Skip to content

Commit 4015bc3

Browse files
committed
Update golang.org/x/net to v0.36.0 to fix CVE-2025-22870
Address security vulnerability GHSA-qxp5-gwg8-xv66 related to HTTP proxy bypass using IPv6 Zone IDs in golang.org/x/net
1 parent 0171b4e commit 4015bc3

File tree

2 files changed

+421
-1
lines changed

2 files changed

+421
-1
lines changed

go.mod

Lines changed: 43 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,10 @@ require (
2222
dario.cat/mergo v1.0.1 // indirect
2323
filippo.io/edwards25519 v1.1.0 // indirect
2424
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
25+
github.com/Masterminds/semver v0.0.0-20190925130524-317e8cce5480 // indirect
26+
github.com/Masterminds/vcs v1.13.1 // indirect
2527
github.com/Microsoft/go-winio v0.6.2 // indirect
28+
github.com/armon/go-radix v0.0.0-20180808171621-7fddfc383310 // indirect
2629
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.6.10 // indirect
2730
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.30 // indirect
2831
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.34 // indirect
@@ -37,7 +40,10 @@ require (
3740
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30.1 // indirect
3841
github.com/aws/aws-sdk-go-v2/service/sts v1.33.18 // indirect
3942
github.com/aws/smithy-go v1.22.3 // indirect
43+
github.com/blang/semver v3.5.1+incompatible // indirect
44+
github.com/boltdb/bolt v1.3.1 // indirect
4045
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
46+
github.com/common-nighthawk/go-figure v0.0.0-20200609044655-c4b36f998cf2 // indirect
4147
github.com/containerd/log v0.1.0 // indirect
4248
github.com/containerd/platforms v0.2.1 // indirect
4349
github.com/cpuguy83/dockercfg v0.3.2 // indirect
@@ -47,17 +53,31 @@ require (
4753
github.com/docker/go-units v0.5.0 // indirect
4854
github.com/ebitengine/purego v0.8.2 // indirect
4955
github.com/felixge/httpsnoop v1.0.4 // indirect
56+
github.com/fsnotify/fsnotify v1.4.7 // indirect
5057
github.com/go-logr/logr v1.4.2 // indirect
5158
github.com/go-logr/stdr v1.2.2 // indirect
5259
github.com/go-ole/go-ole v1.3.0 // indirect
5360
github.com/gogo/protobuf v1.3.2 // indirect
61+
github.com/golang/dep v0.5.4 // indirect
62+
github.com/golang/protobuf v1.5.3 // indirect
5463
github.com/golang/snappy v1.0.0 // indirect
64+
github.com/google/go-github/v30 v30.1.0 // indirect
65+
github.com/google/go-querystring v1.0.0 // indirect
5566
github.com/google/uuid v1.6.0 // indirect
5667
github.com/hashicorp/errwrap v1.1.0 // indirect
5768
github.com/hashicorp/go-multierror v1.1.1 // indirect
69+
github.com/hashicorp/hcl v1.0.0 // indirect
70+
github.com/inconshreveable/go-update v0.0.0-20160112193335-8152e7eb6ccf // indirect
71+
github.com/inconshreveable/mousetrap v1.0.0 // indirect
72+
github.com/jedib0t/go-pretty/v6 v6.0.4 // indirect
73+
github.com/jmank88/nuts v0.4.0 // indirect
5874
github.com/klauspost/compress v1.18.0 // indirect
75+
github.com/logrusorgru/aurora v2.0.3+incompatible // indirect
5976
github.com/lufia/plan9stats v0.0.0-20250317134145-8bc96cf8fc35 // indirect
6077
github.com/magiconair/properties v1.8.10 // indirect
