fix(deps): update module golang.org/x/net to v0.56.0 [security] - #49
fix(deps): update module golang.org/x/net to v0.56.0 [security]#49alaudaa-renovate[bot] wants to merge 1 commit into
Conversation
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
🤖 AI Code Review
SummaryThis PR updates the Review Statistics
Critical Issues
None. This is a security fix and the dependency updates are appropriate. Warnings
None. Suggestions
Positive Feedback
ℹ️ About this reviewThis review was automatically generated using the
|
PR Assist Bot — Owner Approval NeededThis PR targets release branch PR: AlaudaDevops/harbor-scanner-trivy#49 Please reply with |
alaudabot
left a comment
There was a problem hiding this comment.
This PR cleanly patches two CVEs in golang.org/x/net/html (CVE-2025-58190 and CVE-2025-47911) with no blocking issues. The indirect dependency updates are also correct. LGTM.
41cf4bf to
83709ba
Compare
alaudabot
left a comment
There was a problem hiding this comment.
Review Complete
This security dependency update has been reviewed. No critical issues, warnings, or suggestions were found. The PR addresses multiple CVEs (CVE-2025-47911, CVE-2025-58190, CVE-2026-33814) by upgrading golang.org/x/net to v0.53.0.
Recommendation: Merge - security update is safe and necessary.
| go.opentelemetry.io/otel/metric v1.36.0 // indirect | ||
| go.opentelemetry.io/otel/trace v1.36.0 // indirect | ||
| golang.org/x/crypto v0.36.0 // indirect | ||
| golang.org/x/crypto v0.50.0 // indirect |
There was a problem hiding this comment.
Warning (security/dependency-jump): The golang.org/x/text indirect dependency was updated from v0.23.0 to v0.36.0 — a jump of 13 minor versions. Verify the x/text changelog has been reviewed for any breaking changes that could affect this project.
alaudabot
left a comment
There was a problem hiding this comment.
Review Summary
This PR updates golang.org/x/net from v0.38.0 to v0.53.0 to address multiple security vulnerabilities (CVE-2025-47911, CVE-2025-58190, CVE-2026-33814). The changes are straightforward dependency version bumps.
No critical issues found. The dependency updates are appropriate and correctly address the security vulnerabilities.
Suggestions
- Consider adding renovate config to pin
golang.org/x/*dependencies for automatic security updates (go.mod:20)
Review generated from pr-overview.md
| github.com/stretchr/testify v1.10.0 | ||
| github.com/testcontainers/testcontainers-go v0.32.0 | ||
| golang.org/x/net v0.38.0 | ||
| golang.org/x/net v0.53.0 |
There was a problem hiding this comment.
Suggestion (refactor/dependency-management): Consider adding renovate config to pin golang.org/x/* dependencies for automatic security updates:
{
"extends": ["config:base"],
"packageRules": [{
"matchPackagePatterns": ["golang.org/x/*"],
"matchUpdateTypes": ["security"],
"automerge": true
}]
}
Autoclosing SkippedThis PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error. |
83709ba to
483c902
Compare
483c902 to
ab7dba0
Compare
This PR contains the following updates:
v0.55.0->v0.56.0Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
BIT-golang-2026-46600 / CVE-2026-46600 / GO-2026-5942
More information
Details
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Configuration
📅 Schedule: Branch creation - "" in timezone Asia/Shanghai, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.