Update Go modules and Dependabot configuration - #6278
Merged
Merged
Conversation
As we expect to release a new version of Git LFS shortly, we first update our Go module dependencies to resolve any outstanding issues reported by the "govulncheck" utility. At the moment, there are only two, both fixed in recent versions of the "x/net" module. Version 0.54.0 of the "x/net" module resolves the vulnerability reported as GO-2026-4918 and CVE-2026-33814, while version 0.55.0 resolves the issue reported as GO-2026-5026 and CVE-2026-39821: https://pkg.go.dev/vuln/GO-2026-4918 https://pkg.go.dev/vuln/GO-2026-5026 We therefore update to the latest version of the "x/net" module, namely v0.55.0, using the command: go get golang.org/x/net@latest We then also run the "go mod tidy" command to update the set of Go module hashes in our "go.sum" file. Co-authored-by: Cristian <cristian.gherghina@snyk.io>
As we would like the Dependabot utility to continue to provide regular notifications when one of our Go module dependencies has a security update available, we add the "gomod" package ecosystem to our Dependabot configuration file.
larsxschneider
approved these changes
Jun 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
As we expect to release a new version of Git LFS shortly, we first update our Go module dependencies to resolve any outstanding issues reported by the
govulncheckutility. At the moment, there are only two, both fixed in recent versions of thex/netmodule.Version 0.54.0 of the
x/netmodule resolves the vulnerability reported as GO-2026-4918 and CVE-2026-33814, while version 0.55.0 resolves the issue reported as GO-2026-5026 and CVE-2026-39821.We therefore update to the latest version of the
x/netmodule, namely v0.55.0, using the commandgo get golang.org/x/net@latest, and then we run thego mod tidycommand to update the set of Go module hashes in ourgo.sumfile.As well, because we would like the Dependabot utility to continue to provide regular notifications when one of our Go module dependencies has a security update available, we add the
gomodpackage ecosystem to our Dependabot configuration file./cc @cristian-gherghina re PR #6277