Skip to content

Update the golang.org/x indirect dependencies - #90

Merged
beetlebugorg merged 1 commit into
mainfrom
deps/golang-x-packages
Aug 28, 2026
Merged

beetlebugorg merged 1 commit into
mainfrom
deps/golang-x-packages

Conversation

@beetlebugorg

Copy link
Copy Markdown
Owner

What changes

golang.org/x/image  v0.27.0 -> v0.45.0
golang.org/x/net    v0.40.0 -> v0.58.0
golang.org/x/text   v0.25.0 -> v0.41.0

All three are indirect, required through govips. go mod why reports that the main module needs no package from x/image or x/net, so none of the advisories was reachable. The versions were still behind, and each one carried an open alert.

This closes the three open Go Dependabot alerts:

Alert Package Advisory Needed Now
85 golang.org/x/image TIFF PackBits resource consumption 0.41.0 0.45.0
81 golang.org/x/image 0.38.0 0.45.0
84 golang.org/x/net 0.55.0 0.58.0

x/text is not flagged by Dependabot but go get pulled it forward, and the first version it landed on carried GO-2026-5970. It goes to the current release for the same reason.

Verify

govulncheck is clean, including at module level:

No vulnerabilities found.

Before this change it reported two module-level findings that the code does not call. At the intermediate versions x/net@v0.55.0 and x/text@v0.37.0 it still reported GO-2026-5942 and GO-2026-5970, which is why both go higher than the alert asks.

go mod tidy leaves the file unchanged after the bump. go test -race -count=1 ./... passes on the builder image.

@beetlebugorg
beetlebugorg merged commit eb8e126 into main Aug 28, 2026
3 checks passed
@beetlebugorg
beetlebugorg deleted the deps/golang-x-packages branch August 28, 2026 00:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant