Skip to content

Backport of security: Upgrade crypto, oauth, go-jose into release/1.20.x#22208

Merged
abhishek-hashicorp merged 4 commits intorelease/1.20.xfrom
backport/abhishek/fix-vul/heartily-hip-woodcock
Mar 6, 2025
Merged

Backport of security: Upgrade crypto, oauth, go-jose into release/1.20.x#22208
abhishek-hashicorp merged 4 commits intorelease/1.20.xfrom
backport/abhishek/fix-vul/heartily-hip-woodcock

Conversation

@hc-github-team-consul-core
Copy link
Copy Markdown
Collaborator

Backport

This PR is auto-generated from #22207 to be assessed for backporting due to the inclusion of the label backport/1.20.

The below text is copied from the body of the original PR.


Description

Upgraded the following versions

  • golang.org/x/crypto to v0.35.0
  • golang.org/x/oauth2 to v0.27.0
  • github.com/go-jose/go-jose/v3 to v3.0.4

Testing & Reproduction steps

Links

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

@github-actions github-actions bot added the pr/dependencies PR specifically updates dependencies of project label Mar 6, 2025
@abhishek-hashicorp abhishek-hashicorp merged commit 11e4254 into release/1.20.x Mar 6, 2025
101 of 103 checks passed
@abhishek-hashicorp abhishek-hashicorp deleted the backport/abhishek/fix-vul/heartily-hip-woodcock branch March 6, 2025 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr/dependencies PR specifically updates dependencies of project

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants