Skip to content

Bump golang.org/x/net from 0.28.0 to 0.31.0#1622

Merged
miekg merged 1 commit intomasterfrom
dependabot/go_modules/golang.org/x/net-0.31.0
Jan 24, 2025
Merged

Bump golang.org/x/net from 0.28.0 to 0.31.0#1622
miekg merged 1 commit intomasterfrom
dependabot/go_modules/golang.org/x/net-0.31.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Dec 1, 2024

Bumps golang.org/x/net from 0.28.0 to 0.31.0.

Commits
  • 334afa0 go.mod: update golang.org/x dependencies
  • d7f220d quic: add LocalAddr and RemoteAddr to quic.Conn
  • 858db1a http2: surface errors occurring very early in a client conn's lifetime
  • 0aa844c http2: support unencrypted HTTP/2 handoff from net/http
  • f35fec9 http2: detect hung client connections by confirming stream resets
  • e883dae README: don't recommend go get
  • 511cc3a html: add Node.{Ancestors,ChildNodes,Descendants}()
  • 4783315 http2: limit 1xx based on size, do not limit when delivered
  • 5716b98 internal/socket: execute gofmt
  • 42b1186 http2: support ResponseController.EnableFullDuplex
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [golang.org/x/net](https://github.com/golang/net) from 0.28.0 to 0.31.0.
- [Commits](golang/net@v0.28.0...v0.31.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Dec 1, 2024
@dependabot dependabot Bot requested review from miekg and tmthrgd as code owners December 1, 2024 17:20
@weppos
Copy link
Copy Markdown

weppos commented Dec 19, 2024

golang.org/x/net versions < 0.33.0 are affected by a new vulnerability recently disclosed as CVE-2024-45338, and fixed in 0.33.0.

While this is not directly affecting this lib, I would kindly request if you can upgrade the dependency as any project using miekg/dns is currently locked to a non-patched version by indirect version lock.

I was going to create a PR, but I see there's already this dependabot update that could be rebased without creating more tickets. Let me know if you want be to provide a PR instead.

Thanks!

@miekg miekg merged commit fb0c220 into master Jan 24, 2025
@miekg miekg deleted the dependabot/go_modules/golang.org/x/net-0.31.0 branch January 24, 2025 10:34
baest pushed a commit to baest/dns that referenced this pull request Mar 5, 2025
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.28.0 to 0.31.0.
- [Commits](golang/net@v0.28.0...v0.31.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants