0
golang.org/x/sync v0.10.0 -> v0.12.0
golang.org/x/sys v0.29.0 -> v0.31.0
golang.org/x/text v0.21.0 -> v0.23.0

@dpebot
Copy link
Collaborator

dpebot commented Mar 12, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 6e87f11 to a603b18 Compare April 16, 2025 19:44
@renovate renovate bot changed the title fix(deps): Update module golang.org/x/net to v0.36.0 [SECURITY] fix(deps): Update module golang.org/x/net to v0.38.0 [SECURITY] Apr 16, 2025
@dpebot
Copy link
Collaborator

dpebot commented Apr 16, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from a603b18 to 1e489e6 Compare August 10, 2025 14:43
@dpebot
Copy link
Collaborator

dpebot commented Aug 10, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 1e489e6 to b38b97e Compare August 22, 2025 17:24
@dpebot
Copy link
Collaborator

dpebot commented Aug 22, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from b38b97e to 1bc9eb5 Compare August 22, 2025 17:37
@dpebot
Copy link
Collaborator

dpebot commented Aug 22, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 1bc9eb5 to 88ce5fd Compare September 11, 2025 01:43
@dpebot
Copy link
Collaborator

dpebot commented Sep 11, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 88ce5fd to dcd09ce Compare September 11, 2025 04:33
@dpebot
Copy link
Collaborator

dpebot commented Sep 11, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from dcd09ce to 2363bd7 Compare September 11, 2025 10:51
@dpebot
Copy link
Collaborator

dpebot commented Sep 11, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 2363bd7 to ba45936 Compare September 11, 2025 13:33
@dpebot
Copy link
Collaborator

dpebot commented Sep 11, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from ba45936 to 4e79170 Compare September 11, 2025 20:59
@dpebot
Copy link
Collaborator

dpebot commented Sep 11, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 4e79170 to 0f1d308 Compare September 11, 2025 21:21
@dpebot
Copy link
Collaborator

dpebot commented Sep 11, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 0f1d308 to 32c3d81 Compare September 11, 2025 22:03
@dpebot
Copy link
Collaborator

dpebot commented Sep 11, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 32c3d81 to 38d2d0e Compare September 11, 2025 22:22
@dpebot
Copy link
Collaborator

dpebot commented Sep 11, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 38d2d0e to b38ee87 Compare September 12, 2025 04:32
@dpebot
Copy link
Collaborator

dpebot commented Sep 12, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from b38ee87 to 5a1aa13 Compare September 15, 2025 17:01
@dpebot
Copy link
Collaborator

dpebot commented Sep 15, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 5a1aa13 to 5efddf5 Compare September 15, 2025 20:12
@dpebot
Copy link
Collaborator

dpebot commented Sep 15, 2025

/gcbrun

@renovate renovate bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from 5efddf5 to 24b5950 Compare September 16, 2025 20:09
@dpebot
Copy link
Collaborator

dpebot commented Sep 16, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant