Skip to content

chore(deps): update module golang.org/x/net to v0.38.0 [security] (v1.4) #3649

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Apr 22, 2025

Conversation

cilium-renovate[bot]
Copy link
Contributor

@cilium-renovate cilium-renovate bot commented Apr 17, 2025

This PR contains the following updates:

Package Type Update Change
golang.org/x/net indirect minor v0.36.0 -> v0.38.0

Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net

CVE-2025-22872 / GHSA-vvgc-356p-c3xw / GO-2025-3595

More information

Details

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. , , etc contexts).

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


golang.org/x/net vulnerable to Cross-site Scripting

CVE-2025-22872 / GHSA-vvgc-356p-c3xw / GO-2025-3595

More information

Details

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. , , etc contexts).

Severity

  • CVSS Score: Unknown
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

Signed-off-by: cilium-renovate[bot] <134692979+cilium-renovate[bot]@users.noreply.github.com>
@cilium-renovate cilium-renovate bot requested a review from a team as a code owner April 17, 2025 08:18
@cilium-renovate cilium-renovate bot added release-blocker This PR or issue is blocking the next release. release-note/dependency This PR updates one or multiple dependencies labels Apr 17, 2025
@cilium-renovate cilium-renovate bot requested review from tpapagian and removed request for a team April 17, 2025 08:18
@cilium-renovate
Copy link
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: undefined
Command failed: make protogen
go: downloading google.golang.org/protobuf v1.36.5
go: downloading google.golang.org/grpc v1.71.0
go: downloading github.com/google/go-cmp v0.7.0
go: downloading google.golang.org/genproto/googleapis/rpc v0.0.0-20250115164207-1a7da9e5054f
go: downloading go.opentelemetry.io/otel v1.34.0
go: downloading go.opentelemetry.io/otel/sdk/metric v1.34.0
go: downloading go.opentelemetry.io/otel/sdk v1.34.0
go: downloading go.opentelemetry.io/otel/metric v1.34.0
go: downloading go.opentelemetry.io/otel/trace v1.34.0
go: downloading go.opentelemetry.io/auto/sdk v1.1.0
Unable to find image 'quay.io/cilium/cilium-builder:cd04ac813fb4763f840911c88beae99efc4aa457' locally
cd04ac813fb4763f840911c88beae99efc4aa457: Pulling from cilium/cilium-builder
59103914d20e: Pulling fs layer
17d3e8f3d0bc: Pulling fs layer
41f150d063fd: Pulling fs layer
93c374f336b7: Pulling fs layer
4f4fb700ef54: Pulling fs layer
24d10d1252ef: Pulling fs layer
d7075edb03b9: Pulling fs layer
2ad3d6c432f9: Pulling fs layer
94c7ac5a7528: Pulling fs layer
a960d8d5112e: Pulling fs layer
be78cc0a6c06: Pulling fs layer
d353a3c8fe13: Pulling fs layer
3646095f617f: Pulling fs layer
93c374f336b7: Waiting
4f4fb700ef54: Waiting
24d10d1252ef: Waiting
94c7ac5a7528: Waiting
d7075edb03b9: Waiting
2ad3d6c432f9: Waiting
a960d8d5112e: Waiting
3646095f617f: Waiting
be78cc0a6c06: Waiting
d353a3c8fe13: Waiting
41f150d063fd: Verifying Checksum
41f150d063fd: Download complete
59103914d20e: Download complete
4f4fb700ef54: Verifying Checksum
4f4fb700ef54: Download complete
59103914d20e: Pull complete
93c374f336b7: Verifying Checksum
93c374f336b7: Download complete
24d10d1252ef: Verifying Checksum
24d10d1252ef: Download complete
d7075edb03b9: Download complete
2ad3d6c432f9: Verifying Checksum
2ad3d6c432f9: Download complete
94c7ac5a7528: Verifying Checksum
94c7ac5a7528: Download complete
a960d8d5112e: Verifying Checksum
a960d8d5112e: Download complete
d353a3c8fe13: Verifying Checksum
d353a3c8fe13: Download complete
17d3e8f3d0bc: Verifying Checksum
17d3e8f3d0bc: Download complete
3646095f617f: Verifying Checksum
3646095f617f: Download complete
be78cc0a6c06: Verifying Checksum
be78cc0a6c06: Download complete
17d3e8f3d0bc: Pull complete
41f150d063fd: Pull complete
93c374f336b7: Pull complete
4f4fb700ef54: Pull complete
24d10d1252ef: Pull complete
d7075edb03b9: Pull complete
2ad3d6c432f9: Pull complete
94c7ac5a7528: Pull complete
a960d8d5112e: Pull complete
be78cc0a6c06: Pull complete
d353a3c8fe13: Pull complete
3646095f617f: Pull complete
Digest: sha256:2e6761058af195ed75d52187fb15e80aefdefda47f91020b597349c1e251fca4
Status: Downloaded newer image for quay.io/cilium/cilium-builder:cd04ac813fb4763f840911c88beae99efc4aa457
make: *** [Makefile:30: __check-breaking_local] Error 100
make[1]: *** [Makefile:34: all] Error 2
make: *** [Makefile:384: protogen] Error 2

[ upstream commit 317f527 ]

This is to fix the error:
	This is a scheduled Ubuntu 20.04 brownout. Ubuntu 20.04 LTS
	runner will be removed on 2025-04-15. For more details, see
	actions/runner-images#11101

Signed-off-by: Mahe Tardy <[email protected]>
@mtardy mtardy self-assigned this Apr 22, 2025
@cilium-renovate
Copy link
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@mtardy mtardy merged commit 3beb758 into v1.4 Apr 22, 2025
44 checks passed
@mtardy mtardy deleted the renovate/v1.4-go-golang.org-x-net-vulnerability branch April 22, 2025 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
release-blocker This PR or issue is blocking the next release. release-note/dependency This PR updates one or multiple dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant