Skip to content

Commit 5eec9da

Browse files
authored
Bump golang.org/x/net to v0.53.0 (#5242)
## Summary Clears CVE-2026-33814 (HTTP/2 `SETTINGS_MAX_FRAME_SIZE` infinite loop) flagged by govulncheck against `golang.org/x/net@v0.52.0`. Reachable via the Google API transport that the SDK's ID-token credential installs on `http.Client`. This pull request and its description were written by Isaac.
1 parent 9c11d5d commit 5eec9da

2 files changed

Lines changed: 3 additions & 3 deletions

File tree

go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -98,7 +98,7 @@ require (
9898
go.opentelemetry.io/otel/metric v1.43.0 // indirect
9999
go.opentelemetry.io/otel/trace v1.43.0 // indirect
100100
golang.org/x/exp v0.0.0-20240222234643-814bf88cf225 // indirect
101-
golang.org/x/net v0.52.0 // indirect
101+
golang.org/x/net v0.53.0 // indirect
102102
golang.org/x/time v0.14.0 // indirect
103103
google.golang.org/api v0.265.0 // indirect
104104
google.golang.org/genproto/googleapis/rpc v0.0.0-20260203192932-546029d2fa20 // indirect

go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -247,8 +247,8 @@ golang.org/x/exp v0.0.0-20240222234643-814bf88cf225 h1:LfspQV/FYTatPTr/3HzIcmiUF
247247
golang.org/x/exp v0.0.0-20240222234643-814bf88cf225/go.mod h1:CxmFvTBINI24O/j8iY7H1xHzx2i4OsyguNBmN/uPtqc=
248248
golang.org/x/mod v0.35.0 h1:Ww1D637e6Pg+Zb2KrWfHQUnH2dQRLBQyAtpr/haaJeM=
249249
golang.org/x/mod v0.35.0/go.mod h1:+GwiRhIInF8wPm+4AoT6L0FA1QWAad3OMdTRx4tFYlU=
250-
golang.org/x/net v0.52.0 h1:He/TN1l0e4mmR3QqHMT2Xab3Aj3L9qjbhRm78/6jrW0=
251-
golang.org/x/net v0.52.0/go.mod h1:R1MAz7uMZxVMualyPXb+VaqGSa3LIaUqk0eEt3w36Sw=
250+
golang.org/x/net v0.53.0 h1:d+qAbo5L0orcWAr0a9JweQpjXF19LMXJE8Ey7hwOdUA=
251+
golang.org/x/net v0.53.0/go.mod h1:JvMuJH7rrdiCfbeHoo3fCQU24Lf5JJwT9W3sJFulfgs=
252252
golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
253253
golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q=
254254
golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4=

0 commit comments

Comments
 (0)