Skip to content

build(deps): update module golang.org/x/net to v0.51.0 [security] - autoclosed#1270

Closed
renovate-sh-app[bot] wants to merge 1 commit intomainfrom
renovate/go-golang.org-x-net-vulnerability
Closed

build(deps): update module golang.org/x/net to v0.51.0 [security] - autoclosed#1270
renovate-sh-app[bot] wants to merge 1 commit intomainfrom
renovate/go-golang.org-x-net-vulnerability

Conversation

@renovate-sh-app
Copy link
Copy Markdown
Contributor

@renovate-sh-app renovate-sh-app bot commented Feb 27, 2026

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/net v0.50.0v0.51.0 age confidence

Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net

CVE-2026-27141 / GO-2026-4559

More information

Details

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Need help?

You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

@renovate-sh-app renovate-sh-app bot requested a review from a team as a code owner February 27, 2026 18:14
@renovate-sh-app renovate-sh-app bot enabled auto-merge (squash) February 27, 2026 18:14
@renovate-sh-app renovate-sh-app bot changed the title build(deps): update module golang.org/x/net to v0.51.0 [security] build(deps): update module golang.org/x/net to v0.51.0 [security] - autoclosed Mar 4, 2026
@renovate-sh-app renovate-sh-app bot closed this Mar 4, 2026
auto-merge was automatically disabled March 4, 2026 12:11

Pull request was closed

@renovate-sh-app renovate-sh-app bot deleted the renovate/go-golang.org-x-net-vulnerability branch March 4, 2026 12:11
| datasource | package          | from    | to      |
| ---------- | ---------------- | ------- | ------- |
| go         | golang.org/x/net | v0.50.0 | v0.51.0 |


Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@renovate-sh-app renovate-sh-app bot changed the title build(deps): update module golang.org/x/net to v0.51.0 [security] - autoclosed build(deps): update module golang.org/x/net to v0.51.0 [security] Mar 4, 2026
@renovate-sh-app renovate-sh-app bot reopened this Mar 4, 2026
@renovate-sh-app renovate-sh-app bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch 2 times, most recently from 337d2c6 to 4410394 Compare March 4, 2026 15:36
@renovate-sh-app renovate-sh-app bot changed the title build(deps): update module golang.org/x/net to v0.51.0 [security] build(deps): update module golang.org/x/net to v0.51.0 [security] - autoclosed Mar 13, 2026
@renovate-sh-app renovate-sh-app bot closed this Mar 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants