Upgrade golang.org/x/net
from v0.15.0 to v0.17.0
#5448
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This issue fixes CVE-2023-39325. This is the security report on the main branch, prior to this change:
This is the report after the change:
I intend to fix CVE-2021-36156 in a separate pull request.
I believe this is a backwards compatible change which is not user facing, so I'm not updating the changelog. As far as I can tell in the "net" package's release tags, the recent changes to it are minor.