Skip to content

Update Go modules and Dependabot configuration - #6278

Merged
chrisd8088 merged 2 commits into
git-lfs:mainfrom
chrisd8088:update-go-modules
Jun 11, 2026
Merged

chrisd8088 merged 2 commits into
git-lfs:mainfrom
chrisd8088:update-go-modules

Conversation

@chrisd8088

Copy link
Copy Markdown
Member

As we expect to release a new version of Git LFS shortly, we first update our Go module dependencies to resolve any outstanding issues reported by the govulncheck utility. At the moment, there are only two, both fixed in recent versions of the x/net module.

Version 0.54.0 of the x/net module resolves the vulnerability reported as GO-2026-4918 and CVE-2026-33814, while version 0.55.0 resolves the issue reported as GO-2026-5026 and CVE-2026-39821.

We therefore update to the latest version of the x/net module, namely v0.55.0, using the command go get golang.org/x/net@latest, and then we run the go mod tidy command to update the set of Go module hashes in our go.sum file.

As well, because we would like the Dependabot utility to continue to provide regular notifications when one of our Go module dependencies has a security update available, we add the gomod package ecosystem to our Dependabot configuration file.

/cc @cristian-gherghina re PR #6277

chrisd8088 and others added 2 commits June 8, 2026 22:50
As we expect to release a new version of Git LFS shortly, we first
update our Go module dependencies to resolve any outstanding issues
reported by the "govulncheck" utility.  At the moment, there are
only two, both fixed in recent versions of the "x/net" module.

Version 0.54.0 of the "x/net" module resolves the vulnerability
reported as GO-2026-4918 and CVE-2026-33814, while version 0.55.0
resolves the issue reported as GO-2026-5026 and CVE-2026-39821:

  https://pkg.go.dev/vuln/GO-2026-4918
  https://pkg.go.dev/vuln/GO-2026-5026

We therefore update to the latest version of the "x/net" module,
namely v0.55.0, using the command:

  go get golang.org/x/net@latest

We then also run the "go mod tidy" command to update the set of Go
module hashes in our "go.sum" file.

Co-authored-by: Cristian <cristian.gherghina@snyk.io>
As we would like the Dependabot utility to continue to provide
regular notifications when one of our Go module dependencies has
a security update available, we add the "gomod" package ecosystem
to our Dependabot configuration file.
@chrisd8088
chrisd8088 requested a review from a team as a code owner June 9, 2026 06:05
@chrisd8088 chrisd8088 added the dependencies Pull requests that update a dependency file label Jun 9, 2026
@chrisd8088
chrisd8088 merged commit af133ba into git-lfs:main Jun 11, 2026
28 of 30 checks passed
@chrisd8088
chrisd8088 deleted the update-go-modules branch June 11, 2026 02:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Sponsor
SponsoredKunjungi sekarang
Promo