78+
github.com/mattn/go-runewidth v0.0.9 // indirect
79+
github.com/mitchellh/go-homedir v1.1.0 // indirect
80+
github.com/mitchellh/mapstructure v1.1.2 // indirect
6181
github.com/moby/docker-image-spec v1.3.1 // indirect
6282
github.com/moby/patternmatcher v0.6.0 // indirect
6383
github.com/moby/sys/sequential v0.6.0 // indirect
@@ -66,15 +86,33 @@ require (
6686
github.com/moby/term v0.5.2 // indirect
6787
github.com/montanaflynn/stats v0.7.1 // indirect
6888
github.com/morikuni/aec v1.0.0 // indirect
89+
github.com/nightlyone/lockfile v1.0.0 // indirect
6990
github.com/opencontainers/go-digest v1.0.0 // indirect
7091
github.com/opencontainers/image-spec v1.1.1 // indirect
92+
github.com/package-url/packageurl-go v0.1.0 // indirect
93+
github.com/pelletier/go-toml v1.9.5 // indirect
7194
github.com/pkg/errors v0.9.1 // indirect
7295
github.com/pmezard/go-difflib v1.0.0 // indirect
7396
github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55 // indirect
97+
github.com/recoilme/pudge v1.0.3 // indirect
98+
github.com/rhysd/go-github-selfupdate v1.2.3 // indirect
99+
github.com/sdboyer/constext v0.0.0-20170321163424-836a14457353 // indirect
74100
github.com/shirou/gopsutil/v4 v4.25.3 // indirect
101+
github.com/shopspring/decimal v1.2.0 // indirect
75102
github.com/sirupsen/logrus v1.9.3 // indirect
103+
github.com/sonatype-nexus-community/go-sona-types v0.1.6 // indirect
104+
github.com/sonatype-nexus-community/nancy v1.0.48 // indirect
105+
github.com/spf13/afero v1.1.2 // indirect
106+
github.com/spf13/cast v1.3.0 // indirect
107+
github.com/spf13/cobra v1.0.0 // indirect
108+
github.com/spf13/jwalterweatherman v1.0.0 // indirect
109+
github.com/spf13/pflag v1.0.5 // indirect
110+
github.com/spf13/viper v1.7.1 // indirect
111+
github.com/subosito/gotenv v1.2.0 // indirect
112+
github.com/tcnksm/go-gitconfig v0.1.2 // indirect
76113
github.com/tklauser/go-sysconf v0.3.15 // indirect
77114
github.com/tklauser/numcpus v0.10.0 // indirect
115+
github.com/ulikunitz/xz v0.5.9 // indirect
78116
github.com/xdg-go/pbkdf2 v1.0.0 // indirect
79117
github.com/xdg-go/scram v1.1.2 // indirect
80118
github.com/xdg-go/stringprep v1.0.4 // indirect
@@ -88,12 +126,16 @@ require (
88126
go.opentelemetry.io/otel/trace v1.35.0 // indirect
89127
go.opentelemetry.io/proto/otlp v1.0.0 // indirect
90128
golang.org/x/crypto v0.37.0 // indirect
91-
golang.org/x/net v0.33.0 // indirect
129+
golang.org/x/net v0.36.0 // indirect
130+
golang.org/x/oauth2 v0.0.0-20190604053449-0f29369cfe45 // indirect
92131
golang.org/x/sync v0.13.0 // indirect
93132
golang.org/x/sys v0.32.0 // indirect
94133
golang.org/x/text v0.24.0 // indirect
134+
google.golang.org/appengine v1.6.1 // indirect
95135
google.golang.org/genproto/googleapis/api v0.0.0-20231120223509-83a465c0220f // indirect
96136
google.golang.org/genproto/googleapis/rpc v0.0.0-20240401170217-c3f982113cda // indirect
97137
google.golang.org/protobuf v1.35.2 // indirect
138+
gopkg.in/ini.v1 v1.60.1 // indirect
139+
gopkg.in/yaml.v2 v2.3.0 // indirect
98140
gopkg.in/yaml.v3 v3.0.1 // indirect
99141
)

0 commit comments

Comments
 (0)