Skip to content

Conversation

@jbradforddillon
Copy link
Contributor

@jbradforddillon jbradforddillon commented Jan 22, 2026

Summary

  • Updates golang.org/x/net from v0.34.0 to v0.38.0 to address Dependabot security alerts
  • Fixes CVE for HTTP Proxy bypass using IPv6 Zone IDs (medium severity)
  • Fixes CVE for Cross-site Scripting vulnerability (medium severity)

Also updates related dependencies:

  • golang.org/x/sys v0.29.0 → v0.31.0
  • golang.org/x/text v0.21.0 → v0.23.0

Test plan

  • go mod tidy runs without errors
  • go test ./... passes

🤖 Generated with Claude Code


Note

Dependency updates

  • Bumps golang.org/x/net v0.34.0v0.38.0 (addresses security advisories)
  • Updates golang.org/x/sys v0.29.0v0.31.0 and golang.org/x/text v0.21.0v0.23.0
  • Refreshes go.sum; no production code changes

Written by Cursor Bugbot for commit ee78d2a. This will update automatically on new commits. Configure here.

Addresses Dependabot security alerts:
- CVE for HTTP Proxy bypass using IPv6 Zone IDs (medium)
- CVE for Cross-site Scripting vulnerability (medium)

Also updates related dependencies:
- golang.org/x/sys v0.29.0 → v0.31.0
- golang.org/x/text v0.21.0 → v0.23.0

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@erikist erikist merged commit 893e7bc into main Jan 22, 2026
11 checks passed
@jbradforddillon jbradforddillon deleted the jbradforddillon/fix-dependabot-vulns branch January 22, 2026 21:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants