Skip to content

vendor: update golang.org/x/ dependencies#49070

Merged
vvoland merged 4 commits intomoby:masterfrom
thaJeztah:bump_crypto
Dec 12, 2024
Merged

vendor: update golang.org/x/ dependencies#49070
vvoland merged 4 commits intomoby:masterfrom
thaJeztah:bump_crypto

Conversation

@thaJeztah
Copy link
Member

vendor: golang.org/x/sys v0.28.0

full diff: golang/sys@v0.27.0...v0.28.0

vendor: golang.org/x/sync v0.10.0

no changes in vendored code

full diff: golang/sync@v0.9.0...v0.10.0

vendor: golang.org/x/text v0.21.0

no changes in vendored code

full diff: golang/text@v0.20.0...v0.21.0

vendor: golang.org/x/crypto v0.31.0

update to the latest version of this dependency, which has a fix for a
authorization bypass in the ssh package. We don't use this functionality,
so there's no need to backport this change (other than de-noising false positives).

This is CVE-2024-45337 and Go issue https://go.dev/issue/70779.

full diff: golang/crypto@v0.29.0...v0.31.0

no changes in vendored code

full diff: golang/sync@v0.9.0...v0.10.0

Signed-off-by: Sebastiaan van Stijn <[email protected]>
no changes in vendored code

full diff: golang/text@v0.20.0...v0.21.0

Signed-off-by: Sebastiaan van Stijn <[email protected]>
update to the latest version of this dependency, which has a fix for a
authorization bypass in the ssh package. We don't use this functionality,
so there's no need to backport this change (other than de-noising false positives).

This is CVE-2024-45337 and Go issue https://go.dev/issue/70779.

full diff: golang/crypto@v0.29.0...v0.31.0

Signed-off-by: Sebastiaan van Stijn <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants