Skip to content

chore: update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosed - #93

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-oauth2-vulnerability
Closed

chore: update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosed#93
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-oauth2-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jul 26, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/oauth2 v0.16.0v0.27.0 age confidence

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

CVE-2025-22868 / GHSA-6v2p-p543-phr9

More information

Details

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the security label Jul 26, 2025
@renovate
renovate Bot requested a review from pyshx as a code owner July 26, 2025 07:59
@renovate renovate Bot added the security label Jul 26, 2025
@netlify

netlify Bot commented Jul 26, 2025

Copy link
Copy Markdown

Deploy Preview for reearth-classic canceled.

Name Link
🔨 Latest commit a2511e0
🔍 Latest deploy log https://app.netlify.com/projects/reearth-classic/deploys/68848ad6569cea0008f9212b

@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from a2511e0 to 46da9ea Compare September 26, 2025 00:04
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 3 times, most recently from 40caab9 to 236b534 Compare November 27, 2025 08:20
@renovate
renovate Bot requested a review from soneda-yuya as a code owner November 27, 2025 08:20
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 7 times, most recently from 9666e5f to 773db44 Compare December 5, 2025 06:16
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 773db44 to acc60b5 Compare December 19, 2025 01:46
@renovate renovate Bot changed the title chore: update module golang.org/x/oauth2 to v0.27.0 [security] chore: update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosed Dec 24, 2025
@renovate renovate Bot closed this Dec 24, 2025
@renovate
renovate Bot deleted the renovate/go-golang.org-x-oauth2-vulnerability branch December 24, 2025 05:59
@renovate renovate Bot changed the title chore: update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosed chore: update module golang.org/x/oauth2 to v0.27.0 [security] Dec 25, 2025
@renovate renovate Bot reopened this Dec 25, 2025
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from ca4b7cd to acc60b5 Compare December 25, 2025 06:47
@renovate

renovate Bot commented Dec 25, 2025

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: server/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
cloud.google.com/go/compute/metadata v0.2.3 -> v0.3.0

@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from acc60b5 to ca4b7cd Compare December 25, 2025 06:47
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from b4a56ef to 505ef3f Compare January 8, 2026 01:02
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from 1f966a6 to f8075af Compare January 20, 2026 06:43
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from f8075af to 6e9d606 Compare February 13, 2026 20:15
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 6e9d606 to 7940c22 Compare April 7, 2026 02:16
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from 3df4a92 to 0dda3e0 Compare May 19, 2026 06:51
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 0dda3e0 to d9378fd Compare May 19, 2026 07:22
@renovate renovate Bot changed the title chore: update module golang.org/x/oauth2 to v0.27.0 [security] chore: update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosed May 19, 2026
@renovate renovate Bot closed this May 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants