chore(deps): bump golang.org/x/term from 0.40.0 to 0.41.0#101
chore(deps): bump golang.org/x/term from 0.40.0 to 0.41.0#101dependabot[bot] wants to merge 2 commits intomainfrom
Conversation
AssigneesThe following users could not be added as assignees: Please fix the above issues or remove invalid values from |
|
| Severity | Count |
|---|---|
| 🟡 MEDIUM | 1 |
Total: 1
View all 1 findings
🟡 MEDIUM (1)
github.com/go-git/go-git/v5_github.com/go-git/go-git/v5@v5.17.0_github.com/go-git/go-git/v5@v5.17.0_armis-cli_47617378_go.mod_gomod_github.com/go-git/go-git/v5 - This package is affected by 2 vulnerabilities
Location: go.mod
- CVE-2026-34165: Direct Dependency: 'github.com/go-git/go-git/v5@v5.17.0': This package is affected by 2 vulnerabilities: - CVE-2026-34165: Direct Dependency: 'github.com/go-git/go-git/v5@v5.17.0'. go-git: Maliciously crafted idx file can cause asymmetric memory consumption (Fix version: N/A) - CVE-2026-33762: Direct Dependency: 'github.com/go-git/go-git/v5@v5.17.0'. go-git missing validation decoding Index v4 files leads to panic (Fix version: N/A) Unfortunately, as of now, there isn't a completely vulnerability-free version of this package available. Consider replacing it with a more secure alternative. Please make sure to test your application after upgrading, as this may introduce breaking changes.
CVEs: CVE-2026-34165, CVE-2026-33762
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
@dependabot recreate |
Bumps [golang.org/x/term](https://github.com/golang/term) from 0.40.0 to 0.41.0. - [Commits](golang/term@v0.40.0...v0.41.0) --- updated-dependencies: - dependency-name: golang.org/x/term dependency-version: 0.41.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
536d1b6 to
e761f9a
Compare
|
A newer version of golang.org/x/term exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Consolidates three dependabot PRs (#101, #139, #140): - github.com/mattn/go-runewidth 0.0.21 → 0.0.23 - golang.org/x/term 0.40.0 → 0.41.0 (+ x/sys 0.41.0 → 0.42.0) - actions/github-script v8 → v9 - go directive 1.24.0 → 1.25.0 (required by x/term v0.41.0) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Bumps golang.org/x/term from 0.40.0 to 0.41.0.
Commits
9d2dc07go.mod: update golang.org/x dependenciesd954e03all: upgrade go directive to at least 1.25.0 [generated]Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)