Repository navigation
Update golang.org/x dependencies - #163
Merged
Merged
Conversation
govulncheck reported 8 reachable vulnerabilities, all in golang.org/x/net/html via examples/rss-bridge. Bump x/net to v0.58.0 (fixed in v0.55.0) and the other golang.org/x modules to their latest versions that still build with go 1.25, which requires raising the go directive from 1.23.1 to 1.25.0. go mod tidy also drops github.com/gobwas/ws and its dependencies, which no longer have any importer in the tree. govulncheck now reports no reachable vulnerabilities.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
govulncheck reported 8 reachable vulnerabilities on master, all in
golang.org/x/net/html, reached throughexamples/rss-bridge:This bumps
golang.org/x/netto v0.58.0 (the affected ones are fixed in v0.55.0) and the rest of thegolang.org/xmodules to the latest versions that still build with go 1.25. That requires raising thegodirective from 1.23.1 to 1.25.0 — everyx/netrelease carrying the fix needs at least go 1.25.0, so the bump is unavoidable. I stopped at 1.25.0 rather than going to the newest releases, which would have pushed the directive to 1.26.0.go mod tidyalso dropsgithub.com/gobwas/wsand its two dependencies; nothing in the tree imports them anymore.govulncheck ./...now reports no reachable vulnerabilities, andgo build ./...,go vet ./...andgo test .all pass.Supersedes #158, #159 and #157, which proposed a
go.mod-only edit without the matchinggo.sumupdate.