Skip to content

Update golang.org/x/net to v0.39.0#1514

Merged
sondavidb merged 1 commit into
awslabs:mainfrom
sondavidb:fix-cve-go-2025-3595
Apr 17, 2025
Merged

Update golang.org/x/net to v0.39.0#1514
sondavidb merged 1 commit into
awslabs:mainfrom
sondavidb:fix-cve-go-2025-3595

Conversation

@sondavidb
Copy link
Copy Markdown
Contributor

This is a manual dependency bump to patch CVE GO-2025-3595, since our automated script doesn't auto-bump indirect dependencies.

https://pkg.go.dev/vuln/GO-2025-3595

Issue #, if available:

Description of changes:

Testing performed:

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@sondavidb sondavidb requested a review from a team as a code owner April 16, 2025 19:08
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Apr 16, 2025
This is a manual dependency bump to patch CVE GO-2025-3595, since our
automated script doesn't auto-bump indirect dependencies.

https://pkg.go.dev/vuln/GO-2025-3595

Signed-off-by: David Son <davbson@amazon.com>
@sondavidb sondavidb force-pushed the fix-cve-go-2025-3595 branch from 591ac4b to 6b10697 Compare April 17, 2025 16:57
@sondavidb
Copy link
Copy Markdown
Contributor Author

Rebased with mainline to update CI

@sondavidb sondavidb merged commit 575576d into awslabs:main Apr 17, 2025
18 checks passed
@sondavidb sondavidb deleted the fix-cve-go-2025-3595 branch April 17, 2025 20:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants