chore: bump golang.org/x/oauth2 to v0.27.0#2490
Conversation
Update golang.org/x/oauth2 dependency to v0.27.0, which removes deprecated App Engine support and the google.golang.org/appengine dependency. Fix GitLab provider test mocks to URL-encode file paths, matching the go-gitlab library behavior exposed by the oauth2 update. Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com> Signed-off-by: Akshay Pant <akshay.akshaypant@gmail.com>
Summary of ChangesHello @theakshaypant, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request focuses on a significant dependency upgrade for Highlights
Changelog
Activity
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request updates the golang.org/x/oauth2 dependency to v0.27.0, removes the deprecated google.golang.org/appengine dependency, and updates the Go module version to 1.23.0. These changes address a security vulnerability (GHSA-6v2p-p543-phr9) and a path traversal vulnerability in a GitLab test utility function, which is fixed by correctly URL-encoding the filename. The updates enhance the overall security of the codebase and are well-contained.
| encodedFname := url.PathEscape(fname) | ||
| mux.HandleFunc(fmt.Sprintf("/projects/%d/repository/files/%s/raw", pid, encodedFname), func(rw http.ResponseWriter, _ *http.Request) { |
There was a problem hiding this comment.
This change correctly addresses a potential path traversal vulnerability. The previous implementation did not sanitize the fname parameter before using it to construct a URL path for the mock server, which could allow a malicious filename (e.g., ../../etc/passwd) to traverse the directory structure. By using url.PathEscape, the filename is now properly sanitized, preventing this vulnerability. This is an excellent security improvement.
|
Closing this for now. |
📝 Description of the Change
Update golang.org/x/oauth2 dependency to v0.27.0, which removes deprecated App Engine support and the google.golang.org/appengine dependency.
Fix GitLab provider test mocks to URL-encode file paths, matching the go-gitlab library behavior exposed by the oauth2 update.
CVE fix for GHSA-6v2p-p543-phr9
Also pushed the the changes with
--no-verifysince the number of linting issue in this version are HUMONGOUS and take too long to fix all of them.Have run the unit tests locally and they all pass. Skipped the linters hook 👀
👨🏻 Linked Jira
N/A
🔗 Linked GitHub Issue
Fixes #
🚀 Type of Change
fix:)feat:)feat!:,fix!:)docs:)chore:)refactor:)enhance:)deps:)🧪 Testing Strategy
🤖 AI Assistance
If you have used AI assistance, please provide the following details:
Which LLM was used?
Extent of AI Assistance:
Important
If the majority of the code in this PR was generated by an AI, please add a
Co-authored-bytrailer to your commit message.For example:
Co-authored-by: Gemini gemini@google.com
Co-authored-by: ChatGPT noreply@chatgpt.com
Co-authored-by: Claude noreply@anthropic.com
Co-authored-by: Cursor noreply@cursor.com
Co-authored-by: Copilot Copilot@users.noreply.github.com
**💡You can use the script
./hack/add-llm-coauthor.shto automatically addthese co-author trailers to your commits.
✅ Submitter Checklist
fix:,feat:) matches the "Type of Change" I selected above.make testandmake lintlocally to check for and fix anyissues. For an efficient workflow, I have considered installing
pre-commit and running
pre-commit installtoautomate these checks.