Skip to content

fix(deps): update module golang.org/x/net to v0.56.0 [security] (alauda-v0.68.2) - #192

Open
alaudaa-renovate[bot] wants to merge 1 commit into
alauda-v0.68.2from
renovate/alauda-v0.68.2-go-golang.org-x-net-vulnerability
Open

fix(deps): update module golang.org/x/net to v0.56.0 [security] (alauda-v0.68.2)#192
alaudaa-renovate[bot] wants to merge 1 commit into
alauda-v0.68.2from
renovate/alauda-v0.68.2-go-golang.org-x-net-vulnerability

Conversation

@alaudaa-renovate

@alaudaa-renovate alaudaa-renovate Bot commented Aug 2, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/net v0.55.0 -> v0.56.0 age confidence

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

BIT-golang-2026-46600 / CVE-2026-46600 / GO-2026-5942

More information

Details

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Shanghai, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@alaudaa-renovate alaudaa-renovate Bot added the dependencies Pull requests that update a dependency file label Aug 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant