Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade golang.org/x/net to v0.17.0 (CVE-2023-44487) #680

Closed
maysunfaisal opened this issue Oct 31, 2023 · 1 comment
Closed

Upgrade golang.org/x/net to v0.17.0 (CVE-2023-44487) #680

maysunfaisal opened this issue Oct 31, 2023 · 1 comment

Comments

@maysunfaisal
Copy link

I noticed that #674 to upgrade golang.org/x/net to v0.17.0 was closed without any reason provided.

The golang.org/x/net version should be upgraded to v0.17.0 to mitigate CVE-2023-44487 and either have a new patch or a new release of golang.org/x/oauth2 with this update.

@rolandshoemaker
Copy link
Member

rolandshoemaker commented Oct 31, 2023

We don't accept PRs via the GitHub UI for the golang.org/x/oauth2 repository, so all PRs are automatically closed (additionally, I thought we'd disabled dependabot for this repository).

oauth2 doesn't actually using golang.org/x/net/http2 directly, so it isn't impacted, and we typically don't do dependency updates in these cases since they cause unnecessary churn. This repository, along with most of the golang.org/x/ repos are automatically tagged on a ~monthly basis, so at some point in the future this will magically disappear.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants