Skip to content

build(deps): upgrade golang.org/x/sys to v0.45.0#33

Merged
flexiondotorg merged 1 commit into
mainfrom
sec-fix
Jun 6, 2026
Merged

build(deps): upgrade golang.org/x/sys to v0.45.0#33
flexiondotorg merged 1 commit into
mainfrom
sec-fix

Conversation

@flexiondotorg
Copy link
Copy Markdown
Contributor

Fixes CVE-2026-39824 (integer overflow in NewNTUnicodeString) Closes GO-2026-5024

Fixes CVE-2026-39824 (integer overflow in NewNTUnicodeString)
Closes GO-2026-5024

Signed-off-by: Martin Wimpress <code@wimpress.io>
Copy link
Copy Markdown

@cubic-dev-ai cubic-dev-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Auto-approved: This PR updates only the indirect dependency golang.org/x/sys from v0.38.0 to v0.45.0 in go.mod and go.sum to fix a security vulnerability, with no changes to application logic, making it a low-risk dependency bump.

Re-trigger cubic

@flexiondotorg flexiondotorg merged commit 5ef67e1 into main Jun 6, 2026
12 checks passed
@flexiondotorg flexiondotorg deleted the sec-fix branch June 6, 2026 10:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant