Commit 68c872c
chore(deps): bump golang.org/x/crypto to v0.52.0 and golang.org/x/sys to v0.45.0
Fixes 14 OSV vulnerabilities flagged by osv-scanner on this PR:
golang.org/x/crypto 0.48.0 -> 0.52.0 (13 GO-2026-5005..5023, 5033)
golang.org/x/sys 0.41.0 -> 0.45.0 (GO-2026-5024; x/crypto transitive bump)
Both deps are indirect; bumping the minimum required versions resolves
the scan / osv-scan check failure on dependabot PR #34.
Local gate green: go build ./..., go vet ./..., go test ./... -race -count=1
(all 16 packages pass, including queueprovider/{nats,kafka,rabbitmq,legacyopen},
storageprovider/{dospaces,r2,s3}, readiness, plans, crypto).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 81322da commit 68c872c
2 files changed
Lines changed: 6 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
21 | | - | |
| 20 | + | |
| 21 | + | |
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| |||
0 commit comments