Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Jul 26, 2025

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/oauth2 v0.16.0v0.27.0 age confidence

GitHub Vulnerability Alerts

CVE-2025-22868

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the security label Jul 26, 2025
@renovate renovate bot requested a review from pyshx as a code owner July 26, 2025 07:59
@renovate renovate bot added the security label Jul 26, 2025
@netlify
Copy link

netlify bot commented Jul 26, 2025

Deploy Preview for reearth-classic canceled.

Name Link
🔨 Latest commit a2511e0
🔍 Latest deploy log https://app.netlify.com/projects/reearth-classic/deploys/68848ad6569cea0008f9212b

@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from a2511e0 to 46da9ea Compare September 26, 2025 00:04
@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 3 times, most recently from 40caab9 to 236b534 Compare November 27, 2025 08:20
@renovate renovate bot requested a review from soneda-yuya as a code owner November 27, 2025 08:20
@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 7 times, most recently from 9666e5f to 773db44 Compare December 5, 2025 06:16
@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 773db44 to acc60b5 Compare December 19, 2025 01:46
@renovate renovate bot changed the title chore: update module golang.org/x/oauth2 to v0.27.0 [security] chore: update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosed Dec 24, 2025
@renovate renovate bot closed this Dec 24, 2025
@renovate renovate bot deleted the renovate/go-golang.org-x-oauth2-vulnerability branch December 24, 2025 05:59
@renovate renovate bot changed the title chore: update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosed chore: update module golang.org/x/oauth2 to v0.27.0 [security] Dec 25, 2025
@renovate renovate bot reopened this Dec 25, 2025
@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from ca4b7cd to acc60b5 Compare December 25, 2025 06:47
@renovate
Copy link
Author

renovate bot commented Dec 25, 2025

ℹ️ Artifact update notice

File name: server/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
cloud.google.com/go/compute/metadata v0.2.3 -> v0.3.0
go 1.21 -> 1.23.0
go (toolchain) 1.21.0 -> 1.24.11

@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from acc60b5 to ca4b7cd Compare December 25, 2025 06:47
@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from ca4b7cd to b4a56ef Compare January 7, 2026 04:51
@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from b4a56ef to 505ef3f Compare January 8, 2026 01:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant