Skip to content

Conversation

@Keralin
Copy link
Contributor

@Keralin Keralin commented Dec 1, 2025

Summary

This PR addresses security vulnerability GHSA-f6x5-jh6r-wrfv (MEDIUM) in golang.org/x/crypto and prepares the v0.9.8 release.

Security fix:

Changes:

  • deps: Upgrade golang.org/x/crypto v0.41.0 → v0.45.0
  • deps: Upgrade golang.org/x/net v0.43.0 → v0.47.0 (transitive)
  • deps: Upgrade golang.org/x/sys v0.35.0 → v0.38.0 (transitive)
  • docs: Update README.md version references to v0.9.8

Ready for release tagging after merge.

This update resolves GHSA-f6x5-jh6r-wrfv (MEDIUM) in golang.org/x/crypto
by upgrading from v0.41.0 to v0.45.0.

Changes:
- Update golang.org/x/crypto v0.41.0 → v0.45.0
- Update golang.org/x/net v0.43.0 → v0.47.0 (transitive)
- Update golang.org/x/sys v0.35.0 → v0.38.0 (transitive)
Update all version references in README.md from v0.9.7 to v0.9.8

This release includes:
- Security fix for GHSA-f6x5-jh6r-wrfv (MEDIUM) in golang.org/x/crypto

Changes:
- Update version badge to v0.9.8
- Update all download URLs to point to v0.9.8
- Update DOCKERIZE_VERSION environment variable examples
@Keralin
Copy link
Contributor Author

Keralin commented Dec 1, 2025

Hey @jwilder made the PR to address the CVE issues, as for example asked in this issue #257 let me know if you need something more to create the release

@jwilder jwilder merged commit a311640 into jwilder:master Dec 1, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants