Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): Update module github.com/hashicorp/go-retryablehttp to v0.7.7 [SECURITY] #1774

Merged

Conversation

cq-bot
Copy link
Contributor

@cq-bot cq-bot commented Jun 24, 2024

This PR contains the following updates:

Package Type Update Change
github.com/hashicorp/go-retryablehttp indirect patch v0.7.5 -> v0.7.7

GitHub Vulnerability Alerts

CVE-2024-6104

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.


Release Notes

hashicorp/go-retryablehttp (github.com/hashicorp/go-retryablehttp)

v0.7.7

Compare Source

v0.7.6

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@github-actions github-actions bot added the fix label Jun 24, 2024
@kodiakhq kodiakhq bot merged commit e5e8e7e into main Jun 24, 2024
9 checks passed
@kodiakhq kodiakhq bot deleted the renovate/go-github.com/hashicorp/go-retryablehttp-vulnerability branch June 24, 2024 22:28
Copy link

github-actions bot commented Jun 24, 2024

⏱️ Benchmark results

  • Glob-8 ns/op: 91.46

kodiakhq bot pushed a commit that referenced this pull request Jun 27, 2024
🤖 I have created a release *beep* *boop*
---


## [4.49.0](v4.48.0...v4.49.0) (2024-06-27)


### Features

* Better OTEL traces, add metrics ([#1751](#1751)) ([874c33a](874c33a))


### Bug Fixes

* **deps:** Update module github.com/hashicorp/go-retryablehttp to v0.7.7 [SECURITY] ([#1774](#1774)) ([e5e8e7e](e5e8e7e))

---
This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant