Skip to content

chore(go-git): bump to v5.18.0 to address vulnerability#4330

Merged
josephwoodward merged 1 commit intomainfrom
jw/bump-go-git
Apr 23, 2026
Merged

chore(go-git): bump to v5.18.0 to address vulnerability#4330
josephwoodward merged 1 commit intomainfrom
jw/bump-go-git

Conversation

@josephwoodward
Copy link
Copy Markdown
Contributor

@claude
Copy link
Copy Markdown

claude Bot commented Apr 23, 2026

Commits
LGTM

Review
Straightforward dependency bump of github.com/go-git/go-git/v5 from v5.17.2 to v5.18.0 to address SNYK-GOLANG-GITHUBCOMGOGITGOGITV5PLUMBINGTRANSPORTHTTP-16109639. The library is used by internal/impl/git/input.go; v5.18.0 is a minor release with no breaking changes to the APIs used (plumbing, plumbing/transport, plumbing/transport/http, plumbing/transport/ssh).

LGTM

@josephwoodward josephwoodward merged commit 271639c into main Apr 23, 2026
7 checks passed
@josephwoodward josephwoodward deleted the jw/bump-go-git branch April 23, 2026 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants