Skip to content

RED-208474: Update net and crypto packages for fixing flagged CVEs - #9

Merged
peperon merged 1 commit into
masterfrom
peperon_RED-208474-fix-cves
Jul 28, 2026
Merged

RED-208474: Update net and crypto packages for fixing flagged CVEs#9
peperon merged 1 commit into
masterfrom
peperon_RED-208474-fix-cves

Conversation

@peperon

@peperon peperon commented Jul 28, 2026

Copy link
Copy Markdown
Member

Update golang.org/x/net and golang.org/x/crypto for fixing flagged CVEs


Note

Low Risk
Lockfile-only indirect dependency upgrades with no code changes; typical low-risk security maintenance, with minor residual risk from transitive behavior changes in networking/crypto libraries.

Overview
Bumps indirect golang.org/x module versions in go.mod and go.sum to address flagged CVEs, with no application source changes.

golang.org/x/crypto goes from v0.49.0 to v0.52.0 and golang.org/x/net from v0.51.0 to v0.55.0 as the primary security-related updates. golang.org/x/sys (v0.42.0 → v0.45.0) and golang.org/x/text (v0.35.0 → v0.37.0) are updated alongside them, likely as transitive alignment from the module graph.

Reviewed by Cursor Bugbot for commit 82390b5. Bugbot is set up for automated code reviews on this repo. Configure here.

@peperon
peperon merged commit 42779d9 into master Jul 28, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants