Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Why?
We are currently pinned to a very old version of
golang.org/x/net
which contains a number of vulnerabilities, of whichgovulncheck
reports two. The minimal version that address the vulnerabilities isgolang.org/x/[email protected]
. In order to upgrade togolang.org/x/[email protected]
, we must upgrade the Go version ingo.mod
to 1.18 (found by binary search).What?
1.18
golang.org/x/net
tov0.23.0
go 1.18
.http.Client
on older versions of Gogovulncheck
CI test tobeta
branchSee Also
Output from
govulncheck
before change:after change: