Skip to content

chore(security): update vendor to fix CVE#4121

Merged
appleboy merged 1 commit into
gin-gonic:masterfrom
xlgao-zju:update-vendor
Dec 28, 2024
Merged

chore(security): update vendor to fix CVE#4121
appleboy merged 1 commit into
gin-gonic:masterfrom
xlgao-zju:update-vendor

Conversation

@xlgao-zju
Copy link
Copy Markdown
Contributor

update golang.org/x/net to fix CVE-2024-45338
update golang.org/x/crypto to fix CVE-2024-45337

Signed-off-by: Xianglin Gao <[email protected]>
@helzahalim
Copy link
Copy Markdown

Can we prioritize this and get this PR merged please?

Denial of Service (DoS)
Affecting golang.org/x/net/html package, versions <0.33.0>

@appleboy appleboy changed the title update vendor to fix cve chore(security): update vendor to fix CVE Dec 28, 2024
@appleboy appleboy merged commit e2e80f3 into gin-gonic:master Dec 28, 2024
@appleboy appleboy added this to the v1.11 milestone Dec 28, 2024
@xlgao-zju xlgao-zju deleted the update-vendor branch December 30, 2024 02:25
@xlgao-zju
Copy link
Copy Markdown
Contributor Author

Can we prioritize this and get this PR merged please?

Denial of Service (DoS) Affecting golang.org/x/net/html package, versions <0.33.0>

golang.org/x/net/html I think we do not use this pkg for now...

1911860538 pushed a commit to 1911860538/gin that referenced this pull request Feb 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants