Skip to content

Update golang.org/x/net dependency#82

Merged
zhengchun merged 1 commit intoantchfx:masterfrom
rhmdnd:update-deps
Jul 15, 2022
Merged

Update golang.org/x/net dependency#82
zhengchun merged 1 commit intoantchfx:masterfrom
rhmdnd:update-deps

Conversation

@rhmdnd
Copy link
Copy Markdown
Contributor

@rhmdnd rhmdnd commented Jul 14, 2022

xmlquery has a transitive dependency on golang.org/x/text/languages
through golang.org/x/net. It's recommended to use newer versions of
x/text/languages [0].

This commit updates the golang.org/x/net dependency to the version that
includes golang.org/x/text version 0.3.7 [1], per vulnerabiltiy guidance.

[0] https://pkg.go.dev/vuln/GO-2021-0113
[1] https://cs.opensource.google/go/x/net/+/cd36cc0744dd695657988f15f08446dc81e16efc:go.mod

xmlquery has a transitive dependency on golang.org/x/text/languages
through golang.org/x/net. It's recommended to use newer versions of
x/text/languages [0].

This commit updates the golang.org/x/net dependency to the version that
includes golang.org/x/text version 0.3.7 [1], per vulnerabiltiy guidance.

[0] https://pkg.go.dev/vuln/GO-2021-0113
[1] https://cs.opensource.google/go/x/net/+/cd36cc0744dd695657988f15f08446dc81e16efc:go.mod
@rhmdnd
Copy link
Copy Markdown
Contributor Author

rhmdnd commented Jul 14, 2022

Note that the vulnerability suggests 0.3.7 is susceptible [0], but the version list for x/text doesn't list 0.3.7 as impacted.

[0] https://pkg.go.dev/vuln/GO-2021-0113
[1] https://pkg.go.dev/golang.org/x/text/language?tab=versions

@zhengchun zhengchun merged commit b7a095a into antchfx:master Jul 15, 2022
@rhmdnd
Copy link
Copy Markdown
Contributor Author

rhmdnd commented Jul 15, 2022

@zhengchun thanks for the review. Do you have a release on the horizon? If not, I can wait, just curious is all.

@zhengchun
Copy link
Copy Markdown
Contributor

@rhmdnd , see https://github.com/antchfx/xmlquery/releases/tag/v1.3.12

rhmdnd added a commit to rhmdnd/compliance-operator-archive that referenced this pull request Aug 1, 2022
A new version was recently made available that addresses a potential
security issues with x/text/languages.

https://github.com/antchfx/xmlquery/releases/tag/v1.3.12
antchfx/xmlquery#82

This commit updates the dependency on xmlquery to address the security
concerns in x/text/languages.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants