chore(deps): update module github.com/moby/spdystream to v0.5.1 - #211
chore(deps): update module github.com/moby/spdystream to v0.5.1#211red-hat-konflux[bot] wants to merge 1 commit into
Conversation
5013a85 to
c7e6003
Compare
c7e6003 to
584d85e
Compare
584d85e to
af2c49c
Compare
af2c49c to
6e5ed4e
Compare
6e5ed4e to
60b5a21
Compare
|
🤖 Finished Review · ✅ Success · Started 10:40 PM UTC · Completed 10:45 PM UTC |
Review — PR #211Verdict: Approve SummaryThis PR bumps the indirect dependency Analysis
FindingsNo findings. This is a straightforward, security-motivated dependency patch bump with no behavioral risk. Previous runLooks good to me Previous run (2)Looks good to me |
3ddabee to
c1c58e2
Compare
|
🤖 Finished Review · ✅ Success · Started 6:47 AM UTC · Completed 6:51 AM UTC |
c1c58e2 to
0f63924
Compare
|
🤖 Finished Review · ❌ Failure · Started 5:28 AM UTC · Completed 5:29 AM UTC |
|
🤖 Finished Review · ✅ Success · Started 9:37 PM UTC · Completed 9:40 PM UTC |
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
This PR contains the following updates:
v0.5.0→v0.5.1Release Notes
moby/spdystream (github.com/moby/spdystream)
v0.5.1Compare Source
What's Changed
Security
Fix memory amplification in SPDY frame parsing leads to denial of service (CVE-2026-35469 / GHSA-pc3f-x583-g7j2)
Changes
Full Changelog: moby/spdystream@v0.5.0...v0.5.1
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.