Skip to content

fix vulns 2025-05 - #338

Merged
troy-chuang merged 1 commit into
masterfrom
fix-vulns-2026-05
May 29, 2026
Merged

fix vulns 2025-05#338
troy-chuang merged 1 commit into
masterfrom
fix-vulns-2026-05

Conversation

@troy-chuang

@troy-chuang troy-chuang commented May 28, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Bump golang.org/x/net to v0.55.0 to patch CVE-2026-39821.
Update Makefile and CI workflows for go version bump required by the package upgrade.

Where should the reviewer start?

go.mod

How should this be manually tested?

Collected metrics data using both the new and current production versions.
Analyze that we produced equivalent content.

Any background context you want to provide?

What picture best describes this PR (optional but encouraged)?

What are the relevant Github Issues?

Developer Done List

  • Tests Added/Updated
  • Updated README.md
  • Verified backward compatible
  • Verified database migrations will not be catastrophic
  • Considered Security, Availability and Confidentiality

For the Reviewer:

By approving this PR, the reviewer acknowledges that they have checked all items in this done list.

Reviewer/Approval Done List

  • Tests Pass Locally
  • CI Build Passes
  • Verified README.md is updated
  • Verified changes are backward compatible
  • Reviewed impact to Security, Availability and Confidentiality (if issue found, add comments and request changes)

@troy-chuang
troy-chuang marked this pull request as ready for review May 29, 2026 18:47

@daniel-spray daniel-spray left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@troy-chuang
troy-chuang merged commit a8ec6b8 into master May 29, 2026
5 checks passed
@troy-chuang
troy-chuang deleted the fix-vulns-2026-05 branch May 29, 2026 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants