Skip to content

Update golang.org/x dependencies - #163

Merged
mattn merged 1 commit into
masterfrom
deps/update-x-packages
Sep 10, 2026
Merged

mattn merged 1 commit into
masterfrom
deps/update-x-packages

Conversation

@mattn

@mattn mattn commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator

govulncheck reported 8 reachable vulnerabilities on master, all in golang.org/x/net/html, reached through examples/rss-bridge:

#1: examples/rss-bridge/feed.go:55:44: rss.getFeedURL calls goquery.NewDocumentFromReader, which calls html.Parse

This bumps golang.org/x/net to v0.58.0 (the affected ones are fixed in v0.55.0) and the rest of the golang.org/x modules to the latest versions that still build with go 1.25. That requires raising the go directive from 1.23.1 to 1.25.0 — every x/net release carrying the fix needs at least go 1.25.0, so the bump is unavoidable. I stopped at 1.25.0 rather than going to the newest releases, which would have pushed the directive to 1.26.0.

go mod tidy also drops github.com/gobwas/ws and its two dependencies; nothing in the tree imports them anymore.

govulncheck ./... now reports no reachable vulnerabilities, and go build ./..., go vet ./... and go test . all pass.

Supersedes #158, #159 and #157, which proposed a go.mod-only edit without the matching go.sum update.

govulncheck reported 8 reachable vulnerabilities, all in
golang.org/x/net/html via examples/rss-bridge. Bump x/net to v0.58.0
(fixed in v0.55.0) and the other golang.org/x modules to their latest
versions that still build with go 1.25, which requires raising the go
directive from 1.23.1 to 1.25.0.

go mod tidy also drops github.com/gobwas/ws and its dependencies, which
no longer have any importer in the tree.

govulncheck now reports no reachable vulnerabilities.
@mattn
mattn merged commit 391838e into master Sep 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant