Skip to content

fix(deps): vuln golang.org/x/net (unstable → v0.52.0) [tests]#3911

Closed
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/unstable/go/tests/2-1775088789
Closed

fix(deps): vuln golang.org/x/net (unstable → v0.52.0) [tests]#3911
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/unstable/go/tests/2-1775088789

Conversation

@gh-worker-campaigns-3e9aa4
Copy link
Copy Markdown

Summary: Security update — 1 package upgraded (UNSTABLE changes included)

Manifests changed:

  • tests (go)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Vulnerabilities Fixed
golang.org/x/net v0.36.0 v0.52.0 unstable 4 MODERATE, 1 UNKNOWN

Security Details

ℹ️ Other Vulnerabilities (5)
Package CVE Severity Summary Unsafe Version Fixed In
golang.org/x/net GO-2026-4440 MODERATE Quadratic parsing complexity in golang.org/x/net/html v0.36.0 0.45.0
golang.org/x/net GHSA-w4gw-w5jq-g9jh MODERATE golang.org/x/net/html has a Quadratic Parsing Complexity issue v0.36.0 -
golang.org/x/net GHSA-vvgc-356p-c3xw MODERATE golang.org/x/net vulnerable to Cross-site Scripting v0.36.0 0.38.0
golang.org/x/net GO-2025-3595 MODERATE Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net v0.36.0 0.38.0
golang.org/x/net GO-2026-4441 unknown Infinite parsing loop in golang.org/x/net v0.36.0 0.45.0

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: Vulnerability Remediation

🤖 Generated by DataDog Automated Dependency Management System

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 2, 2026

This PR has been automatically marked as stale because it has not had activity in the last 30 days.
If there is no activity for another 90 days, this issue will be automatically closed.

@github-actions github-actions Bot added the stale Stale - Bot reminder label May 2, 2026
@gh-worker-campaigns-3e9aa4 gh-worker-campaigns-3e9aa4 Bot deleted the engraver-auto-version-upgrade/unstable/go/tests/2-1775088789 branch May 3, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants