← Back to issue list

fix(deps): update module golang.org/x/net to v0.38.0 [security] - autoclosed

View original Github issue

Metadata

Project
fetch-service
Number
#359
Type
pull request
State
closed
Author
renovate[bot]
Labels
Created
Updated
Closed

Current evaluation

Renovate autoclosed the dependency update after failing to refresh go.sum due to disabled checksum verification. The security patch was abandoned and never merged.

Suggested action:

No scores available.

Issue body

This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | golang.org/x/net | `v0.35.0` -> `v0.38.0` | [![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fnet/v0.38.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/golang.org%2fx%2fnet/v0.38.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/golang.org%2fx%2fnet/v0.35.0/v0.38.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fnet/v0.35.0/v0.38.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | ### GitHub Vulnerability Alerts #### [CVE-2025-22870](https://nvd.nist.gov/vuln/detail/CVE-2025-22870) Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied. #### [CVE-2025-22872](https://nvd.nist.gov/vuln/detail/CVE-2025-22872) The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. <math>, <svg>, etc contexts). --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/fetch-service). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS4xOTQuMSIsInVwZGF0ZWRJblZlciI6IjM5LjIzOC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Renovate autoclosed the dependency update after failing to refresh go.sum due to disabled checksum verification. The security patch was abandoned and never merged.

Update history

Date Change
created

Related issues

Issue Project State Summary Similarity
#352 fix(deps): update module golang.org/x/net to v0.37.0 - autoclosed fetch-service closed Renovate automatically closed the dependency update for golang.org/x/net v0.37.0 without merging. The branch was abandoned and changes were not applied to the repository.
89%
#506 fix(deps): update module golang.org/x/net to v0.47.0 - autoclosed fetch-service closed The dependency update PR was autoclosed and abandoned without merging. Renovate automatically closed it due to inactivity and a failing OSV-scanner CI check. The golang.org/x/net update to v0.47.0 was not applied.
89%
#70 fix(deps): update module golang.org/x/net to v0.24.0 - autoclosed fetch-service closed Autoclosed by Renovate. The dependency update for golang.org/x/net to v0.24.0 was superseded or abandoned. No merge occurred.
88%
#287 fix(deps): update module golang.org/x/net to v0.33.0 - autoclosed fetch-service closed Renovate PR updating golang.org/x/net to v0.33.0 was autoclosed due to inactivity. The branch was never merged and the update was abandoned.
87%
#609 fix(deps): update module golang.org/x/sys to v0.45.0 - autoclosed fetch-service closed Renovate autoclosed the golang.org/x/sys update to v0.45.0 due to inactivity. The request was abandoned and never merged or reviewed.
85%
#639 fix(deps): update module golang.org/x/crypto to v0.55.0 - autoclosed fetch-service closed Dependency update PR for golang.org/x/crypto to v0.55.0 was abandoned and autoclosed without merging. Renovate automatically closed it after the OSV scanner check failed. Transitive dependencies were also updated.
85%
#86 fix(deps): update module golang.org/x/net to v0.23.0 [security] fetch-service merged Merged security update for golang.org/x/net to v0.23.0, addressing CVE-2023-45288. Automated by Renovate bot, approved by two reviewers, passed CI checks, and merged into main.
84%
#618 fix(deps): update module golang.org/x/sys to v0.46.0 - autoclosed fetch-service closed Autoclosed by Renovate due to inactivity. The dependency update for golang.org/x/sys to v0.46.0 was not merged. CI checks included failing snap tests on jammy and noble architectures.
84%
#318 fix(deps): update module golang.org/x/net to v0.33.0 [security] fetch-service merged Merged automated update to golang.org/x/net v0.33.0, patching CVE-2024-45338 denial-of-service vulnerability. Also updated golang.org/x/crypto, golang.org/x/sys, and golang.org/x/text. Approved by reviewers and passed CI.
84%
#435 fix(deps): update module golang.org/x/crypto to v0.41.0 - autoclosed fetch-service closed Renovate automatically closed this dependency update for golang.org/x/crypto to v0.41.0. Despite approval and passing CI checks, the pull request was autoclosed, indicating it was superseded or abandoned.
83%