Skip to content

build: Update module golang.org/x/net to v0.45.0 [SECURITY] (releases/v5.x)#183

Merged
pjbgf merged 1 commit intoreleases/v5.xfrom
renovate/releases/v5.x-go-golang.org-x-net-vulnerability
Feb 6, 2026
Merged

build: Update module golang.org/x/net to v0.45.0 [SECURITY] (releases/v5.x)#183
pjbgf merged 1 commit intoreleases/v5.xfrom
renovate/releases/v5.x-go-golang.org-x-net-vulnerability

Conversation

@go-git-renovate
Copy link
Contributor

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/net v0.38.0v0.45.0 age confidence

Quadratic parsing complexity in golang.org/x/net/html

CVE-2025-47911 / GO-2026-4440

More information

Details

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Infinite parsing loop in golang.org/x/net

CVE-2025-58190 / GO-2026-4441

More information

Details

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@go-git-renovate go-git-renovate bot added the dependencies Pull requests that update a dependency file label Feb 6, 2026
@go-git-renovate
Copy link
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 2 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.23.0 -> 1.24.0
go (toolchain) 1.24.11 -> 1.24.13
golang.org/x/sys v0.31.0 -> v0.36.0
golang.org/x/text v0.23.0 -> v0.29.0

@pjbgf pjbgf merged commit 247a741 into releases/v5.x Feb 6, 2026
22 checks passed
@pjbgf pjbgf deleted the renovate/releases/v5.x-go-golang.org-x-net-vulnerability branch February 6, 2026 09:12
Maks1mS pushed a commit to stplr-dev/stplr that referenced this pull request Feb 25, 2026
This PR contains the following updates:

| Package | Type | Update | Change | OpenSSF |
|---|---|---|---|---|
| [github.com/go-git/go-billy/v5](https://github.com/go-git/go-billy) | require | minor | `v5.7.0` → `v5.8.0` | [![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/go-git/go-billy/badge)](https://securityscorecards.dev/viewer/?uri=github.com/go-git/go-billy) |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

---

### Release Notes

<details>
<summary>go-git/go-billy (github.com/go-git/go-billy/v5)</summary>

### [`v5.8.0`](https://github.com/go-git/go-billy/releases/tag/v5.8.0)

[Compare Source](go-git/go-billy@v5.7.0...v5.8.0)

#### What's Changed

- build: Update module golang.org/x/net to v0.45.0 \[SECURITY] (releases/v5.x) by [@&#8203;go-git-renovate](https://github.com/go-git-renovate)\[bot] in [#&#8203;183](go-git/go-billy#183)
- v5: Ensure Chmod behaviour across BoundOS and ChrootOS by [@&#8203;pjbgf](https://github.com/pjbgf) in [#&#8203;187](go-git/go-billy#187)

**Full Changelog**: <go-git/go-billy@v5.7.0...v5.8.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At 12:00 AM through 04:59 AM and 10:00 PM through 11:59 PM, Monday through Friday ( * 0-4,22-23 * * 1-5 ), Only on Sunday and Saturday ( * * * * 0,6 ) (UTC), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMTUuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiS2luZC9EZXBlbmRlbmNpZXMiXX0=-->

Reviewed-on: https://altlinux.space/stapler/stplr/pulls/318
Co-authored-by: Renovate Bot <[email protected]>
Co-committed-by: Renovate Bot <[email protected]>
arthurzam pushed a commit to gentoo-golang-dist/forgejo-runner that referenced this pull request Feb 27, 2026
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/go-git/go-billy/v5](https://github.com/go-git/go-billy) | `v5.6.2` -> `v5.8.0` | ![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgo-git%2fgo-billy%2fv5/v5.8.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgo-git%2fgo-billy%2fv5/v5.6.2/v5.8.0?slim=true) |

---

### Release Notes

<details>
<summary>go-git/go-billy (github.com/go-git/go-billy/v5)</summary>

### [`v5.8.0`](https://github.com/go-git/go-billy/releases/tag/v5.8.0)

[Compare Source](go-git/go-billy@v5.7.0...v5.8.0)

#### What's Changed

- build: Update module golang.org/x/net to v0.45.0 \[SECURITY] (releases/v5.x) by [@&#8203;go-git-renovate](https://github.com/go-git-renovate)\[bot] in [#&#8203;183](go-git/go-billy#183)
- v5: Ensure Chmod behaviour across BoundOS and ChrootOS by [@&#8203;pjbgf](https://github.com/pjbgf) in [#&#8203;187](go-git/go-billy#187)

**Full Changelog**: <go-git/go-billy@v5.7.0...v5.8.0>

### [`v5.7.0`](https://github.com/go-git/go-billy/releases/tag/v5.7.0)

[Compare Source](go-git/go-billy@v5.6.2...v5.7.0)

#### What's Changed

- Add support for Chmod on billy.Filesystem by [@&#8203;bitfehler](https://github.com/bitfehler) in [#&#8203;171](go-git/go-billy#171)
- build: Update module golang.org/x/net to v0.38.0 \[SECURITY] (releases/v5.x) by [@&#8203;go-git-renovate](https://github.com/go-git-renovate)\[bot] in [#&#8203;177](go-git/go-billy#177)

**Full Changelog**: <go-git/go-billy@v5.6.2...v5.7.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 03:59 AM ( * 0-3 * * * ) (UTC), Automerge - Between 12:00 AM and 03:59 AM ( * 0-3 * * * ) (UTC).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41LjAiLCJ1cGRhdGVkSW5WZXIiOiI0My41LjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbIktpbmQvRGVwZW5kZW5jeVVwZGF0ZSIsInJ1bi1lbmQtdG8tZW5kLXRlc3RzIl19-->

Reviewed-on: https://code.forgejo.org/forgejo/runner/pulls/1409
Reviewed-by: Mathieu Fenniak <[email protected]>
Co-authored-by: Renovate Bot <[email protected]>
Co-committed-by: Renovate Bot <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant