Skip to content

build(deps): bump the gomod-minor group across 1 directory with 2 updates - #473

Merged
bomly-guy merged 1 commit into
mainfrom
dependabot/go_modules/gomod-minor-057ba3f227
Sep 15, 2026
Merged

bomly-guy merged 1 commit into
mainfrom
dependabot/go_modules/gomod-minor-057ba3f227

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor

Bumps the gomod-minor group with 2 updates in the / directory: golang.org/x/term and golang.org/x/tools.

Updates golang.org/x/term from 0.45.0 to 0.46.0

Commits
  • 6226200 go.mod: update golang.org/x dependencies
  • 7c2fb74 term: process bytes returned with a read error
  • 3963fce all: upgrade go directive to at least 1.26.0 [generated]
  • See full diff in compare view

Updates golang.org/x/tools from 0.49.0 to 0.50.0

Commits
  • 265dd1a go.mod: update golang.org/x dependencies
  • 2af88d6 gopls/internal/cache: handle multiple legacy build constraints in standalone ...
  • 9e18529 gopls/internal/test/integration/fake: don't poll after a workspace edit
  • 2543006 go/gcexportdata: update package docs + minor tweaks
  • 7c2cac4 gopls/internal/golang/completion: handle new(expr)
  • 28649ea go/analysis/passes/modernize: elide redundant clone in appendclipped
  • 332fd4c gopls/internal/protocol: trace error messages
  • 4d65dec gopls/internal/cache: tolerate missing nodes in reachability analysis
  • 664b13f internal/refactor/inline: guard against non-ellipsis
  • 567ef61 go/analysis/passes/modernize: testingcontext - skip deferred calls
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ates

Bumps the gomod-minor group with 2 updates in the / directory: [golang.org/x/term](https://github.com/golang/term) and [golang.org/x/tools](https://github.com/golang/tools).


Updates `golang.org/x/term` from 0.45.0 to 0.46.0
- [Commits](golang/term@v0.45.0...v0.46.0)

Updates `golang.org/x/tools` from 0.49.0 to 0.50.0
- [Release notes](https://github.com/golang/tools/releases)
- [Commits](golang/tools@v0.49.0...v0.50.0)

---
updated-dependencies:
- dependency-name: golang.org/x/term
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor
- dependency-name: golang.org/x/tools
  dependency-version: 0.50.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 15, 2026
@dependabot
dependabot Bot requested a review from bomly-guy as a code owner September 15, 2026 05:26
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 15, 2026
@coderabbitai

coderabbitai Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: e7c53f43-1a1d-496c-9537-022419417a50

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Bomly Diff Summary

Compared 3feb9f47858a635b97c2bb1b715560c33c4c092c to e45becfaa61e19b6e730efa429df1892a278018e.

Overview

Status Manifests Dependencies Findings Duration
✅ Pass +0 / ~1 / -0 0 added / 9 version changed / 0 detail changes / 0 removed 0 introduced / 0 persisted / 2 resolved 1m 25s

Dependency Changes

Summary: 0 added, 9 version changed, 0 detail changes, 0 removed.

Changed Dependencies

Change Package Version Direct? Scope Licenses
changed golang.org/x/crypto v0.55.0 → v0.57.0 No runtime BSD-3-Clause
changed golang.org/x/mod v0.40.0 → v0.41.0 No runtime BSD-3-Clause
changed golang.org/x/net v0.58.0 → v0.59.0 No runtime BSD-3-Clause
changed golang.org/x/sync v0.22.0 → v0.23.0 No runtime BSD-3-Clause
changed golang.org/x/sys v0.47.0 → v0.48.0 No runtime BSD-3-Clause
changed golang.org/x/telemetry v0.0.0-20260811182544-a038080d80e5 → v0.0.0-20260908163034-4bcc4b2ee518 No runtime BSD-3-Clause
changed golang.org/x/term v0.45.0 → v0.46.0 Yes runtime BSD-3-Clause
changed golang.org/x/text v0.41.0 → v0.42.0 No runtime BSD-3-Clause
changed golang.org/x/tools v0.49.0 → v0.50.0 Yes runtime BSD-3-Clause

Vulnerabilities

Summary: 0 introduced, 1 persisted, 2 resolved.

Persisted Vulnerabilities

Change Severity ID Package Fixed In Source Title
persisted UNKNOWN GO-2026-5932 golang.org/x/[email protected] - grype The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used. If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.

Resolved Vulnerabilities

Change Severity ID Package Fixed In Source Title
resolved HIGH GO-2026-6354 golang.org/x/[email protected] 0.56.0 grype Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
resolved HIGH GO-2026-6355 golang.org/x/[email protected] 0.56.0 grype Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.

License Changes

✅ No license changes.

Project Posture

✅ No project posture changes (--matchers +scorecard was not selected).

Policy Findings

Summary: 0 introduced, 0 persisted, 2 resolved.

Resolved Findings

Status Category Severity ID Package Fixed In Title
✅ resolved vulnerability HIGH GO-2026-6354 golang.org/x/[email protected] 0.56.0 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
✅ resolved vulnerability HIGH GO-2026-6355 golang.org/x/[email protected] 0.56.0 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.

Legend: ✅ resolved · ❌ failing · ⚠️ warning

Remediation

ℹ️ No fix suggestions available for 1 vulnerable package.

Vulnerable package Status Recommended version Action Suggested action for Manifest Manager advice
golang.org/x/[email protected] Fix availability unknown - Manual review pkg:golang/github.com/bomly-dev/[email protected] go.mod -

@bomly-guy
bomly-guy merged commit d15dfaa into main Sep 15, 2026
13 checks passed
@bomly-guy
bomly-guy deleted the dependabot/go_modules/gomod-minor-057ba3f227 branch September 15, 2026 05:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant