← Back to issue list

fix(deps): update module golang.org/x/net to v0.23.0 [security]

View original Github issue

Metadata

Project
fetch-service
Number
#86
Type
pull request
State
merged
Author
renovate[bot]
Labels
Created
Updated
Closed

Current evaluation

Merged security update for golang.org/x/net to v0.23.0, addressing CVE-2023-45288. Automated by Renovate bot, approved by two reviewers, passed CI checks, and merged into main.

Suggested action:

No scores available.

Issue body

[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | golang.org/x/net | `v0.22.0` -> `v0.23.0` | [![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fnet/v0.23.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/golang.org%2fx%2fnet/v0.23.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/golang.org%2fx%2fnet/v0.22.0/v0.23.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fnet/v0.22.0/v0.23.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | ### GitHub Vulnerability Alerts #### [CVE-2023-45288](https://nvd.nist.gov/vuln/detail/CVE-2023-45288) An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection. --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/fetch-service). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4zMDEuNCIsInVwZGF0ZWRJblZlciI6IjM3LjMwMS40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged security update for golang.org/x/net to v0.23.0, addressing CVE-2023-45288. Automated by Renovate bot, approved by two reviewers, passed CI checks, and merged into main.

Update history

Date Change
created

Related issues

Issue Project State Summary Similarity
#471 fix(deps): update module golang.org/x/net to v0.46.0 fetch-service merged Merged automated dependency update for golang.org/x/net from v0.45.0 to v0.46.0. Approved by two reviewers, passed all CI checks, and merged via Renovate bot.
91%
#318 fix(deps): update module golang.org/x/net to v0.33.0 [security] fetch-service merged Merged automated update to golang.org/x/net v0.33.0, patching CVE-2024-45338 denial-of-service vulnerability. Also updated golang.org/x/crypto, golang.org/x/sys, and golang.org/x/text. Approved by reviewers and passed CI.
90%
#611 fix(deps): update module golang.org/x/net to v0.55.0 fetch-service merged Merged an automated dependency update from Renovate. The golang.org/x/net module was upgraded from v0.54.0 to v0.55.0. The change passed CI checks and received two approvals before merging into the main branch.
89%
#436 fix(deps): update module golang.org/x/net to v0.43.0 fetch-service merged Merged automated dependency update upgrading golang.org/x/net to v0.43.0, alongside transitive bumps to crypto, sys, and text modules. Approved by two reviewers and merged after passing core CI checks.
89%
#118 fix(deps): update module golang.org/x/net to v0.26.0 fetch-service merged Merged automated dependency update. Upgraded golang.org/x/net to v0.26.0, automatically updating golang.org/x/crypto to v0.24.0 and golang.org/x/sys to v0.21.0. PR passed CI checks and received two approvals before merging.
88%
#321 fix(deps): update module golang.org/x/net to v0.35.0 fetch-service merged Merged automated dependency update upgrading golang.org/x/net to v0.35.0. Transitive dependencies golang.org/x/crypto, golang.org/x/sys, and golang.org/x/text were also updated. Approved by two reviewers and passed CI checks prior to merge.
88%
#406 fix(deps): update module golang.org/x/net to v0.42.0 fetch-service merged Merged automated dependency update for golang.org/x/net from v0.41.0 to v0.42.0. Approved by two reviewers and passed all CI checks. Two files modified.
88%
#569 fix(deps): update module golang.org/x/net to v0.53.0 fetch-service merged Merged automated dependency update for golang.org/x/net to v0.53.0. go get also updated golang.org/x/crypto, golang.org/x/sys, and golang.org/x/text. Approved by two reviewers and passed all CI checks before manual merge.
88%
#138 fix(deps): update module golang.org/x/net to v0.27.0 fetch-service merged Merged automated dependency update upgrading golang.org/x/net to v0.27.0. Transitive updates also applied for golang.org/x/crypto to v0.25.0 and golang.org/x/sys to v0.22.0. Approved by reviewers and passed CI checks.
88%
#468 fix(deps): update module golang.org/x/net to v0.45.0 fetch-service merged Merged automated dependency update. Upgraded golang.org/x/net to v0.45.0, which also updated golang.org/x/crypto, golang.org/x/sys, and golang.org/x/text. Approved by two reviewers and passed all CI checks.
88%