Skip to content
This repository has been archived by the owner on Jun 27, 2023. It is now read-only.

Update dependencies #608

Closed
wants to merge 1 commit into from
Closed

Update dependencies #608

wants to merge 1 commit into from

Conversation

szh
Copy link

@szh szh commented Dec 23, 2021

Removes dependencies on "golang.org/x/net" package version with security vulnerability (golang/go#50058).
This will fix projects depending on this package from being flagged by security scanners such as Snyk.

@szh szh requested a review from codyoss as a code owner December 23, 2021 18:31
@codyoss
Copy link
Member

codyoss commented Dec 30, 2021

@szh could you please sign the CLA: https://cla.developers.google.com/.

@szh
Copy link
Author

szh commented Jan 3, 2022

@codyoss Sorry for the delay. Working through this with legal.

@codyoss
Copy link
Member

codyoss commented Jan 7, 2022

@szh No worries. If it does not work out lmk and I can make a similar PR to get things updated. This might be a good time to prep for a next release and stop supporting older Go versions.(Updating to head dependencies may force this)

@szh
Copy link
Author

szh commented Jan 10, 2022

@codyoss Honestly the sooner this is fixed the better. If it'll be faster for you to do it that's better for me too.

@codyoss
Copy link
Member

codyoss commented Jan 10, 2022

Sounds good, I will try to get something out soon. Closing.

@codyoss codyoss closed this Jan 10, 2022
@codyoss
Copy link
Member

codyoss commented Jan 10, 2022

#611 has landed on HEAD.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants